Project

General

Profile

Actions

Feature #4515

closed

Add DNS logging of Z flag

Added by Odin Jenseg almost 3 years ago. Updated about 2 years ago.

Status:
Closed
Priority:
Normal
Assignee:
Target version:
Effort:
Difficulty:
Label:
Protocol, Rust

Description

The this Z field is logged by Zeek: https://docs.zeek.org/en/master/logs/dns.html
And has shown good value to have in investigations, and there has been created a sigma rule that is based on this flag:
https://github.com/SigmaHQ/sigma/blob/master/rules/network/zeek/zeek_dns_suspicious_zbit_flag.yml

I think this should be pretty strightforward, so I will great a PR


Related issues 1 (0 open1 closed)

Related to Suricata - Bug #4924: dns: transaction not created when z-bit setClosedJason IshActions
Actions

Also available in: Atom PDF