cscli scenarios install mstilkerich/bind9-refused
Detect AXFR requests and DNS queries rejected by bind9 security policy:
1type: leaky2name: mstilkerich/bind9-refused3description: "Act on queries / zone transfers denied by bind9 policy"4debug: false5filter: "evt.Meta.log_type == 'bind9_denied'"6groupby: evt.Meta.source_ip7capacity: 58leakspeed: 10s9blackhole: 1m10labels:11 service: domain12 classification:13 - attack.T1590.00214 spoofable: 015 confidence: 316 behavior: "generic:scan"17 label: "Domain transfer attempt"18 remediation: true19