Skip to content

Create win_system_possible_ipv6_dns_takeover.yml #5242

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 5 commits into
base: master
Choose a base branch
from

Conversation

NinnessOtu
Copy link

This rule detects a possible IPv6 DNS takeover using ISATAP configuration events (Event ID 4100).

Below is a screenshot showing evidence of the logs and the attack.
1_attack
2_logs

You can find the full details in my write-up on Medium:
https://medium.com/@ninnesoturan/detecting-ipv6-dns-takeover-a54a6a88be1f

@github-actions github-actions bot added Rules Windows Pull request add/update windows related rules labels Mar 22, 2025
@NinnessOtu NinnessOtu changed the title Create Possible_IPV6_DNS_Takeover.yml Create win_system_possible_ipv6_dns_takeover.yml Mar 22, 2025
…stem_possible_ipv6_dns_takeover.yml

Co-authored-by: frack113 <[email protected]>
@NinnessOtu NinnessOtu requested a review from frack113 April 1, 2025 00:23
Copy link
Member

@frack113 frack113 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM
I think the rule can be high as the legit use should be rare enough.

@frack113 frack113 added the 2nd Review Needed PR need a second approval label Apr 1, 2025
@frack113 frack113 requested a review from nasbench April 1, 2025 05:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
2nd Review Needed PR need a second approval Rules Windows Pull request add/update windows related rules
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants