DevNet Associate DEVASC 200-901 Official Certification Guide by Adrian Iliesiu (z-lib.org)

(andrew) #1

Feed NameDescription


autorun-
registry

Registry entry data derived from querying
registry changes known for persistence

banking-
dns

Banking Trojan network communications

dga-dns DGA domains with pseudo-randomly generated
names

dll-
hijacking


  • dns


Domains communicated to by samples
leveraging DLL sideloading and hijacking
techniques

doc-net-
com-dns

Document (PDF, Office) network
communications

downloa
ded- pe-
dns

Samples downloading executables network
communications

dynamic-
dns

Samples leveraging dynamic DNS providers

irc-dns Internet Relay Chat (IRC) network
communications

modified
-hosts-
dns

Modified Windows hosts file network
communications

parked-
dns

Parked domains resolving to RFC 1918 localhost
and broadcast addresses

public-
ip-check-
dns

Public IP address network communications

ransomw
are-dns

Samples communicating with ransomware
servers
Free download pdf