-
GenAI Process Connection to Suspicious Top Level Domain
Sep 19, 2026 · Domain: Endpoint OS: macOS OS: Windows Use Case: Threat Detection Tactic: Command and Control Data Source: Elastic Defend Data Source: Sysmon Resources: Investigation Guide Domain: LLM Mitre Atlas: T0086 Noise: Medium Performance: Normal Profile: Recommended Threat: Suspicious TLD Threat: Unauthorized AI Usage Rule Type: Event Correlation (EQL) Platform: Windows Platform: macOS Domain: GenAI ·Detects when GenAI tools connect to domains using suspicious TLDs commonly abused for malware C2 infrastructure. TLDs like .top, .xyz, .ml, .cf, .onion are frequently used in phishing and malware campaigns. Legitimate GenAI services use well-established domains (.com, .ai, .io), so connections to suspicious TLDs may indicate compromised tools, malicious plugins, or AI-generated code connecting to attacker infrastructure.
Read More -
Network Activity to a Suspicious Top Level Domain
Sep 19, 2026 · Domain: Endpoint OS: Windows Use Case: Threat Detection Tactic: Command and Control Resources: Investigation Guide Data Source: Elastic Endgame Data Source: Elastic Defend Data Source: SentinelOne Data Source: Crowdstrike Data Source: Sysmon Noise: High Performance: Normal Profile: Aggressive Threat: Living off the Land Threat: Suspicious TLD Rule Type: Event Correlation (EQL) Platform: Windows ·Identifies DNS queries to commonly abused Top Level Domains by common LOLBINs or executables running from world writable directories or unsigned binaries. This behavior matches on common malware C2 abusing less formal domain names.
Read More -
Unusual DNS Request to Suspicious Top Level Domain
Sep 19, 2026 · Domain: Endpoint Domain: Network OS: Linux Platform: Linux Use Case: Threat Detection Tactic: Command and Control Tactic: Exfiltration Data Source: Elastic Defend Rule Type: ES|QL Resources: Investigation Guide Noise: High Performance: Normal Profile: Aggressive Threat: Suspicious TLD ·This rule detects unusual DNS queries to commonly abused top level domains. Malware authors may use these domains to host command and control infrastructure, exfiltrate data, or to download payloads for later execution.
Read More -
This rule monitors for the unusual occurrence of outbound network connections to suspicious top level domains.
Read More