Vendor: Splunk

April 15, 2026 · View on GitHub

Product: Splunk Stream

RulesModelsMITRE ATT&CK® TTPsActivity TypesParsers
50520
Use-CaseActivity Types/ParsersMITRE ATT&CK® TTPContent
Malwaredns-query
splunk-stream-json-dns-request-success-query

dns-response
splunk-stream-json-dns-response-success-messagetype
T1071 - Application Layer Protocol
T1568 - Dynamic Resolution
T1568.002 - Dynamic Resolution: Domain Generation Algorithms
T1583 - T1583
T1583.001 - T1583.001
  • 5 Rules

MITRE ATT&CK® Framework for Enterprise

Initial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Dynamic Resolution

Dynamic Resolution: Domain Generation Algorithms

Application Layer Protocol