SIGMA
Rule Structure
yamlCopiarEditartitle: Suspicious domain with sensitive keyword
id: 8c7a-fake-1234-5678
status: stable
description: Detects domains containing sensitive internal keywords
level: medium
author: drp.team@inopli.com
detection:
selection:
type: domain
value|contains: "internal"
condition: selectionDetection Model
Use Cases
Incident Triggering
Last updated