Analytics Story: Host Redirection
REMOVED ANALYTIC STORY
This analytic story has been removed from the Splunk Threat Research content library and is no longer maintained or supported.
Reason: Analytic Story deprecated as it no longer effectively identifies the intended malicious activity
Removed in version: 5.2.0
If you have any questions or concerns, please reach out to us at research@splunk.com.
Description
Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website.
Why it matters
Attackers will often attempt to manipulate client communications for nefarious purposes. In some cases, an attacker may endeavor to modify a local host file to redirect communications with resources (such as antivirus or system-update services) to prevent clients from receiving patches or updates. In other cases, an attacker might use this tactic to have the client connect to a site that looks like the intended site, but instead installs malware or collects information from the victim. Additionally, an attacker may redirect a victim in order to execute a MITM attack and observe communications.
Detections
| Name | Technique | Type |
|---|
Data Sources
| Name | Platform | Sourcetype | Source |
|---|
References
Version: 1