title: Suspicious DNS Query with B64 Encoded String id: 4153a907-2451-4e4f-a578-c52bb6881432 status: experimental description: Detects suspicious DNS queries using base64 encoding references: - https://github.com/krmaxwell/dns-exfiltration author: Florian Roth date: 2018/05/10 logsource: category: dns detection: selection: query: - '*==.*' condition: selection falsepositives: - Unknown level: medium