<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Find the source for &amp;quot;DNS amplification attack response&amp;quot; in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/find-the-source-for-quot-dns-amplification-attack-response-quot/m-p/585300#M116852</link>
    <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/922167235"&gt;@Arman_Zaheri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The (36029) signature triggers when DNS TYPE is TXT, section is ANSWER, and length between 3800 and 4000 in the response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Grab the PCAP from the threat log (you might have to enable PCAP in the TID first).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1714463821455.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59347iCDC139A4DD1D5492/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1714463821455.png" alt="kiwi_0-1714463821455.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Send the PCAP over to TAC for analysis.&amp;nbsp; If this is truly a FP then the signature might have to be updated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
    <pubDate>Tue, 30 Apr 2024 08:04:36 GMT</pubDate>
    <dc:creator>kiwi</dc:creator>
    <dc:date>2024-04-30T08:04:36Z</dc:date>
    <item>
      <title>Find the source for "DNS amplification attack response"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/find-the-source-for-quot-dns-amplification-attack-response-quot/m-p/585211#M116843</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We receive many "&lt;SPAN&gt;DNS amplification attack response" alerts with the source of our internal DNS servers toward public DNS servers on the Internet. How can we know whether these alerts are not false positives and if they are true positive, how to find the main endpoint responsible for this type of attack?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you all &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2024 12:11:02 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/find-the-source-for-quot-dns-amplification-attack-response-quot/m-p/585211#M116843</guid>
      <dc:creator>Arman_Zaheri</dc:creator>
      <dc:date>2024-04-29T12:11:02Z</dc:date>
    </item>
    <item>
      <title>Re: Find the source for "DNS amplification attack response"</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/find-the-source-for-quot-dns-amplification-attack-response-quot/m-p/585300#M116852</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/922167235"&gt;@Arman_Zaheri&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The (36029) signature triggers when DNS TYPE is TXT, section is ANSWER, and length between 3800 and 4000 in the response.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Grab the PCAP from the threat log (you might have to enable PCAP in the TID first).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kiwi_0-1714463821455.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/59347iCDC139A4DD1D5492/image-size/medium?v=v2&amp;amp;px=400" role="button" title="kiwi_0-1714463821455.png" alt="kiwi_0-1714463821455.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Send the PCAP over to TAC for analysis.&amp;nbsp; If this is truly a FP then the signature might have to be updated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind regards,&lt;/P&gt;
&lt;P&gt;-Kim.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2024 08:04:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/find-the-source-for-quot-dns-amplification-attack-response-quot/m-p/585300#M116852</guid>
      <dc:creator>kiwi</dc:creator>
      <dc:date>2024-04-30T08:04:36Z</dc:date>
    </item>
  </channel>
</rss>

