Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

DNS query with an abnormally long leftmost label

AN0030 describes junk characters padded into a command-and-control protocol, measured by MITRE's PayloadEntropyThreshold knob and by a send-to-receive ratio. Neither is available on the analytic's network-connection source — Sysmon EventID 3 carries addresses and ports and no byte counts at all — so the rule is built on the other source the analytic supplies, EventID 22, where the query name *is* the payload and the padding is therefore visible on a single event. The regex requires the leftmost label to be 45 or more characters of label-legal alphanumerics and hyphens before the first dot, which is the closest a single-event Sigma rule gets to an entropy test: junk inserted between significant characters lengthens the label whatever the encoding, while ordinary hostnames are short because humans type them. Read that as a proxy and not as a measurement, because it cuts both ways — a padded channel that keeps its labels short is missed entirely, and a long dictionary-word hostname alerts. The other forms of junk data MITRE covers, padding inside HTTP bodies or a raw TCP stream, leave no trace on any log source in this strategy and are outside what this rule can reach. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0011, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 2 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: DNS query with an abnormally long leftmost labelid: c1eb6448-b94a-4b62-a810-1c2b618a7815status: experimentaldescription: |  AN0030 describes junk characters padded into a command-and-control protocol,  measured by MITRE's PayloadEntropyThreshold knob and by a send-to-receive  ratio. Neither is available on the analytic's network-connection source —  Sysmon EventID 3 carries addresses and ports and no byte counts at all — so  the rule is built on the other source the analytic supplies, EventID 22,  where the query name *is* the payload and the padding is therefore visible on  a single event. The regex requires the leftmost label to be 45 or more  characters of label-legal alphanumerics and hyphens before the first dot,  which is the closest a single-event Sigma rule gets to an entropy test: junk  inserted between significant characters lengthens the label whatever the  encoding, while ordinary hostnames are short because humans type them. Read  that as a proxy and not as a measurement, because it cuts both ways — a  padded channel that keeps its labels short is missed entirely, and a long  dictionary-word hostname alerts. The other forms of junk data MITRE covers,  padding inside HTTP bodies or a raw TCP stream, leave no trace on any log  source in this strategy and are outside what this rule can reach.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0011, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1001/001  - https://attack.mitre.org/detectionstrategies/DET0011author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.command-and-control  - attack.t1001.001logsource:  category: dns_query  product: windowsdetection:  selection:    QueryName|re: '^[A-Za-z0-9-]{45,}\.'  condition: selectionfalsepositives:  - "Content-delivery networks, cloud object storage and anti-malware cloud-reputation lookups, all of which put a long hash or opaque token in the leftmost label. These fire continuously on every host and will outnumber everything else the rule returns, so treat it as a hunting lead over the Image field rather than an alert until the parent domains behind them are suppressed — suppression belongs on the domain, not on the length threshold."  - "Enterprise SaaS, device-management and telemetry endpoints that embed a tenant or device identifier in the hostname. A 36-character GUID plus any prefix clears 45 characters on its own, so these are a permanent floor of matches under a handful of stable parent domains."  - "DNS-based protocols that encode data in names by design and are entirely benign: DKIM selector lookups, DNSBL and RBL queries that prepend a reversed address, and certificate or DANE lookups."  - "The threshold is arbitrary and mine, not MITRE's — MITRE names PayloadEntropyThreshold and this log source has no field to bind it to. Raising it above 45 trades recall for volume with no principled place to stop."level: low

Splunk · SPL

Run this as a search.

index=* | where match(QueryName, "^[A-Za-z0-9-]{45,}\\.")

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,dns_query,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="QueryName" type="pcre2">(?i)^[A-Za-z0-9-]{45,}\.</field>    <description>DNS query with an abnormally long leftmost label</description>    <mitre>      <id>T1001.001</id>    </mitre>  </rule></group>

Sentinel · KQL

Run this as a search.

Sentinel cannot express this construct. No Sentinel table is modelled for this logsource ({"category":"dns_query","product":"windows"}), so there is nothing honest to query. Pick a logsource this translator maps, or write the KQL by hand. The Sigma source is on the first tab, unchanged.

Elastic · ES|QL

Run this as a search.

Elastic cannot express this construct. ES|QL RLIKE uses Lucene regexp syntax, which has no case-insensitive flag, and Sigma regexes are case-insensitive. Use |contains/|startswith/|endswith, or write the ES|QL by hand. The Sigma source is on the first tab, unchanged.

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.