AryStinger Botnet DNS Hijacking - Anomalous A Record Response vs Authoritative Baseline
This rule detects potential DNS hijacking or redirection by comparing the returned IP address from a DNS query against a known list of authoritative IP addresses for specific domains. If an internal DNS resolver returns an IP address that does not match the authoritative record, it flags the event as a potential DNS response mismatch. It includes risk scoring based on the number of distinct affected hosts.
Splunk (SPL)

