Zeek DNS: Detect NKN Seed Domain Queries

Alerts on Zeek DNS queries containing "seed" and ending with .nkn.org, a pattern consistent with NKN network activity.

FreeReviewedSigma · Low · v2
Product
zeek
Service
dns
Author
Michael Portera (@mportatoes) (SigmaHQ), DRL 1.1
Published
2022-04-21
Updated
2026-07-31

What it detects

This rule identifies DNS queries that contain both the substring "seed" and the domain suffix ".nkn.org". Attackers may use NKN-related endpoints as part of a decentralized command-and-control workflow, so targeted domain lookups can be an early indicator of such activity. It relies on Zeek DNS telemetry, specifically the queried hostname content fields captured for DNS requests.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.