Zeek HTTP Requests to Low Reputation TLDs or Suspicious File Extensions

Alerts on Zeek HTTP requests to low-reputation TLDs or URIs/MIME types consistent with executable payload delivery.

FreeReviewedSigma · Medium · v2
Product
zeek
Service
http
Author
@signalblur, Corelight (SigmaHQ), DRL 1.1
Published
2025-02-26
Updated
2026-07-31

What it detects

Identifies Zeek HTTP traffic where the request host ends with a low reputation or commonly abused top-level domain, or the requested URI ends with a suspicious executable/script/archive shortcut extension. This matters because attackers often use newly registered or abused domains to host or stage malicious payloads and lure victims into fetching dangerous files. The rule relies on Zeek HTTP fields for the requested host, requested URI, and observed response MIME types corresponding to common malware file formats.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.