# detects iodine covert tunnels (over DNS), send feedback on rules to merc [at] securitywire.com alert udp any any -> any 53 (content:" |01 00 00 01 00 00 00 00 00 01|" ; offset: 2; depth: 10; content:" |00 00 29 10 00 00 00 80 00 00 00|" ; \ msg: " covert iodine tunnel request" ; threshold: type limit, track by_src, count 1, seconds 300; sid: 5619500; rev: 1;) alert udp any 53 -> any any (content: " |84 00 00 01 00 01 00 00 00 00|" ; offset: 2; depth: 10; content:" |00 00 0a 00 01|" ; \ msg: " covert iodine tunnel response" ; threshold: type limit, track by_src, count 1, seconds 300; sid: 5619501; rev: 1;)
NSE4/FMG-VM64/FortiAnalyzer-VM/6.0 (FWF30E/FW92D/FGT200D/FGT101E/FGT81E)/ FAP220B/221C
User | Count |
---|---|
2546 | |
1354 | |
795 | |
643 | |
455 |
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2025 Fortinet, Inc. All Rights Reserved.