Update sysmon_dns_serverlevelplugindll.yml

This commit is contained in:
Jonhnathan 2020-10-15 20:03:29 -03:00 committed by GitHub
parent bdca2febe9
commit c4a44e2376
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -30,7 +30,7 @@ logsource:
category: registry_event
detection:
dnsregmod:
TargetObject: '*\services\DNS\Parameters\ServerLevelPluginDll'
TargetObject|endswith: '\services\DNS\Parameters\ServerLevelPluginDll'
condition: 1 of them
---
logsource:
@ -38,5 +38,5 @@ logsource:
product: windows
detection:
dnsadmin:
CommandLine: 'dnscmd.exe /config /serverlevelplugindll *'
condition: 1 of them
CommandLine|startswith 'dnscmd.exe /config /serverlevelplugindll '
condition: 1 of them