mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 17:58:52 +00:00
Update sysmon_dns_over_https_enabled.yml
This commit is contained in:
parent
c7685e1c18
commit
edf1740ec4
@ -17,11 +17,11 @@ detection:
|
||||
selection1:
|
||||
TargetObject:
|
||||
- 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\BuiltInDnsClientEnabled'
|
||||
Details: 'DWORD (1)'
|
||||
Details: 'DWORD (1)'
|
||||
selection2:
|
||||
TargetObject:
|
||||
- 'HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\DnsOverHttpsMode'
|
||||
Details: 'DWORD (secure)'
|
||||
Details: 'DWORD (secure)'
|
||||
condition: selection1 or selection2
|
||||
falsepositives:
|
||||
- "Unlikely"
|
||||
|
Loading…
Reference in New Issue
Block a user