mirror of
https://github.com/valitydev/SigmaHQ.git
synced 2024-11-07 09:48:58 +00:00
d0d51b6601
The references indicate that this rule should apply to TXT records, but without specifying that the "record_type" must be "TXT" there's the potential for a lot of false positives. "record_type" was chosen as that fits with Splunks "Network Resolution (DNS)" datamodel. |
||
---|---|---|
.. | ||
net_mal_dns_cobaltstrike.yml | ||
net_susp_dns_b64_queries.yml | ||
net_susp_dns_txt_exec_strings.yml | ||
net_susp_network_scan.yml | ||
net_susp_telegram_api.yml |