-
-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Closed
Labels
Work In ProgressSome changes are neededSome changes are needed
Description
Hello!
Just reviewing the DNS exfiltration rule at - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml and was curious on the detection logic of looking for "Invoke-DNSExfiltrator" OR all of the flags its running with.
Based on the references and the wiki for the tool, it doesn't look like the detection logic is accurate. Could you please confirm?
Kind Regards,
Pramod
nasbench
Metadata
Metadata
Assignees
Labels
Work In ProgressSome changes are neededSome changes are needed