Skip to content

DNS Exfiltration rule #4889

@pramodpabbati

Description

@pramodpabbati

Hello!

Just reviewing the DNS exfiltration rule at - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_invoke_dnsexfiltration.yml and was curious on the detection logic of looking for "Invoke-DNSExfiltrator" OR all of the flags its running with.

Based on the references and the wiki for the tool, it doesn't look like the detection logic is accurate. Could you please confirm?

Kind Regards,
Pramod

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions