Skip to content

Commit 1ce551d

Browse files
committed
lamehug
1 parent 99b4d48 commit 1ce551d

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

detections/endpoint/windows_ai_platform_dns_query.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,8 @@ description: The following analytic detects DNS queries initiated by the Windows
99
data_source:
1010
- Sysmon EventID 22
1111
search: '`sysmon` EventCode=22 process_name="python.exe" QueryName= "router.huggingface.co"
12-
| stats count min(_time) as firstTime max(_time) as lastTime
12+
| rename dvc as dest
13+
| stats count min(_time) as firstTime max(_time) as lastTime
1314
by answer answer_count dest process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id
1415
vendor_product QueryName QueryResults QueryStatus
1516
| `security_content_ctime(firstTime)`

0 commit comments

Comments
 (0)