We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 0ed670c commit afa518bCopy full SHA for afa518b
detections/endpoint/windows_ai_platform_dns_query.yml
@@ -11,7 +11,7 @@ data_source:
11
search: '`sysmon` EventCode=22 process_name IN ("python.exe", "cmd.exe", "rundll32.exe","powershell.exe", "pwsh.exe") QueryName= "router.huggingface.co"
12
| rename dvc as dest
13
| stats count min(_time) as firstTime max(_time) as lastTime
14
- by answer answer_count dvc process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id
+ by answer answer_count dest process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id
15
vendor_product QueryName QueryResults QueryStatus
16
| `security_content_ctime(firstTime)`
17
| `security_content_ctime(lastTime)`
0 commit comments