Skip to content

Commit afa518b

Browse files
committed
lamehug
1 parent 0ed670c commit afa518b

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

detections/endpoint/windows_ai_platform_dns_query.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ data_source:
1111
search: '`sysmon` EventCode=22 process_name IN ("python.exe", "cmd.exe", "rundll32.exe","powershell.exe", "pwsh.exe") QueryName= "router.huggingface.co"
1212
| rename dvc as dest
1313
| stats count min(_time) as firstTime max(_time) as lastTime
14-
by answer answer_count dvc process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id
14+
by answer answer_count dest process_exec process_guid process_name query query_count reply_code_id signature signature_id src user_id
1515
vendor_product QueryName QueryResults QueryStatus
1616
| `security_content_ctime(firstTime)`
1717
| `security_content_ctime(lastTime)`

0 commit comments

Comments
 (0)