Skip to content

Commit 9731c2d

Browse files
wikijmgithub-actions[bot]
authored andcommitted
Apply automatic changes
1 parent d685515 commit 9731c2d

21 files changed

+21
-21
lines changed

S1PQ-rules-windows-dns_query/dns_query_win_anonymfiles_com.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and event.dns.request contains ".anonfiles.com")
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_appinstaller.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (src.process.image.path contains "C:\\Program Files\\WindowsApps\\Microsoft.DesktopAppInstaller_" and src.process.image.path contains "\\AppInstaller.exe"))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_cloudflared_communication.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains ".v2.argotunnel.com" or event.dns.request contains "protocol-v2.argotunnel.com" or event.dns.request contains "trycloudflare.com" or event.dns.request contains "update.argotunnel.com"))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_common_malware_hosting_services.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains "msapp.workers.dev" or event.dns.request contains "trycloudflare.com" or event.dns.request contains "infinityfreeapp.com" or event.dns.request contains "my5353.com" or event.dns.request contains "reurl.cc" or event.dns.request contains "lihi.cc" or event.dns.request contains "tinyurl.com"))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_devtunnels_communication.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and event.dns.request contains ".devtunnels.ms")
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_dns_server_discovery_via_ldap_query.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains "_ldap." and (not ((src.process.image.path contains ":\\Program Files\\" or src.process.image.path contains ":\\Program Files (x86)\\" or src.process.image.path contains ":\\Windows\\") or (src.process.image.path contains ":\\ProgramData\\Microsoft\\Windows Defender\\Platform\\" and src.process.image.path contains "\\MsMpEng.exe") or src.process.image.path="<unknown process>" or not (src.process.image.path matches "\.*"))) and (not (src.process.image.path contains "C:\\WindowsAzure\\GuestAgent" or (src.process.image.path contains "\\chrome.exe" or src.process.image.path contains "\\firefox.exe" or src.process.image.path contains "\\opera.exe")))))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_domain_azurewebsites.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains "azurewebsites.net" and (not ((src.process.image.path in ("C:\\Program Files\\Google\\Chrome\\Application\\chrome.exe","C:\\Program Files (x86)\\Google\\Chrome\\Application\\chrome.exe")) or (src.process.image.path in ("C:\\Program Files\\Mozilla Firefox\\firefox.exe","C:\\Program Files (x86)\\Mozilla Firefox\\firefox.exe")) or (src.process.image.path in ("C:\\Program Files (x86)\\Internet Explorer\\iexplore.exe","C:\\Program Files\\Internet Explorer\\iexplore.exe")) or (src.process.image.path contains "C:\\Program Files (x86)\\Microsoft\\EdgeWebView\\Application\\" or src.process.image.path contains "\\WindowsApps\\MicrosoftEdge.exe" or (src.process.image.path in ("C:\\Program Files (x86)\\Microsoft\\Edge\\Application\\msedge.exe","C:\\Program Files\\Microsoft\\Edge\\Application\\msedge.exe"))) or ((src.process.image.path contains "C:\\Program Files (x86)\\Microsoft\\EdgeCore\\" or src.process.image.path contains "C:\\Program Files\\Microsoft\\EdgeCore\\") and (src.process.image.path contains "\\msedge.exe" or src.process.image.path contains "\\msedgewebview2.exe")) or src.process.image.path contains "\\safari.exe" or (src.process.image.path contains "\\MsMpEng.exe" or src.process.image.path contains "\\MsSense.exe") or (src.process.image.path contains "\\brave.exe" and src.process.image.path contains "C:\\Program Files\\BraveSoftware\\") or (src.process.image.path contains "\\AppData\\Local\\Maxthon\\" and src.process.image.path contains "\\maxthon.exe") or (src.process.image.path contains "\\AppData\\Local\\Programs\\Opera\\" and src.process.image.path contains "\\opera.exe") or ((src.process.image.path contains "C:\\Program Files\\SeaMonkey\\" or src.process.image.path contains "C:\\Program Files (x86)\\SeaMonkey\\") and src.process.image.path contains "\\seamonkey.exe") or (src.process.image.path contains "\\AppData\\Local\\Vivaldi\\" and src.process.image.path contains "\\vivaldi.exe") or ((src.process.image.path contains "C:\\Program Files\\Naver\\Naver Whale\\" or src.process.image.path contains "C:\\Program Files (x86)\\Naver\\Naver Whale\\") and src.process.image.path contains "\\whale.exe") or src.process.image.path contains "\\Tor Browser\\" or ((src.process.image.path contains "C:\\Program Files\\Waterfox\\" or src.process.image.path contains "C:\\Program Files (x86)\\Waterfox\\") and src.process.image.path contains "\\Waterfox.exe") or (src.process.image.path contains "\\AppData\\Local\\Programs\\midori-ng\\" and src.process.image.path contains "\\Midori Next Generation.exe") or ((src.process.image.path contains "C:\\Program Files\\SlimBrowser\\" or src.process.image.path contains "C:\\Program Files (x86)\\SlimBrowser\\") and src.process.image.path contains "\\slimbrowser.exe") or (src.process.image.path contains "\\AppData\\Local\\Flock\\" and src.process.image.path contains "\\Flock.exe") or (src.process.image.path contains "\\AppData\\Local\\Phoebe\\" and src.process.image.path contains "\\Phoebe.exe") or ((src.process.image.path contains "C:\\Program Files\\Falkon\\" or src.process.image.path contains "C:\\Program Files (x86)\\Falkon\\") and src.process.image.path contains "\\falkon.exe") or ((src.process.image.path contains "C:\\Program Files (x86)\\Avant Browser\\" or src.process.image.path contains "C:\\Program Files\\Avant Browser\\") and src.process.image.path contains "\\avant.exe")))))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_finger.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and src.process.image.path contains "\\finger.exe")
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_hybridconnectionmgr_servicebus.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains "servicebus.windows.net" and src.process.image.path contains "HybridConnectionManager"))
44
```
55

S1PQ-rules-windows-dns_query/dns_query_win_kerberos_coercion_via_dns_object_spoofing.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
```sql
2-
// Translated content (automatically translated on 25-01-2026 02:31:51):
2+
// Translated content (automatically translated on 26-01-2026 02:30:45):
33
event.category="dns" and (endpoint.os="windows" and (event.dns.request contains "UWhRCA" and event.dns.request contains "BAAAA"))
44
```
55

0 commit comments

Comments
 (0)