Title:Unusual Child Process of dns.exe Status:test Description:Detects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed) References: -https://www.elastic.co/guide/en/security/current/unusual-child-process-of-dns-exe.html Author: Tim Rauch, Elastic (idea) Date: 2022-09-27 modified:2023-02-05 Tags:
-'attack.persistence'
-'attack.initial-access'
-'attack.t1133'
Logsource:
category: process_creation
product: windows
Detection: selection: ParentImage|endswith:
'\dns.exe' filter: Image|endswith:
'\conhost.exe' condition:selection and not filter Falsepositives:
-Unknown Level:high