Detection rules › Kusto Query Language

RecordedFuture Threat Hunting Domain All Actors

Source
upstream

'Recorded Future Threat Hunting domain correlation for all actors.'

MITRE ATT&CK coverage

TacticTechniques
Initial AccessT1566 Phishing
Command & ControlT1568 Dynamic Resolution

Event coverage

ProviderEvent IDTitle
Sysmon22DNSEvent (DNS query)

Stages and Predicates

Stage 1: source

_Im_Dns

Stage 2: where

Domain is_not_null

Stage 3: extend

Stage 4: join

Stage 5: mv-expand

Stage 6: project