Detection rules › Kusto Query Language
RecordedFuture Threat Hunting IP All Actors
'Recorded Future Threat Hunting IP correlation for all actors.'
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Command & Control | T1568 Dynamic Resolution |
| Exfiltration | T1041 Exfiltration Over C2 Channel |
Event coverage
Stages and Predicates
Stage 1: source
_Im_NetworkSession
Stage 2: where
DstIpAddr is_not_null