Detection rules › Kusto Query Language

Google Threat Intelligence - Threat Hunting Domain

Source
upstream

'Google Threat Intelligence domain correlation.'

MITRE ATT&CK coverage

TacticTechniques
Command & ControlT1071 Application Layer Protocol

Event coverage

ProviderEvent IDTitle
Sysmon22DNSEvent (DNS query)

Stages and Predicates

Stage 1: source

_Im_Dns

Stage 2: where

DnsQuery is_not_null

Stage 3: extend

Stage 4: join

Stage 5: project