adding additional allow for dns service (domain controllers)

This commit is contained in:
Tim Shelton
2021-11-10 17:09:15 +00:00
parent d7612739e7
commit 52d0cb67eb
@@ -38,9 +38,11 @@ detection:
- '\FSAssessment.exe'
- '\MobaRTE.exe'
- '\chrome.exe'
- '\System32\dns.exe'
- '\thor.exe'
- '\thor64.exe'
condition: selection and not filter
falsepositives:
- Other Remote Desktop RDP tools
- domain controller using dns.exe
level: high