Update proc_creation_win_dnscmd_discovery.yml

Modified selection name
This commit is contained in:
Daniel Gott
2022-07-31 18:54:34 -04:00
committed by GitHub
parent 7155eb999b
commit 78ca0d324c
@@ -21,7 +21,7 @@ logsource:
detection:
selection_dsamain:
Image|endswith: '\dnscmd.exe'
selection_recon1:
selection_1:
CommandLine|contains:
- '/enumrecords'
- '/enumzones'