Update zeek_dns_suspicious_zbit_flag.yml
This commit is contained in:
@@ -38,7 +38,7 @@ detection:
|
||||
- 'NS'
|
||||
- 'ns'
|
||||
- 'MX'
|
||||
- 'MX'
|
||||
- 'mx'
|
||||
exclude_responses:
|
||||
answers|endswith: '\\x00'
|
||||
exclude_netbios:
|
||||
|
||||
Reference in New Issue
Block a user