Update sysmon_dns_over_https_enabled.yml
This commit is contained in:
@@ -17,11 +17,11 @@ detection:
|
||||
selection1:
|
||||
TargetObject:
|
||||
- 'HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Edge\BuiltInDnsClientEnabled'
|
||||
Details: 'DWORD (1)'
|
||||
Details: 'DWORD (1)'
|
||||
selection2:
|
||||
TargetObject:
|
||||
- 'HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\DnsOverHttpsMode'
|
||||
Details: 'DWORD (secure)'
|
||||
Details: 'DWORD (secure)'
|
||||
condition: selection1 or selection2
|
||||
falsepositives:
|
||||
- "Unlikely"
|
||||
|
||||
Reference in New Issue
Block a user