Title:Unusual File Deletion by Dns.exe Status:test Description:Detects an unexpected file being deleted by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed) References: -https://www.elastic.co/guide/en/security/current/unusual-file-modification-by-dns-exe.html Author: Tim Rauch (Nextron Systems), Elastic (idea) Date: 2022-09-27 modified:2023-02-15 Tags:
-'attack.persistence'
-'attack.initial-access'
-'attack.t1133'
Logsource:
category: file_delete
product: windows
Detection: selection: Image|endswith:
'\dns.exe' filter: TargetFilename|endswith:
'\dns.log' condition:selection and not filter Falsepositives:
-Unknown Level:high