Unusual Child Process of dns.exe

 Original Source: [Sigma source]
Title: Unusual Child Process of dns.exe
Status: test
Description:Detects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)
References:
  -https://www.elastic.co/guide/en/security/current/unusual-child-process-of-dns-exe.html
Author: Tim Rauch, Elastic (idea)
Date: 2022-09-27
modified:2023-02-05
Tags:
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.t1133'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    ParentImage|endswith: '\dns.exe'
  filter:
    Image|endswith: '\conhost.exe'
  condition:selection and not filter
Falsepositives:
  -Unknown
Level: high