Windows hosts file modification: endpointEndpointrisk_score:252024-10-17version:3
The search looks for modifications to the hosts file on all Windows endpoints across your environment.
DNS Query Requests Resolved by Unauthorized DNS Servers: networkEndpointrisk_score:252024-10-17version:5
This search will detect DNS requests resolved by unauthorized DNS servers. Legitimate DNS servers should be identified in the Enterprise Security Assets and Identity Framework.
Clients Connecting to Multiple DNS Servers: networkEndpointrisk_score:252024-10-17version:5
This search allows you to identify the endpoints that have connected to more than five DNS servers and made DNS Queries over the time frame of the search.