Thanks to visit codestin.com
Credit goes to github.com

Skip to content

new: Suspicious Process DNS Query To Known Abused Web Services - clos…#5884

Open
heyyanu wants to merge 1 commit intoSigmaHQ:masterfrom
heyyanu:fix/dns-query-abuse-web-services
Open

new: Suspicious Process DNS Query To Known Abused Web Services - clos…#5884
heyyanu wants to merge 1 commit intoSigmaHQ:masterfrom
heyyanu:fix/dns-query-abuse-web-services

Conversation

@heyyanu
Copy link

@heyyanu heyyanu commented Feb 25, 2026

…es #4748

Summary of the Pull Request

New detection rule for suspicious processes making DNS queries to known
abused web services such as pastebin, discord, telegram commonly used
for C2 communication and payload delivery.

Changelog

new: Suspicious Process DNS Query To Known Abused Web Services

Example Log Event

Image: C:\Windows\System32\powershell.exe
QueryName: pastebin.com

Fixed Issues

Closes #4748

SigmaHQ Rule Creation Conventions

  • Rule follows SigmaHQ conventions
  • Status set to experimental
  • MITRE ATT&CK tags properly formatted
  • If your PR adds new rules, please consider following and applying these conventions

@github-actions github-actions bot added Rules Review Needed The PR requires review Windows Pull request add/update windows related rules labels Feb 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Review Needed The PR requires review Rules Windows Pull request add/update windows related rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Suspicious Process DNS Query Known Abuse Web Services

1 participant