Nslookup PowerShell Download Cradle - ProcessCreation
Description
Detects suspicious powershell download cradle using nslookup. This cradle uses nslookup to extract payloads from DNS records
Query · sigma
selection_img: - Image|contains: \nslookup.exe - OriginalFileName: \nslookup.exe selection_cmd: ParentImage|endswith: - \powershell.exe - \pwsh.exe CommandLine|contains: - ' -q=txt ' - ' -querytype=txt ' condition: all of selection_*
Known false positives
- Unknown