Skip to content

Commit e8a6894

Browse files
Neo23x0nasbench
andauthored
Merge PR #5132 from @Neo23x0 - Update DNS Query To Remote Access Software Domain From Non-Browser App
update: DNS Query To Remote Access Software Domain From Non-Browser App - Add `getscreen.me` --------- Co-authored-by: Nasreddine Bencherchali <[email protected]>
1 parent aec72e1 commit e8a6894

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

rules/windows/dns_query/dns_query_win_remote_access_software_domains_non_browsers.yml

+2-1
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ references:
2323
- https://learn.microsoft.com/en-us/windows/client-management/client-tools/quick-assist#disable-quick-assist-within-your-organization
2424
author: frack113, Connor Martin
2525
date: 2022-07-11
26-
modified: 2024-09-13
26+
modified: 2024-12-17
2727
tags:
2828
- attack.command-and-control
2929
- attack.t1219
@@ -51,6 +51,7 @@ detection:
5151
- 'dwservice.net'
5252
- 'express.gotoassist.com'
5353
- 'getgo.com'
54+
- 'getscreen.me' # https://x.com/malmoeb/status/1868757130624614860?s=12&t=C0_T_re0wRP_NfKa27Xw9w
5455
- 'integratedchat.teamviewer.com'
5556
- 'join.zoho.com'
5657
- 'kickstart.jumpcloud.com'

0 commit comments

Comments
 (0)