Skip to content

Instantly share code, notes, and snippets.

@michaelhidalgo
Created April 14, 2020 02:44
Show Gist options
  • Save michaelhidalgo/4c437770ed28cd9cca42a6a250301a29 to your computer and use it in GitHub Desktop.
Save michaelhidalgo/4c437770ed28cd9cca42a6a250301a29 to your computer and use it in GitHub Desktop.
Sysmon DNS Query
<?xml version="1.0" ?>
<event name="SYSMON_DNS_QUERY" value="22" level="Informational" template="Dns query" rulename="DnsQuery" ruledefault="exclude" version="5">
<data name="RuleName" inType="win:UnicodeString" outType="xs:string"/>
<data name="UtcTime" inType="win:UnicodeString" outType="xs:string"/>
<data name="ProcessGuid" inType="win:GUID"/>
<data name="ProcessId" inType="win:UInt32" outType="win:PID"/>
<data name="QueryName" inType="win:UnicodeString" outType="xs:string"/>
<data name="QueryStatus" inType="win:UnicodeString" outType="xs:string"/>
<data name="QueryResults" inType="win:UnicodeString" outType="xs:string"/>
<data name="Image" inType="win:UnicodeString" outType="xs:string"/>
</event>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment