Unusual Child Process of dns.exe — Detection Rule

Detects an unexpected process spawning from dns.exe which may indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)

Read the full analysis on IntelFusions