Unusual File Modification by dns.exe — Detection Rule

Detects an unexpected file being modified by dns.exe which my indicate activity related to remote code execution or other forms of exploitation as seen in CVE-2020-1350 (SigRed)

Read the full analysis on IntelFusions