Forum Discussion

404_BrainNotFound's avatar
404_BrainNotFound
Copper Contributor
Dec 14, 2023

Detection Rule using known bad email domains/addresses

Hi Folks,

 

I wrote a query for detecting PowerShell activity when a user clicks on a links coming form known bad email addresses/domains.

 

My query works for a single email/domain, I was trying to find a way to convert this into a detection rule where all the domains/addresses we collect from Threat Intelligence sources can be constantly monitored for all onboarded devices.

 

I'm struggling to figure out how to funnel all the collected domains into the query. 

 

Really appreciate any guidance/help on this.

No RepliesBe the first to reply

Resources