Forum Discussion
404_BrainNotFound
Dec 14, 2023Copper Contributor
Detection Rule using known bad email domains/addresses
Hi Folks,
I wrote a query for detecting PowerShell activity when a user clicks on a links coming form known bad email addresses/domains.
My query works for a single email/domain, I was trying to find a way to convert this into a detection rule where all the domains/addresses we collect from Threat Intelligence sources can be constantly monitored for all onboarded devices.
I'm struggling to figure out how to funnel all the collected domains into the query.
Really appreciate any guidance/help on this.
No RepliesBe the first to reply