LoFP
/
T1566.003
T1566.003
Title
Tags
if a known good domain is not listed in the legit_domains.csv file, then the search could give you false postives. please update that lookup file to filter out dns requests to legitimate domains.
T1566.003
endpoint
splunk