You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The rule 4d07b1f4-cb00-4470-b9f8-b0191d48ff52 detects remote access software domain like teamviewer and anydesk.
There is a less known remote access software that is DWservice and that could be usefull to detect.
It provides remote desktop view, terminal access, files access under linux, windows, mac osx.
- This commit adds coverage for `dwservice.net` as suggested in issue SigmaHQ#4438
- Sorts the list of tlds
- Removes leading dots to avoid missing coverage
Description of the Idea of the Rule
The rule 4d07b1f4-cb00-4470-b9f8-b0191d48ff52 detects remote access software domain like teamviewer and anydesk.
There is a less known remote access software that is DWservice and that could be usefull to detect.
It provides remote desktop view, terminal access, files access under linux, windows, mac osx.
https://www.dwservice.net/fr/home.html
https://www.dwservice.net/fr/applications.html
Public References / Example Event Log
I suscessfully detected such access adding this domain:
Here are some DNS I get from real detections:
The text was updated successfully, but these errors were encountered: