Detection rules for SIGRed vulnerability
ID: 3d535ee1-1bdc-516b-b0f2-bb11bd907809
STIX ID: report--3d535ee1-1bdc-516b-b0f2-bb11bd907809
Feed Name: Elastic Security Labs
On July 14, 2020 Microsoft released a patch for SIGRed (CVE-2020-1350), a critical (CVSS 10) remote code execution and DoS vulnerability in Windows DNS Server affecting Windows 2003+. This report summarizes the impact and timeline, provides detection rules for endpoint and network telemetry (KQL and Packetbeat/Zeek/Suricata), and offers mitigation recommendations including applying the Microsoft security update or a registry-based workaround and maintaining backups and vulnerability scanning.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
