Query
[T1059.001] NSLookup Remote Payload
LogScale · Detection & Monitoring · v2 · @sebastian · 24.7.2026
Detect PowerShell-spawned nslookup.exe queries using -q=txt, often used for remote payload retrieval, mapped to MITRE ATT&CK T1059.001.
DetectionEndpointWindows
Query contentv2
Download v2Loading editor…
Version history
Every save keeps the previous content. Open any version to view or download it.