Query
[T1059.001] NSLookup Remote Payload
LogScale · Detection & Monitoring · v2 · @sebastian · 24.7.2026
Detect PowerShell-spawned nslookup.exe queries using -q=txt, often used for remote payload retrieval, mapped to MITRE ATT&CK T1059.001.
DetectionEndpointWindows
Query contentv2
Download v2Loading editor…
Version history
By default each save creates a new version. Overwrites update the current version in place. Open any version to view or download it.