Best Detection of 2026 Series: DNS-Based ClickFix Payload Staging via nslookup
This rule detects potential command and control or malicious file staging activity by correlating DNS TXT record queries (often used for data exfiltration or staging configuration) performed by common system utilities (nslookup, PowerShell) with the subsequent execution of files from suspicious directories (Downloads, Temp) within a 30-minute window on the same device.
Microsoft Sentinel (KQL)

