DEF CON 34 'Plug & Pwn': Post-PnP DNS Hijack via SwiService Named Pipe (Sierra Wireless CVE Chain)
This rule detects DNS configuration changes (via 'netsh' commands or registry modifications to the 'NameServer' value) initiated by specific system processes ('SwiService.exe' or 'svchost.exe') shortly after a Plug-and-Play (PnP) event, such as a USB drive connection. This pattern is indicative of potential malicious activity attempting to redirect DNS queries upon the insertion of unauthorized hardware.
Microsoft Sentinel (KQL)

