Hey Kanwar!
Thank you for this nice overview!
To extend the scope for the query 2 my expierience in cortex xdr was:
1. take the dns_query_name field too into your scope with or:
dst_action_external_hostname in ("*mega.io*","*mega.nz*","*anonfiles.com*","*dropmefiles.com*","*file.io*","*quaz.im*","*temp.sh*","*termbin.com*","*transfer.sh*","*ufile.io*","*wasabisys.com*") or dns_query_name in ("*mega.io*","*mega.nz*","*anonfiles.com*","*dropmefiles.com*","*file.io*","*quaz.im*","*temp.sh*","*termbin.com*","*transfer.sh*","*ufile.io*","*wasabisys.com*")
2. For subdomains take the star into your scope of the domain to sniff them all:
*wasabisys.com*
BR
Rob
... View more