diff --git a/Sysmon New Events/109100-win_sysmon_new_events.xml b/Sysmon New Events/109100-win_sysmon_new_events.xml
index c777230..9389b11 100644
--- a/Sysmon New Events/109100-win_sysmon_new_events.xml
+++ b/Sysmon New Events/109100-win_sysmon_new_events.xml
@@ -15,10 +15,13 @@
sysmon_event_18,
-
+
61600
^22$
Sysmon - Event 22: DNS Request by $(win.eventdata.image)
+
+ T1071
+
no_full_log
sysmon_event_22,