avatar

Syed Usfar Wasim

@nCD24
DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views

38 detections

This KQL detects potential social engineering and vishing activity in Microsoft Teams over the last 30 days.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
1 month ago
24066
This KQL inventories activity associated with a specified root domain and its subdomains across DeviceNetworkEvents, EmailUrlInfo, CloudAppEvents.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
1 month ago
2112
Detects potential abuse of Microsoft Defender’s BTR boot-time remediation driver by correlating known driver loads with BootClean.log activity, unexpected loader processes, and driver execution outside normal Defender paths.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
1 month ago
218
This Defender XDR query detects high-confidence attempts to export certificates with private keys using native Windows utilities, PowerShell, Mimikatz, AADInternals, Certipy, OpenSSL, and certificate-management tools.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
7014
Detects Defender XDR alerts and evidence potentially related to Certighost / CVE-2026-54121 AD CS abuse, including suspicious certificate requests, Kerberos activity, LDAP security principal anomalies, and possible DCSync or directory replication abuse.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
9032
Detection for reported campaign delivering a trojanized, non-digitally signed TrueConf client installer to users connecting to a compromised TrueConf server.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
5011
Detects suspicious OAuth consent or connected app authorization followed by SaaS query, export, download, or bulk API activity from the same account within 24 hours, indicating possible OAuth token abuse or SaaS data exfiltration.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
11021
This query identifies creation/loading of SysExcSvc.dll and SysReadSvc.dll along with suspicious LSASS memory dumping, reverse SSH tunnel creation.
These patterns are prevalent with "Phantom" including unusual OneDrive or Microsoft Graph access from LOLBins or unexpected processes.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
006
This KQL is designed to hunt for activity that may indicate Active Directory Certificate Services abuse or Certighost-like domain compromise behavior, especially where an attacker may manipulate machine account attributes, impersonate domain-controller-like behavior, or perform follow-on credential extraction.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
3012
Detects a single Entra ID session (SessionId) being used from two different countries within one hour at a travel velocity no physical journey could achieve. This is a signature of a stolen session/refresh token being replayed by an actor from a different location than the legitimate user.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
9233
Page 1 of 4