
Syed Usfar Wasim
@nCD24DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views
38 detections
Filters
Last updated
All Time
Detection languages
38
Categories
4
2
2
2
2
Platforms
18
8
3
2
2
Products / Services
4
3
3
1
1
MITRE Techniques
7
6
6
6
6
CVEs
1
1
1
1
1
IDS Classtypes
2
1
This KQL detects potential social engineering and vishing activity in Microsoft Teams over the last 30 days.
This KQL inventories activity associated with a specified root domain and its subdomains across DeviceNetworkEvents, EmailUrlInfo, CloudAppEvents.
Detects potential abuse of Microsoft Defender’s BTR boot-time remediation driver by correlating known driver loads with BootClean.log activity, unexpected loader processes, and driver execution outside normal Defender paths.
This Defender XDR query detects high-confidence attempts to export certificates with private keys using native Windows utilities, PowerShell, Mimikatz, AADInternals, Certipy, OpenSSL, and certificate-management tools.
Detects Defender XDR alerts and evidence potentially related to Certighost / CVE-2026-54121 AD CS abuse, including suspicious certificate requests, Kerberos activity, LDAP security principal anomalies, and possible DCSync or directory replication abuse.
Detection for reported campaign delivering a trojanized, non-digitally signed TrueConf client installer to users connecting to a compromised TrueConf server.
Detects suspicious OAuth consent or connected app authorization followed by SaaS query, export, download, or bulk API activity from the same account within 24 hours, indicating possible OAuth token abuse or SaaS data exfiltration.
This query identifies creation/loading of SysExcSvc.dll and SysReadSvc.dll along with suspicious LSASS memory dumping, reverse SSH tunnel creation.
These patterns are prevalent with "Phantom" including unusual OneDrive or Microsoft Graph access from LOLBins or unexpected processes.
These patterns are prevalent with "Phantom" including unusual OneDrive or Microsoft Graph access from LOLBins or unexpected processes.
This KQL is designed to hunt for activity that may indicate Active Directory Certificate Services abuse or Certighost-like domain compromise behavior, especially where an attacker may manipulate machine account attributes, impersonate domain-controller-like behavior, or perform follow-on credential extraction.
Detects a single Entra ID session (SessionId) being used from two different countries within one hour at a travel velocity no physical journey could achieve. This is a signature of a stolen session/refresh token being replayed by an actor from a different location than the legitimate user.
Page 1 of 4
