
Syed Usfar Wasim
@nCD24DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views
38 detections
Filters
Last updated
All Time
Detection languages
38
Categories
4
2
2
2
2
Platforms
18
8
3
2
2
Products / Services
4
3
3
1
1
MITRE Techniques
7
6
6
6
6
CVEs
1
1
1
1
1
IDS Classtypes
2
1
This KQL detects possible impossible travel sign-in patterns by identifying users who had successful Entra ID sign-ins from different countries within a short time window of 4 hours.
This KQL identifies inbound emails that were not blocked and have subject lines commonly associated with phishing or social engineering lures along with a URL and/or attachment
This KQL detects attack used TCP port 4307 for unauthenticated access and replaced public\js\locale.php with a web shell that provided persistent remote access.
Detects Microsoft Defender XDR UrlClickEvents where a clicked URL or extracted clicked domain matches known Coinbase Cartel-related URL, onion, messaging, or infrastructure indicators.
Detects file, process, or image-load events in Microsoft Defender XDR where the file hash or initiating-process hash matches known Coinbase Cartel-related hash indicators.
This query detects PowerShell-based AES encryption activity followed by mass file rename/encryption indicators and ransom note creation within a correlated pre-defined timestamp.
This query is trying to identify cases where a newly created machine account may correspond to a device that quickly begins exposing domain-controller-like services, especially LDAP and SMB.
This detects a possible VPN brute-force or password-spray followed by successful authentication, where the same user has 5 failed SSL VPN login attempts followed by a successful tunnel-up event within 2 minutes.
Detects endpoint file artifacts associated with known malicious browser extension IDs in browser extension storage paths, indicating possible installation or presence of malicious browser extensions.
Detects which privileged users have signed in recently, how often, from how many IPs/apps, what authentication methods they used, and whether any password-only sign-ins occurred?
Page 2 of 4
