avatar

Syed Usfar Wasim

@nCD24
DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views

38 detections

This KQL detects possible impossible travel sign-in patterns by identifying users who had successful Entra ID sign-ins from different countries within a short time window of 4 hours.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
13125
This KQL identifies inbound emails that were not blocked and have subject lines commonly associated with phishing or social engineering lures along with a URL and/or attachment
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
10017
This KQL detects attack used TCP port 4307 for unauthenticated access and replaced public\js\locale.php with a web shell that provided persistent remote access.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
203
Detects Microsoft Defender XDR UrlClickEvents where a clicked URL or extracted clicked domain matches known Coinbase Cartel-related URL, onion, messaging, or infrastructure indicators.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
21013
Detects file, process, or image-load events in Microsoft Defender XDR where the file hash or initiating-process hash matches known Coinbase Cartel-related hash indicators.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
7111
This query detects PowerShell-based AES encryption activity followed by mass file rename/encryption indicators and ransom note creation within a correlated pre-defined timestamp.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
3012
This query is trying to identify cases where a newly created machine account may correspond to a device that quickly begins exposing domain-controller-like services, especially LDAP and SMB.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
2 months ago
7015
This detects a possible VPN brute-force or password-spray followed by successful authentication, where the same user has 5 failed SSL VPN login attempts followed by a successful tunnel-up event within 2 minutes.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
15124
Detects endpoint file artifacts associated with known malicious browser extension IDs in browser extension storage paths, indicating possible installation or presence of malicious browser extensions.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
12019
Detects which privileged users have signed in recently, how often, from how many IPs/apps, what authentication methods they used, and whether any password-only sign-ins occurred?
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
32048
Page 2 of 4