avatar

Syed Usfar Wasim

@nCD24
DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views

38 detections

Detects high-confidence BoryptGrab-lineage infostealer activity involving fake GitHub delivery indicators, known C2 infrastructure, suspicious gup.exe execution, libcurl.dll side-loading from user-writable paths, and known malicious file hashes.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
6218
This KQL detects potential Microsoft Defender tampering via PowerShell, including attempts to disable real-time or behavior monitoring and add Defender exclusions. It enriches results with tamper type, suspicious PowerShell flags, and confidence level to help prioritize medium/high-confidence activity.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
28139
This KQL detects activity associated with network traffic to known C2 infrastructure (45.146.252.17), suspicious Node/NPM execution chains and dropped payload/marker files. Also looks for indicators of remote control, clipboard access, screenshot/desktop-control packages, Socket.IO C2 traffic, and file/browser/wallet data exfiltration behavior.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
55024
This detects a suspicious process pattern where "svchost.exe -> svchost.exe -k DHCPServer" running under the Network Service account.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
6121
Detects rundll32.exe making outbound network connections to public IP addresses, excluding cases where the parent process is svchost.exe. This indicates the abuse of "rundll32.exe" as a proxy execution binary for defense evasion, payload execution, or suspicious network communication.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
8013
Detects suspicious execution of tools or command lines associated with DPAPI domain backup key extraction, including mimikatz, SharpDPAPI, lsadump::backupkeys, and related backupkey commands. This behavior may indicate an attempt to obtain the domain DPAPI backup key from a Domain Controller, enabling decryption of DPAPI-protected secrets across the domain.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
5012
This query detects non-browser processes making network connections to .shop or .xyz domains which could possibly pertain to phishing, malware delivery, tracking, ad fraud, or command-and-control.
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
209
This query hunts for suspicious cases where Warp Terminal or a Warp-related parent process spawns Unix-like shell interpreters such as sh, bash, zsh, fish, or dash, and executes commands using shell execution patterns like -c, /bin/sh, sh -c, or bash -c. It detects suspicious post-condition behavior consistent with exploitation attempts for CVE-2026-48703 and CVE-2026-48731
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
4110
https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
24029
This query detectsvinbound web requests containing a suspicious Content-Security-Policy or Content-Security-Policy-Report-Only request header with signs of nonce attribute breakout and JavaScript/data URI injection
avatar
Syed Usfar Wasim@nCD24
avatar
Detections.ai Community
3 months ago
104
Page 3 of 4