
Syed Usfar Wasim
@nCD24DeutschlandCompletionist
0 followers5 downloads452 copies12 likes779 views
38 detections
Filters
Last updated
All Time
Detection languages
38
Categories
4
2
2
2
2
Platforms
18
8
3
2
2
Products / Services
4
3
3
1
1
MITRE Techniques
7
6
6
6
6
CVEs
1
1
1
1
1
IDS Classtypes
2
1
Detects high-confidence BoryptGrab-lineage infostealer activity involving fake GitHub delivery indicators, known C2 infrastructure, suspicious gup.exe execution, libcurl.dll side-loading from user-writable paths, and known malicious file hashes.
This KQL detects potential Microsoft Defender tampering via PowerShell, including attempts to disable real-time or behavior monitoring and add Defender exclusions. It enriches results with tamper type, suspicious PowerShell flags, and confidence level to help prioritize medium/high-confidence activity.
This KQL detects activity associated with network traffic to known C2 infrastructure (45.146.252.17), suspicious Node/NPM execution chains and dropped payload/marker files. Also looks for indicators of remote control, clipboard access, screenshot/desktop-control packages, Socket.IO C2 traffic, and file/browser/wallet data exfiltration behavior.
This detects a suspicious process pattern where "svchost.exe -> svchost.exe -k DHCPServer" running under the Network Service account.
Detects rundll32.exe making outbound network connections to public IP addresses, excluding cases where the parent process is svchost.exe. This indicates the abuse of "rundll32.exe" as a proxy execution binary for defense evasion, payload execution, or suspicious network communication.
Detects suspicious execution of tools or command lines associated with DPAPI domain backup key extraction, including mimikatz, SharpDPAPI, lsadump::backupkeys, and related backupkey commands. This behavior may indicate an attempt to obtain the domain DPAPI backup key from a Domain Controller, enabling decryption of DPAPI-protected secrets across the domain.
This query detects non-browser processes making network connections to .shop or .xyz domains which could possibly pertain to phishing, malware delivery, tracking, ad fraud, or command-and-control.
This query hunts for suspicious cases where Warp Terminal or a Warp-related parent process spawns Unix-like shell interpreters such as sh, bash, zsh, fish, or dash, and executes commands using shell execution patterns like -c, /bin/sh, sh -c, or bash -c. It detects suspicious post-condition behavior consistent with exploitation attempts for CVE-2026-48703 and CVE-2026-48731
https://www.okta.com/en-au/blog/threat-intelligence/vishing-actors-target-microsoft-entra-passkey-enrollment-/
This query detectsvinbound web requests containing a suspicious Content-Security-Policy or Content-Security-Policy-Report-Only request header with signs of nonce attribute breakout and JavaScript/data URI injection
Page 3 of 4
