๐๐๐ป๐๐ถ๐ป๐ด ๐๐๐๐ ๐ฅ๐ฒ๐ฝ๐น๐ฎ๐ ๐๐๐๐ฎ๐ฐ๐ธ๐ ๐ฎ๐ป๐ฑ ๐๐ป๐ณ๐ฟ๐ฎ๐๐๐ฟ๐๐ฐ๐๐๐ฟ๐ฒ ๐๐๐ถ๐ป๐ด ๐๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ฒ๐ฟ๐ซ๐๐ฅ
www.linkedin.com/pulse/defend...
Posts by Steven Lim
๐ ๐ก๐ผ๐๐ฒ๐ฝ๐ฎ๐ฑ++ ๐๐ถ๐ท๐ฎ๐ฐ๐ธ๐ฒ๐ฑ ๐ฏ๐ ๐ฆ๐๐ฎ๐๐ฒ-๐ฆ๐ฝ๐ผ๐ป๐๐ผ๐ฟ๐ฒ๐ฑ ๐ง๐ต๐ฟ๐ฒ๐ฎ๐ ๐๐ฐ๐๐ผ๐ฟ
Heads up, defenders: a supply chain compromise targeting Notepad++ has been linked to state-sponsored activity. Here's a Sentinel KQL to help you hunt for potentially affected endpoints๐ซก
github.com/SlimKQL/Hunt...
LDAPNightmare POC Detection
www.safebreach.com/blog/ldapnig...
Custom detection code:
github.com/SlimKQL/Hunt...
Custom detection code:
github.com/SlimKQL/Hunt...
๐๐๐๐๐ผ๐บ ๐๐ฒ๐ณ๐ฒ๐ป๐ฑ๐ฒ๐ฟ๐ซ๐๐ฅ ๐๐ฒ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป - ๐๐น๐ผ๐ฐ๐ธ๐ถ๐ป๐ด 2๏ธโฃ4๏ธโฃ ๐ ๐ฎ๐น๐ถ๐ฐ๐ถ๐ผ๐๐ ๐๐ต๐ฟ๐ผ๐บ๐ฒ ๐๐
๐๐ฒ๐ป๐๐ถ๐ผ๐ป๐๐ก๏ธ
www.extensiontotal.com/cyberhaven-i...
Hunting 16 Malicious Chrome Extension๐ฅ
thehackernews.com/2024/12/16-c...
github.com/SlimKQL/Hunt...
๐จ Reports suggest US authorities may ban TP-Link Wi-Fi routers in 2025. Regulated industries, ensure your end users aren't connected to TP-Link routers. Use MDE discovery and DefenderXDR's SeenBy() to detect connections. ๐ก๏ธ๐ก
Advanced Vishing KQL Detection by sending your Teams PSTN call log to ADX ๐ฏ
www.trendmicro.com/en_us/resear...
Thanks! :) The threat actor social engineering attacks are targeting normal business users, uers with role are technical in nature and tend not to follow these type of instruction, hence I exclude this group of privilege roles users.
PowerShell Self-Pwn Detection
Proofpoint highlights a social engineering tactic where users are tricked into running malicious PowerShell scripts, leading to malware infections. Despite needing user interaction, the attack's success relies on clever social engineering.
Detecting Teams Red Team Tool ConvoC2
cybersecuritynews.com/red-team-too...
SentinelLab observed threat actor targeting service providers in Southern Europe abusing Visual Studio Code tunnels to maintain persistent remote access to compromised systems. www.bleepingcomputer.com/news/securit... KQL to detect such abuse.
Detect Black Basta Ransomware Campaign RMMTools Deployment - Social Engineering Attack via Teams where the ransomware operator sends a SharePoint link to user to download portable RMM tools to evade detection from web proxy. www.rapid7.com/blog/post/20...
Thank you! ๐๐
The KQL Grimoire ๐
A collection of the most sought-after KQL spells for Microsoft Sentinel and DefenderXDR
www.linkedin.com/pulse/slims-...
๐ก๐ฒ๐ ๐จ๐ฅ๐ ๐๐ถ๐น๐ฒ ๐ก๐ง๐๐ ๐๐ฎ๐๐ต ๐๐ถ๐๐ฐ๐น๐ผ๐๐๐ฟ๐ฒ ๐ฉ๐๐น๐ป๐ฒ๐ฟ๐ฎ๐ฏ๐ถ๐น๐ถ๐๐ ๐๐ฒ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป (0๏ธโฃ๐ฑ๐ฎ๐)
A highly accurate DefenderXDR exposure management detection for URL File NTLM Hash Disclosure Vulnerability (0day) www.bleepingcomputer.com/news/securit...
github.com/SlimKQL/Hunt...
In AD environments, Timeroasting exploits NTP authentication to request password hashes of computer/trust accounts. If non-standard or legacy passwords are used, offline brute-forcing is possible. I've created a KQL query to detect such activities. #KQL #Timeroast
github.com/SlimKQL/Hunt...
Sharing a Sentinel KQL detection for ShadowHound by Friends-Security, which enhances AD enumeration for security assessments. Beware: it can be misused by threat actors & red teamers for reconnaissance. My KQL rule helps identify and mitigate these risks. #KQL #ShadowHound
Hunting Rockstar 2FA: A Key Player in Phishing-as-a-Service (PaaS)
www.trustwave.com/en-us/resour...
Social Engineering Attack Alert - Teams & Emails
Kevin Beaumont shared insights on helping orgs recover from ransomware attacks. Key tactic: social engineering. Attackers used phone recon to gather contacts, then flooded users with emails & Teams messages. Custom KQL script for early detection:
CloudApp BEC Defense Policy - Axios
Attackers bypass MFA using a phishing framework with Axios HTTP client. Detect compromise in sign-in logs with user agent axios/1.7.7. Proposing auto-detection & isolation for SecOps assessment.
Sources: Asger Deleuran Strunk / Stephan Berger
๐ง๐ต๐ฒ ๐ฃ๐ฒ๐ฟ๐ณ๐ฒ๐ฐ๐ ๐๐๐๐๐ผ๐บ ๐๐ฒ๐๐ฒ๐ฐ๐๐ถ๐ผ๐ป ... ๐
Using CloudApp & Behaviour Analytics to detect malicious threat actor Copilot Agent.
#Cybersecurity #DefenderXDR #CloudApp #CopilotAgent #KQL