EXPLORE

EXPLORE DETECTIONS

🔍
581 detections found

Detect malicious documents associated with group known as "OceanLotus"

This query was originally published in a threat analytics report about the group known to other security researchers as *APT32* or *OceanLotus*

KQL

Detect malicious network activity associated with group known as "OceanLotus"

This query was originally published in a threat analytics report about the group known to other security researchers as *APT32* or *OceanLotus*

KQL

Detect malicious use of Msiexec

This query was originally published in the threat analytics report, *Msiexec abuse*.

KQL

Detect malicious use of RegAsm, RegSvcs, and InstallUtil by Snip3

Snip3 is a family of related remote access trojans. Although the malware in this family contain numerous small variations, they all exhibit similar behaviors and techniques.

KQL

Detect nbtscan activity

This query was originally published in the threat analytics report, *Operation Soft Cell*.

KQL

Detect net(1).exe Discovery Activities

This query can be used to detect suspicious net.exe or net1.exe activities that have been executed by a account. The parameters that are to detect this behaviour are:

T1069T1087T1201
KQL

Detect new RDP connections

Detect new RDP connections to devices that have not been established in the past 20 days

KQL

Detect Office products launching wmic.exe

This query was originally published in the threat analytics report, *Ursnif (Gozi) continues to evolve*.

T1047
KQL

Detect potential ConsentFix OAuth authorisation code theft attempts

Query from https://sentinel.blog/consentfix-securing-your-tenant-against-oauth-authorisation-code-theft/

KQL

Detect potentially malicious .jse launch by File Explorer or Word

This query was originally published in the threat analytics report, *Emulation-evading JavaScripts*.

KQL

Detect potentially unwanted activity from ironSource bundlers

This query was originally published in the threat analytics report, *ironSource PUA & unwanted apps impact millions*.

KQL

Detect PsExec being used to spread files

This query was originally published in the threat analytics report, *Ryuk ransomware*. There is also a related [blog](https://www.microsoft.com/security/blog/2020/03/05/human-operated-ransomware-attacks-a-preventable-disaster/).

KQL

Detect rundll.exe being used for reconnaissance and command-and-control

This query was originally published in the threat analytics report, *Trickbot: Pervasive & underestimated*.

KQL

Detect security evasion related to the Robbinhood ransomware campaign

This query was originally published in the threat analytics report, *Ransomware continues to hit healthcare, critical services*. There is also a related [blog](https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/).

KQL

Detect SMB File Copies

Adversaries can use SMB to upload files to remote shares or to interact with files on those shares. A common technique is to upload malcious to remote host. This query detects all SMB file copies. In order to run the query effectively add the benign accounts the the whitelist.

T1021.002T1021
KQL

Detect Snip3 associated communication protocols

Snip3 is a family of related remote access trojans. Although the malware in this family contain numerous small variations, they all exhibit similar behaviors and techniques.

KQL

Detect Snip3 loader call to DetectSandboxie function

Snip3 is a family of related remote access trojans. Although the malware in this family contain numerous small variations, they all exhibit similar behaviors and techniques.

KQL

Detect Snip3 loader-encoded PowerShell command

Snip3 is a family of related remote access trojans. Although the malware in this family contain numerous small variations, they all exhibit similar behaviors and techniques.

KQL

Detect suspicious commands initiated by web server processes

This query was originally published in the threat analytics report, *Operation Soft Cell*.

KQL

Detect suspicious Mshta usage

This query was originally published in the threat analytics report, *Ursnif (Gozi) continues to evolve*.

T1170
KQL

Detect suspicious RDP activity related to BlueKeep

This query was originally published in the threat analytics report, *Exploitation of CVE-2019-0708 (BlueKeep)*.

KQL

Detect the use of a new Sysinternal tool

Detect the use of a new Sysinternal tool that has not been used in the last 90 days (in the case of Defender XDR 30 days).

KQL

Detect Tor DNS request

Credit: Suraj Kumar. Modified from his query

KQL

Detect use of Alternate Data Streams

This query was originally published in the threat analytics report, *Ransomware continues to hit healthcare, critical services*. There is also a related [blog](https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/).

KQL
PreviousPage 7 of 25Next