EXPLORE

EXPLORE DETECTIONS

🔍
581 detections found

Disabled Account Attack Disruption

Attack disruption disabled a cloud/hybrid account due to suspicious activities. The query lists the accounts that have been disabled by MDI.

KQL

Disabling Global Secure Access by Registry

or ActionType == "RegistryKeyCreated"

KQL

Discovering potentially tampered devices [Nobelium]

To evade security software and analyst tools, Nobelium malware enumerates the target system looking for certain running processes, loaded drivers, and registry keys, with the goal of disabling them.

KQL

Display Teams participation duration of account associated with a suspicious IP address

Query is from CISA Playbook https://www.cisa.gov/sites/default/files/2025-01/microsoft-expanded-cloud-logs-implementation-playbook-508c.pdf

KQL

Domain federation trust settings modified

This query will find when federation trust settings are changed for a domain or when the domain is changed from managed to federated authentication. Results will relate to when a new Active Directory Federated Service (ADFS) TrustedRealm object, such as a signing certificate, is added.

T1484.002
KQL

Due Date Passed CISA Known Exploited Vulnerabilities

CISA provides a comprehensive list of known exploited vulnerabilities with CVE numbers, vendor names, product names, vulnerability names, dates, short descriptions, action due dates, and notes. This dynamic list is ingested into a KQL query to detect newly added known exploited vulnerabilities that are active in your environment.

KQL

Email Events from Email Providers

A list of all email provider domains (free, paid, blacklist etc). Some of these are probably not around anymore. I've combined a dozen lists from around the web. Current "major providers" should all be in here as of the date this is created.

KQL

EmailEvents - Sender TLD count

', SenderFromDomain), "/")[0]))

KQL

Emotet Domain IOC Feed

Emotet Domain IOC Feed

KQL

Emotet SHA256 IOC Feed

Emotet SHA256 IOC Feed

KQL

End of Life Software with File Paths using TVM

KQL

End of Support software used

End of Support software used

KQL

Entra - Auditing TenantRestrictionsV2 Events

This query looks for when a user tries to sign-in into a tenant that is not approved by a Tenant's Tenant Restriction Policy. There will be a log in Tenant A and Tenant B.

KQL

Entra Account Disabled

KQL

Entra Group Changes

KQL

Entra Identify and Map Authentication Context Usage

Full credit goes to https://www.chanceofsecurity.com/post/mastering-microsoft-entra-authentication-contexts-part-4-monitoring-and-reporting. I did not write this query

KQL

Entra Password Resets

KQL

Entra Sign-ins to Legacy Azure Active Directory Powershell

KQL

Entra Smart Lockout Tampering

KQL

EntraIdSignInEvents - Hunting Potential Seamless SSO Usage

This query is a replacement to https://github.com/jkerai1/KQL-Queries/blob/main/Defender/AADSignInEventsBeta%20-%20Hunting%20Potential%20Seamless%20SSO%20Usage.kql

KQL

EntraIdSignInEvents - Suspicious User agent

This query is the update to https://github.com/jkerai1/KQL-Queries/blob/main/Defender/AADSignInEventsBeta%20-%20Suspicious%20User%20agent.kqlhttps://github.com/jkerai1/KQL-Queries/blob/main/Defender/AADSignInEventsBeta%20-%20Suspicious%20User%20agent.kql

KQL

Exchange PowerShell snap-in being loaded

This query was originally published in the threat analytics report, "Exchange Server zero-days exploited in the wild".

KQL

Exchange Server IIS dropping web shells and other artifacts

This query was originally published in the threat analytics report, "Exchange Server zero-days exploited in the wild".

KQL

Exchange vulnerability creating web shells via UMWorkerProcess

This query was originally published in the threat analytics report, "Exchange Server zero-days exploited in the wild".

KQL
PreviousPage 9 of 25Next