Skip to content

Some custom KQL for detecting malicious staff

Notifications You must be signed in to change notification settings

palangui/KQL_hunting

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

9 Commits
 
 
 
 

Repository files navigation

KQL_hunting

Repository of custom-made queries that have been useful to detect interesting things (malware / red-teams) from Defender. I will update it little by little

  • Potential DLL Order Hijacking
  • Suspicious DLL loaded in the address space of Rundll32
  • Exfiltracion with rclone, megasync, stealbith
  • Check persistence with Anydesk, Atera, Splashtop
  • Connections from rundll32.exe with no command line
  • Ngrok connections

About

Some custom KQL for detecting malicious staff

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published