• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    RedLine Stealer Communication

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 23, 2026•0•0•5

    Detects network communication patterns indicative of RedLine Stealer activity by looking for specific keywords in the RemoteUrl field during inbound or outbound connections.

    Microsoft Sentinel (KQL)

    Tags

    S1029 - AuTo StealerS1213 - Lumma StealerS1153 - Cuckoo StealerT1071.001 - Web ProtocolsT1041 - Exfiltration Over C2 ChannelTA0011 - Command and ControlTA0010 - ExfiltrationNetwork ConnectionMalware DetectedWindowsWindows Defender Atpkql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?