• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    KRSID/UBP Asset Campaign IOC Hunt (Hashes, Domains, URL)

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Arnold Chan@slaz
    •updated 19 days ago•0•0•0

    This rule monitors for known malicious file hashes (MD5) and network traffic (domains and specific URLs) associated with known threats. It aggregates events from DeviceFileEvents, DeviceProcessEvents, and DeviceNetworkEvents to identify potential interactions with threat infrastructure.

    Microsoft Sentinel (KQL)

    Tags

    T1566 - PhishingT1071 - Application Layer ProtocolT1204 - User ExecutionTA0002 - ExecutionFile EventProcess EventNetwork Connection OutboundWindowsWindows Defender Atpkql

    Found in

    • KRSID Ransomware Distributed via Fraudulent Private HTSLast updated 19 days ago
    • KRSID Ransomware Distributed via Fraudulent Private HTSLast updated 19 days ago
    • KRSID Ransomware Distributed via Fraudulent Private HTSLast updated 19 days ago
    • KRSID Ransomware Distributed via Fraudulent Private HTSLast updated 19 days ago
    • KRSID Ransomware Distributed via Fraudulent Private HTSLast updated 19 days ago

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?