avatar

Andre Zeemering

@Azeemering
Amsterdam, NetherlandsTrusted contributor
5 followers84 downloads192 copies27 likes2,566 views

18 detections

Identify cases where privileged tokens appear in unexpected contexts (e.g., admin accounts logging into low-tier devices, unusual logon types, or rare hosts).
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
14 days ago
204
If your environment does not normally use smart cards or certificate-based authentication, or if a user who does not typically authenticate using smart cards suddenly generates events with TokenHasThisOrgCertificateSid, this may warrant investigation, as it could indicate authentication using a fraudulently issued certificate.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
14 days ago
002
A standard user who suddenly logs on with TokenHasDomainAdminSid is a red flag for potential token manipulation or group membership abuse.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
14 days ago
001
Detects suspicious registry modifications that disable the shutdown button on a user's logon screen. It leverages data from the Endpoint.Registry data model, specifically monitoring changes to registry paths associated with shutdown policies. This activity is significant because it is a tactic used by malware, particularly ransomware like KillDisk, to hinder system usability and prevent the removal of malicious changes. If confirmed malicious, this could impede system recovery efforts, making it difficult to restart the machine and remove other harmful modifications.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
1 month ago
208
This use case detects a potential bypass of a conditional access policy. Most likely bypass would be your MFA policy, bypassing multi factor authentication via some sort of vulnerability or misconfiguration.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
3 months ago
14014
This rule detects the connection of USB devices identified as suspicious based on a curated list of Vendor IDs (VIDs) and Product IDs (PIDs). It monitors 'PnpDeviceConnected' events, extracts VID and PID from the device information, and cross-references them with an external list of known suspicious USB device identifiers. The rule aims to identify potentially malicious or unauthorized USB devices being connected to endpoints.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
4 months ago
12332
Detects high-impact phishing campaigns identified by Microsoft Defender for Office 365. Alerts when a campaign (CampaignName, CampaignId) targets 25 or more recipients (RecipientEmailAddress) within 48 hours, providing timestamp and message details (NetworkMessageId) for investigation.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
8 months ago
9082
This query hunts for inbound emails that contain URLs embedded in QR codes and originate from senders that are not commonly observed in the environment, a common technique used in QR-based phishing campaigns.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
8 months ago
141230
Detects the modification of registry keys to disable Windows Defender Credential Guard. Disabling this security feature can expose credentials to theft and is a common precursor to lateral movement.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
8 months ago
18095
Detects UserAccountBroker.exe being spawned by explorer.exe, which is an unusual parent-child relationship. The rule is enriched by looking for subsequent outbound network connections from the UserAccountBroker.exe process, a behavior observed in ValleyRAT infections.
avatar
Andre Zeemering@Azeemering
avatar
Detections.ai Community
8 months ago
5083