
Collin Lairamore
@BollinmoreTrusted contributorCompletionist
2 followers36 downloads231 copies8 likes5,347 views
63 detections
Filters
Last updated
All Time
Detection languages
54
7
2
Categories
11
10
10
9
8
Platforms
36
14
10
3
1
Products / Services
8
7
7
6
5
MITRE Techniques
8
7
6
6
5
CVEs
1
IDS Classtypes
7
1
IDS Protocols
4
3
2
Suspicious Connection to Custom GPT
Cortex XDR
Detects outbound web traffic to OpenAI ChatGPT Custom GPTs where the URL slug contains keywords potentially indicative of unauthorized or non-standard usage, such as keywords implying premium, professional, or official status, which could be used as a cover for data exfiltration or credential gathering via malicious or typo-squatted GPT instances.
Ranks parent/child process pairs by lift, meaning how much less often the two co-occur than their individual frequencies would predict, so that no single high-volume parent can dominate the results. Sorting on P(child|parent) alone does not work for this pair. In most environments a handful of interpreters and service hosts account for a large share of all process starts, and every rare child of those parents scores lower than any other pairing, burying the classic Office-spawns-a-shell cases. The reciprocal of lift reads directly as "this pairing is N times rarer than chance."
The parent is keyed on normalized directory plus image name rather than name alone, so the many distinct binaries called updater.exe or setup.exe remain separate and any hit is immediately attributable to a specific file. Parent paths are normalized before counting (user profiles, version and GUID directories, temp scratch folders) because unnormalized paths split every per-user and per-version copy into its own identity and manufacture false rarity.
Universal children (conhost.exe, werfault.exe, wermgr.exe) are excluded. They appear beneath nearly every parent, so their very large baselines float any parent that rarely spawns them to the top on arithmetic alone, with no signal behind it.
TUNING
Thresholds are n_b (parent baseline), n_a (child baseline) and n_ab (pair rarity). The probability metrics are derived from these and need no separate cutoff. Set the parent floor well below what you would use for a name-keyed hunt, because keying on path fragments each parent's baseline across its install locations, and a floor tuned for pooled names will silently drop tools that deploy a copy of themselves into every directory they serve. Calibrate by checking the distribution of distinct paths per image name in your own data before setting it.
BLIND SPOT
A masqueraded or newly planted binary has no path baseline of its own, so its parent count is tiny and the floor removes it. Pooling by image
The parent is keyed on normalized directory plus image name rather than name alone, so the many distinct binaries called updater.exe or setup.exe remain separate and any hit is immediately attributable to a specific file. Parent paths are normalized before counting (user profiles, version and GUID directories, temp scratch folders) because unnormalized paths split every per-user and per-version copy into its own identity and manufacture false rarity.
Universal children (conhost.exe, werfault.exe, wermgr.exe) are excluded. They appear beneath nearly every parent, so their very large baselines float any parent that rarely spawns them to the top on arithmetic alone, with no signal behind it.
TUNING
Thresholds are n_b (parent baseline), n_a (child baseline) and n_ab (pair rarity). The probability metrics are derived from these and need no separate cutoff. Set the parent floor well below what you would use for a name-keyed hunt, because keying on path fragments each parent's baseline across its install locations, and a floor tuned for pooled names will silently drop tools that deploy a copy of themselves into every directory they serve. Calibrate by checking the distribution of distinct paths per image name in your own data before setting it.
BLIND SPOT
A masqueraded or newly planted binary has no path baseline of its own, so its parent count is tiny and the floor removes it. Pooling by image
Surfaces binaries executing from directories they almost never use, by computing pair probabilities across process-start events rather than matching signatures. For each (binary, normalized directory) pair it derives P(A|B) -- of all times this binary ran, what fraction ran from here and ranks ascending, so a binary with thousands of executions appearing once somewhere unexpected rises to the top. Execution paths are normalized first (user profiles, WinSxS versions, GUID/hex/temp directories, version folders) so per-install variance does not manufacture false rarity.
Tuned at n_b >= 10000, n_ab <= 5 over a 7-day window; scale n_b with fleet volume. Rarity is not maliciousness: triage by
directory writability, whether the binary has a fixed legitimate home, and host count, then pull parent process for anything that clears the bar.
Tuned at n_b >= 10000, n_ab <= 5 over a 7-day window; scale n_b with fleet volume. Rarity is not maliciousness: triage by
directory writability, whether the binary has a fixed legitimate home, and host count, then pull parent process for anything that clears the bar.
Pairs the connecting process against the remote destination port and ranks by lift, meaning how much less often the two co-occur than their individual frequencies would predict. The target shape is a process with a large network baseline that has touched a given service port once or twice: a browser or office application reaching SMB, RDP, SSH or WinRM, or an observability agent speaking a protocol outside its purpose. Those pairings are lateral movement or credential access wearing a familiar process name.
The process is keyed on normalized directory plus image name rather than name alone, so distinct binaries sharing a name stay separate and any hit is attributable to a specific file. The kernel-mode System process is preserved by falling back to the image name when no path exists, because System on SMB is meaningful client activity and dropping it would be a real coverage loss.
PORT HANDLING
Ephemeral ports are cut. On inbound connections the remote port is drawn from the dynamic range, so every one appears unique and produces tens of thousands of meaningless rare pairings; an inbound source port carries no information.
Universal ports are excluded: HTTPS, HTTP and DNS, plus the discovery and broadcast protocols (mDNS, LLMNR, NetBIOS, SSDP, WS-Discovery) and optionally LDAP and Global Catalog. Their baselines are large enough that any process which rarely touches them floats to the top on arithmetic alone, and "this application made one HTTPS call" is not a finding.
WATCH FOR SHARED BASELINES
When a port exists to serve one application, that port's baseline and the application's baseline are the same flows. Any third process meeting that port then produces the largest possible denominator and ranks first while being entirely benign. Compare the port's total against the dominant process's total; if they match closely, treat pairings on that port as suspect ranking rather than signal.
TUNING
Thresholds are the port baseline, the process baseline, and the pair
The process is keyed on normalized directory plus image name rather than name alone, so distinct binaries sharing a name stay separate and any hit is attributable to a specific file. The kernel-mode System process is preserved by falling back to the image name when no path exists, because System on SMB is meaningful client activity and dropping it would be a real coverage loss.
PORT HANDLING
Ephemeral ports are cut. On inbound connections the remote port is drawn from the dynamic range, so every one appears unique and produces tens of thousands of meaningless rare pairings; an inbound source port carries no information.
Universal ports are excluded: HTTPS, HTTP and DNS, plus the discovery and broadcast protocols (mDNS, LLMNR, NetBIOS, SSDP, WS-Discovery) and optionally LDAP and Global Catalog. Their baselines are large enough that any process which rarely touches them floats to the top on arithmetic alone, and "this application made one HTTPS call" is not a finding.
WATCH FOR SHARED BASELINES
When a port exists to serve one application, that port's baseline and the application's baseline are the same flows. Any third process meeting that port then produces the largest possible denominator and ranks first while being entirely benign. Compare the port's total against the dominant process's total; if they match closely, treat pairings on that port as suspect ranking rather than signal.
TUNING
Thresholds are the port baseline, the process baseline, and the pair
System File Execution Location Anomaly
Cortex XDR
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
Detects instances where a host that is not identified as a Domain Controller performs a DRSUAPI 'DRSGetNCChanges' request against another Domain Controller. This pattern is commonly associated with DCSync attacks, where an adversary mimics the Active Directory replication process to extract password hashes.
Process Spawns Multiple Recon Processes
Cortex XDR
Detect or threat hunt for a burst of Windows built-in discovery/reconnaissance utilities (Seven or more distinct tools within a single day) executed under one causality chain on one host, consistent with post-exploitation situational awareness by an interactive operator, script, or C2 implant.
System File Execution Location Anomaly
Cortex XDR
Detects Windows system binaries and commonly abused native LOLBins executing from outside their expected system directories, indicating a renamed, relocated, or imposter copy consistent with masquerading, DLL side-loading staging, or process-name spoofing.
Detects OAuth applications receiving permissions to the tenant, used for persistence and data theft. A consented app holds its own token and survives password resets and MFA, which is why consent phishing and post-compromise app registration are favored by both commodity BEC actors and nation-state (PerfectData is linked to Midnight Blizzard / APT29). Tiered: a hardcoded list of known-abused app IDs (PerfectData, eM Client, rclone, Supermailer, and others), layered over a scope-characteristic tier that catches bespoke apps by the permissions they request (Mail/EWS, Files/Sites, Directory, Application, offline_access), with admin/AllPrincipals consent escalating blast radius. Parses all three consent event shapes and resolves app identity across them.
Page 1 of 7
