avatar

Rory Wagner

@Sleuthifer
Completionist
2 followers37 downloads152 copies29 likes1,521 views

9 detections

This detection/hunting query identifies Chromium-based browser extensions matching known malicious extension IDs from the ExtSentry IOC feed. Adversaries and commodity malware families sideload extensions to steal session cookies, intercept credentials, and maintain persistence inside the browser, where the activity survives endpoint remediation that does not touch the browser profile. The rule covers three installation paths: files written to the extension directories, registry registration and policy-based force-install, and command-line sideloading via --load-extension. Wallet and password manager extensions are excluded upstream as sensitive rather than malicious.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 month ago
652122
Identifies core Windows subsystem binaries executing from any location other than System32. Binaries such as lsass.exe, winlogon.exe, services.exe and svchost.exe are never legitimately relocated or bundled by third-party software, so execution from an unexpected path indicates an adversary has placed a renamed or copied payload to blend in with normal process listings.

The detection uses a composite name-and-path key rather than checking either value independently, which catches relocation while permitting the genuine SysWOW64 copy of svchost.exe. Device paths reported by early-boot processes are normalised rather than excluded so that a genuine hit from a device path still fires. Scope is limited to Windows endpoints via DeviceInfo.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
2 months ago
1016
This KQL query identifies file creation events within common Windows startup directories and enriches them with Windows Shell Link (shortcut) creation activity.

Startup folders are frequently abused by adversaries for persistence since files or shortcuts placed here automatically execute at user login. The query covers both system-wide and user-specific startup paths and can exclude known legitimate items via an exclusion list to reduce false positives.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
8 months ago
336219
This detection monitors the CommonSecurityLog (which adheres to the Common Event Format - CEF) for indications of malicious network activity. Specifically, it flags outgoing HTTP requests originating from system utilities such as curl, wget, and PowerShell. These requests are often leveraged by attackers for data theft (exfiltration) or establishing command-and-control channels.

Review the full user agent string and destination hostname. Investigate the source IP and user context. Check whether the tool usage aligns with expected behavior for the host or user. Correlate with other indicators such as unusual process execution, file access, or authentication anomalies. Escalate if the destination is unknown or suspicious. Remove the KQL summarise line to view more details.

UA_Check and SafeHosts will require tuning for your specific environment setup and traffic.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
102430
This KQL query detects the activation or modification of Guest accounts or Guest group memberships, which may indicate unauthorized access attempts or privilege escalation.

Analysts should review the initiating user (SubjectUserName) and process context. Confirm whether the Guest account is expected to be active on the system. Investigate the host for signs of lateral movement or privilege abuse. Correlate with logon events and group membership changes. Escalate if Guest account activation is unexpected or unauthorized.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
73349
Detecting LOLDrivers using www.loldrivers.io and MDE telemetry.

This rule was created by Mehmet Ergene from BluRaven Academy and added to Detections.ai as it was missing from the repository.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
247180
Detects suspicious registry modifications for IFEO entries which can be used by attackers for persistence.

This is based off of testing with Atomic Red Team tests - https://www.atomicredteam.io/atomic-red-team/atomics/T1546.012
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
2187
This detection identifies attempts to establish persistence by modifying known Windows startup registry keys. These keys control which programs are automatically executed during system boot or user logon and are frequently abused by adversaries to maintain access across reboots.

Analysts will need to tune the rule through testing and using the exclusion statements to remove noise of what is known good within their environments.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
4359
This KQL detection is designed for use in Microsoft Defender for Endpoint Advanced Hunting or Microsoft Sentinel, depending on table availability.

It focuses on identifying two common persistence techniques used by threat actors:

COM hijacking via user-specific registry hives (InprocServer32 and LocalServer32), particularly when leveraged by .NET or PowerShell-based malware; and uncommon registry-based persistence through suspicious keys such as DelegateExecute, TreatAs, and ScriptletURL.

The KQL focusses on user-specific registry hives as they don't require elevated privileges to modify and is why we also ignore "nt authority" activity as this detection is focused on low hanging fruit that would be easily accessible to a threat actor initially for persistence without privilege escalation.
avatar
Rory Wagner@Sleuthifer
avatar
Detections.ai Community
1 year ago
6559