avatar

Udi B

@Udi
Aotearoa | New Zealand
0 followers3 downloads147 copies2 likes441 views

21 detections

Tracks changes and activities affecting a specific user account across both on-premises Active Directory and Microsoft Entra ID. The query combines Windows Security Events and Entra ID Audit Logs into a single timeline, making it easier to investigate account modifications, privilege changes, MFA updates, directory synchronization activity, and administrative actions impacting a user.

This detection is particularly useful during incident response, insider threat investigations, account compromise assessments, and user lifecycle reviews
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
32041
Correlates email delivery, URL click telemetry, endpoint network connections, and process execution evidence for one or more suspicious URLs or domains.

This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.

It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.

The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
15026
Identifies potentially suspicious email forwarding configurations, mailbox permission assignments, transport rule changes, and delegate access grants that could enable unauthorized email access or data exfiltration.

The query correlates multiple Microsoft 365 audit activities including:
Inbox forwarding rules
SMTP mailbox forwarding
Transport rule forwarding
Delegate mailbox access assignments
Removed or disabled forwarding configurations

This helps detect common Business Email Compromise (BEC) techniques where attackers establish persistence by forwarding mail to external addresses or granting unauthorized mailbox access.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
11021
Inbound email campaigns containing links to external personal SharePoint sites (*-my.sharepoint.com) sent to multiple recipients.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
5013
Finds Microsoft Sentinel analytics rules that generate high volumes of non-actionable closed incidents. The query calculates false positive, benign positive, undetermined, and true positive rates per rule, then provides practical tuning recommendations to help SOC and detection engineering teams reduce alert fatigue.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
6010
Identifies Microsoft Entra Privileged Identity Management (PIM) role activations occurring outside normal business hours or during weekends.

The query reviews role management audit events, converts timestamps to a defined local timezone, and highlights successful privileged role activations that occur outside business hours and on weekends.

This detection helps security teams identify unusual, privileged access activity that may warrant additional investigation, especially for highly privileged roles.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
7010
Provides a consolidated view of email metadata, delivery outcomes, attachments, embedded URLs, sender infrastructure, and security verdicts for inbound and outbound email investigations.

The query enriches email events with attachment and URL data, allowing analysts to quickly assess:
Sender and recipient information
Delivery actions
Phishing and spam verdicts
URLs contained within messages
Attached files and hashes
Threat classifications
Sender IP infrastructure

This query is useful for phishing investigations, malware delivery analysis, threat hunting, and message trace reviews.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
209
This rule monitors Microsoft 365 SharePoint and OneDrive audit logs for the 'SharingSet' operation to detect when internal items are shared with external guests. It classifies sharing events based on permission level and site type (Personal vs. SharePoint site) to highlight potentially high-risk external collaboration.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
608
Correlates Microsoft Sentinel Security Alerts and Security Incidents associated with a specific user account over a 90-day period. The query identifies medium and high-severity alerts, maps them to their corresponding incidents, and provides investigation outcomes including classification, closure details, and ownership information.

This detection enables analysts to quickly understand a user's historical security exposure, determine whether previous incidents were resolved appropriately, and identify patterns of recurring security activity.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
306
Aggregates identity, endpoint, cloud application, and messaging telemetry to build a consolidated profile of the devices, clients, applications, and user agents associated with a specific user account.

The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.

This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
avatar
Udi B@Udi
avatar
Detections.ai Community
2 months ago
105
Page 1 of 3