
Udi B
@UdiAotearoa | New Zealand
0 followers3 downloads147 copies2 likes441 views
21 detections
Filters
Last updated
All Time
Detection languages
21
Categories
10
5
5
3
3
Platforms
10
10
8
4
1
Products / Services
15
6
3
3
3
MITRE Techniques
9
6
5
4
4
Tracks changes and activities affecting a specific user account across both on-premises Active Directory and Microsoft Entra ID. The query combines Windows Security Events and Entra ID Audit Logs into a single timeline, making it easier to investigate account modifications, privilege changes, MFA updates, directory synchronization activity, and administrative actions impacting a user.
This detection is particularly useful during incident response, insider threat investigations, account compromise assessments, and user lifecycle reviews
This detection is particularly useful during incident response, insider threat investigations, account compromise assessments, and user lifecycle reviews
Correlates email delivery, URL click telemetry, endpoint network connections, and process execution evidence for one or more suspicious URLs or domains.
This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.
It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.
The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
This query helps analysts identify who received an email containing a target URL, who clicked it, whether the URL was observed on managed endpoints, which devices were involved, and what processes initiated related network or command-line activity.
It is useful for phishing investigations, malicious URL exposure reviews, post-delivery impact checks, campaign scoping, and confirming whether a user interaction led to endpoint activity.
The query uses Microsoft Defender XDR advanced hunting tables including EmailUrlInfo, EmailEvents, UrlClickEvents, DeviceNetworkEvents, and DeviceProcessEvents. Microsoft documents UrlClickEvents as containing Safe Links click information from email messages, Teams, and Office apps, populated by Defender for Office 365.
Identifies potentially suspicious email forwarding configurations, mailbox permission assignments, transport rule changes, and delegate access grants that could enable unauthorized email access or data exfiltration.
The query correlates multiple Microsoft 365 audit activities including:
Inbox forwarding rules
SMTP mailbox forwarding
Transport rule forwarding
Delegate mailbox access assignments
Removed or disabled forwarding configurations
This helps detect common Business Email Compromise (BEC) techniques where attackers establish persistence by forwarding mail to external addresses or granting unauthorized mailbox access.
The query correlates multiple Microsoft 365 audit activities including:
Inbox forwarding rules
SMTP mailbox forwarding
Transport rule forwarding
Delegate mailbox access assignments
Removed or disabled forwarding configurations
This helps detect common Business Email Compromise (BEC) techniques where attackers establish persistence by forwarding mail to external addresses or granting unauthorized mailbox access.
Inbound email campaigns containing links to external personal SharePoint sites (*-my.sharepoint.com) sent to multiple recipients.
Finds Microsoft Sentinel analytics rules that generate high volumes of non-actionable closed incidents. The query calculates false positive, benign positive, undetermined, and true positive rates per rule, then provides practical tuning recommendations to help SOC and detection engineering teams reduce alert fatigue.
Identifies Microsoft Entra Privileged Identity Management (PIM) role activations occurring outside normal business hours or during weekends.
The query reviews role management audit events, converts timestamps to a defined local timezone, and highlights successful privileged role activations that occur outside business hours and on weekends.
This detection helps security teams identify unusual, privileged access activity that may warrant additional investigation, especially for highly privileged roles.
The query reviews role management audit events, converts timestamps to a defined local timezone, and highlights successful privileged role activations that occur outside business hours and on weekends.
This detection helps security teams identify unusual, privileged access activity that may warrant additional investigation, especially for highly privileged roles.
Provides a consolidated view of email metadata, delivery outcomes, attachments, embedded URLs, sender infrastructure, and security verdicts for inbound and outbound email investigations.
The query enriches email events with attachment and URL data, allowing analysts to quickly assess:
Sender and recipient information
Delivery actions
Phishing and spam verdicts
URLs contained within messages
Attached files and hashes
Threat classifications
Sender IP infrastructure
This query is useful for phishing investigations, malware delivery analysis, threat hunting, and message trace reviews.
The query enriches email events with attachment and URL data, allowing analysts to quickly assess:
Sender and recipient information
Delivery actions
Phishing and spam verdicts
URLs contained within messages
Attached files and hashes
Threat classifications
Sender IP infrastructure
This query is useful for phishing investigations, malware delivery analysis, threat hunting, and message trace reviews.
This rule monitors Microsoft 365 SharePoint and OneDrive audit logs for the 'SharingSet' operation to detect when internal items are shared with external guests. It classifies sharing events based on permission level and site type (Personal vs. SharePoint site) to highlight potentially high-risk external collaboration.
Correlates Microsoft Sentinel Security Alerts and Security Incidents associated with a specific user account over a 90-day period. The query identifies medium and high-severity alerts, maps them to their corresponding incidents, and provides investigation outcomes including classification, closure details, and ownership information.
This detection enables analysts to quickly understand a user's historical security exposure, determine whether previous incidents were resolved appropriately, and identify patterns of recurring security activity.
This detection enables analysts to quickly understand a user's historical security exposure, determine whether previous incidents were resolved appropriately, and identify patterns of recurring security activity.
Aggregates identity, endpoint, cloud application, and messaging telemetry to build a consolidated profile of the devices, clients, applications, and user agents associated with a specific user account.
The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.
This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
The query combines Microsoft Entra sign-in data, endpoint logon activity, cloud application events, and email telemetry to provide a high-level overview of a user's activity footprint across the environment.
This query is useful for incident response, account compromise investigations, insider threat investigations, and validating whether a user is accessing services from expected devices and client applications.
Page 1 of 3
