
Benjamin Zulliger
@benschaTrusted contributorCompletionist
27 followers229 downloads1,603 copies143 likes20,763 views
55 detections
Filters
Last updated
All Time
Detection languages
55
Categories
19
10
9
8
8
Platforms
29
15
6
4
4
Products / Services
24
8
8
5
4
MITRE Techniques
24
20
19
18
16
CVEs
1
This rule detects the execution of script interpreters (such as PowerShell, cmd, bash, python, etc.) where the command line contains non-ASCII characters, specifically Cyrillic, Arabic, or Chinese Unicode characters. This pattern can be indicative of obfuscation techniques used by adversaries to evade detection or to target specific regions.
This rule detects suspicious command-line activity involving several Windows executables (wscript.exe, cscript.exe, wmic.exe, ssh.exe) when combined with specific keywords. It looks for wscript.exe or cscript.exe executing 'SyncAppvPublishingServer.vbs', wmic.exe executing 'process', 'call', or 'create', or ssh.exe using 'ProxyCommand'. Additionally, the rule filters for command lines containing keywords like 'gal', 'i*x', 'gcm', '*stM*', 'jsdelivr.net', 'github', or 'powershell', which are often associated with malicious activity, obfuscation, or external resource loading.
This rule detects suspicious outbound network connections from devices that exhibit a consistent timing pattern (low standard deviation relative to the average time delta between connections) to public IP addresses. It specifically looks for connections that are not initiated by common browsers unless they are running in headless mode, or connections initiated by processes with low global prevalence or identified as Living Off The Land Binaries (LOLBAS). This pattern can indicate automated activity, command and control communication, or data exfiltration.
This query identifies potential post-exploitation behavior on Linux systems by monitoring for clusters of discovery and enumeration commands. Instead of alerting on single, potentially benign commands, it utilizes a behavioral scoring engine that categorizes activities such as credential hunting, privilege escalation, and network scanning.
By implementing extensive allowlists for common administrative tools (e.g., Ansible, Zabbix, Monitoring Agents) and requiring a minimum threshold of unique activity categories, the query effectively filters out "noise." It calculates a dynamic Risk Score and assigns a Severity level based on the criticality of the commands and the speed of execution (Burst Detection), making it a highly reliable tool for SOC analysts to detect active hands-on-keyboard attacks.
By implementing extensive allowlists for common administrative tools (e.g., Ansible, Zabbix, Monitoring Agents) and requiring a minimum threshold of unique activity categories, the query effectively filters out "noise." It calculates a dynamic Risk Score and assigns a Severity level based on the criticality of the commands and the speed of execution (Burst Detection), making it a highly reliable tool for SOC analysts to detect active hands-on-keyboard attacks.
This query identifies users exhibiting unusual authentication behavior by combining Behavior Analytics with recent sign-in activity. It highlights high‑risk sign-ins originating from previously unseen IP addresses where the user agent or operating system has changed compared to historical patterns. The query enriches findings with historical sign-in context and Identity Info to support investigation of potentially compromised accounts.
Detects when a user generates an unusually high number of prompts to Copilot within a short period (e.g., 50 prompts in an hour). This could indicate automated activity, data exfiltration attempts, or misuse of the Copilot service.
This rule detects instances where a 'jailbreak' attempt is identified within a Microsoft Copilot interaction. It specifically looks for CopilotInteraction events where the 'JailbreakDetected' flag is set to true in the message data.
This rule detects instances where Microsoft Copilot accesses external resources, specifically identifying events where 'XPIADetected' is true. This indicates Copilot interacting with resources outside its immediate environment, which could be a security concern if the accessed resources are sensitive or untrusted.
Detects attempts to disable or stop syslog services (syslog, rsyslog, syslog-ng) using common system utilities like systemctl, service, chkconfig, or update-rc.d. This activity could indicate an adversary attempting to impair defenses by preventing logging of their actions.
Detects critical permission changes in Azure DevOps, specifically focusing on 'allow' changes to sensitive permissions like 'Edit build pipeline', 'Manage permissions', 'Queue builds', 'Administer build', and 'Bypass policies when completing' within key namespaces such as 'Git Repositories', 'ReleaseManagement', 'PipelinesPrivileges', and 'Project-level Permissions'. This rule aims to identify potential privilege escalation or unauthorized access attempts within Azure DevOps environments.
