avatar

Benjamin Zulliger

@benscha
Trusted contributorCompletionist
27 followers229 downloads1,603 copies143 likes20,763 views

55 detections

This rule detects the execution of script interpreters (such as PowerShell, cmd, bash, python, etc.) where the command line contains non-ASCII characters, specifically Cyrillic, Arabic, or Chinese Unicode characters. This pattern can be indicative of obfuscation techniques used by adversaries to evade detection or to target specific regions.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
4 months ago
302377
This rule detects suspicious command-line activity involving several Windows executables (wscript.exe, cscript.exe, wmic.exe, ssh.exe) when combined with specific keywords. It looks for wscript.exe or cscript.exe executing 'SyncAppvPublishingServer.vbs', wmic.exe executing 'process', 'call', or 'create', or ssh.exe using 'ProxyCommand'. Additionally, the rule filters for command lines containing keywords like 'gal', 'i*x', 'gcm', '*stM*', 'jsdelivr.net', 'github', or 'powershell', which are often associated with malicious activity, obfuscation, or external resource loading.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
5 months ago
141139
This rule detects suspicious outbound network connections from devices that exhibit a consistent timing pattern (low standard deviation relative to the average time delta between connections) to public IP addresses. It specifically looks for connections that are not initiated by common browsers unless they are running in headless mode, or connections initiated by processes with low global prevalence or identified as Living Off The Land Binaries (LOLBAS). This pattern can indicate automated activity, command and control communication, or data exfiltration.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
502320
This query identifies potential post-exploitation behavior on Linux systems by monitoring for clusters of discovery and enumeration commands. Instead of alerting on single, potentially benign commands, it utilizes a behavioral scoring engine that categorizes activities such as credential hunting, privilege escalation, and network scanning.

By implementing extensive allowlists for common administrative tools (e.g., Ansible, Zabbix, Monitoring Agents) and requiring a minimum threshold of unique activity categories, the query effectively filters out "noise." It calculates a dynamic Risk Score and assigns a Severity level based on the criticality of the commands and the speed of execution (Burst Detection), making it a highly reliable tool for SOC analysts to detect active hands-on-keyboard attacks.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
370210
This query identifies users exhibiting unusual authentication behavior by combining Behavior Analytics with recent sign-in activity. It highlights high‑risk sign-ins originating from previously unseen IP addresses where the user agent or operating system has changed compared to historical patterns. The query enriches findings with historical sign-in context and Identity Info to support investigation of potentially compromised accounts.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
554724
Detects when a user generates an unusually high number of prompts to Copilot within a short period (e.g., 50 prompts in an hour). This could indicate automated activity, data exfiltration attempts, or misuse of the Copilot service.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
221172
This rule detects instances where a 'jailbreak' attempt is identified within a Microsoft Copilot interaction. It specifically looks for CopilotInteraction events where the 'JailbreakDetected' flag is set to true in the message data.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
241157
This rule detects instances where Microsoft Copilot accesses external resources, specifically identifying events where 'XPIADetected' is true. This indicates Copilot interacting with resources outside its immediate environment, which could be a security concern if the accessed resources are sensitive or untrusted.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
120152
Detects attempts to disable or stop syslog services (syslog, rsyslog, syslog-ng) using common system utilities like systemctl, service, chkconfig, or update-rc.d. This activity could indicate an adversary attempting to impair defenses by preventing logging of their actions.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
100111
Detects critical permission changes in Azure DevOps, specifically focusing on 'allow' changes to sensitive permissions like 'Edit build pipeline', 'Manage permissions', 'Queue builds', 'Administer build', and 'Bypass policies when completing' within key namespaces such as 'Git Repositories', 'ReleaseManagement', 'PipelinesPrivileges', and 'Project-level Permissions'. This rule aims to identify potential privilege escalation or unauthorized access attempts within Azure DevOps environments.
avatar
Benjamin Zulliger@benscha
avatar
Detections.ai Community
7 months ago
6084