avatar

Smarth Arora

@smarthxarora
Toronto, ONCompletionist
1 follower243 downloads39 copies0 likes1,300 views

22 detections

Detects the starting of the RemoteRegistry service via command-line utilities such as 'sc.exe' or 'net.exe'. This service is often started by adversaries to facilitate remote access to the Windows Registry for reconnaissance or enumeration of logon sessions.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
1038
Detects the creation of a Windows Scheduled Task configured with the 'InteractiveToken' LogonType. This configuration is often associated with adversary techniques designed to execute tasks in an interactive user context, potentially to bypass certain security controls or to facilitate the extraction of sensitive tokens or credentials (e.g., PRT cookies).
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
8017
Detects the execution of BrowserCore.exe, a native messaging component for web browsers, when combined with command-line redirection (< or >) or specific output file creation (e.g., prt_cookie.txt, formatted_nonce.txt). This behavior is characteristic of an attack designed to extract Primary Refresh Tokens (PRTs) or browser cookies, which can be used to bypass authentication mechanisms.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
1 month ago
106
Detects an authentication event using the OAuth 2.0 Device Code grant flow, immediately followed by rapid access to multiple high-value cloud resources. This pattern is characteristic of consent phishing or device code phishing, where an adversary tricks a user into authorizing a malicious application, subsequently using that application's access token to programmatically enumerate or exfiltrate data from various services.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
1014
Detects the execution of the roadtx command-line utility, which is a component of the ROADtools framework used for OAuth device code flow interaction and token acquisition within Entra ID (formerly Azure AD) environments.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
0013
Detects Microsoft Graph API requests that query directory role assignments specifically looking for highly privileged roles such as Global Administrator, Exchange Administrator, or Security Administrator. This activity may indicate an adversary is enumerating privileged roles to identify potential targets for privilege escalation or lateral movement within an Azure/Microsoft 365 environment.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
17011
Detects spearphishing emails that contain both a link to the legitimate 'microsoft.com/devicelogin' page and the phrase 'device code'. This is a common social engineering tactic used to trick users into providing a device authorization code to an attacker, enabling them to bypass MFA and hijack user sessions via OAuth device code flow.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
1010
Detects successful authentication events in Azure SigninLogs that utilize the Device Code OAuth flow. Attackers may leverage this flow in phishing campaigns or to bypass MFA by tricking users into authorizing malicious devices, which can lead to subsequent token theft.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
4010
This rule detects the use of the OAuth 2.0 Device Code Authorization flow directed towards 'microsoft.com/devicelogin'. This authentication method is frequently abused by attackers in phishing campaigns to hijack device-based user sessions by tricking victims into entering a device code on a malicious site, effectively bypassing traditional password-based authentication.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
109
Detects the presence of specific Microsoft Entra (formerly Azure AD) authentication session cookies (ESTSAUTH, ESTSAUTHPERSISTENT, ESTSAUTHLIGHT) in web proxy traffic. This activity is indicative of session cookie theft and potential replay attacks (Pass-the-Cookie) where an adversary attempts to authenticate to Microsoft services using stolen session material from an unauthorized or non-enrolled device.
avatar
Smarth Arora@smarthxarora
avatar
Detections.ai Community
3 months ago
207
Page 1 of 3