
Smarth Arora
@smarthxaroraToronto, ONCompletionist
1 follower243 downloads39 copies0 likes1,300 views
22 detections
Filters
Last updated
All Time
Detection languages
22
Categories
8
5
4
3
3
Platforms
11
8
5
5
3
Products / Services
6
6
4
2
2
MITRE Techniques
12
8
7
7
7
Detects the starting of the RemoteRegistry service via command-line utilities such as 'sc.exe' or 'net.exe'. This service is often started by adversaries to facilitate remote access to the Windows Registry for reconnaissance or enumeration of logon sessions.
Detects the creation of a Windows Scheduled Task configured with the 'InteractiveToken' LogonType. This configuration is often associated with adversary techniques designed to execute tasks in an interactive user context, potentially to bypass certain security controls or to facilitate the extraction of sensitive tokens or credentials (e.g., PRT cookies).
Detects the execution of BrowserCore.exe, a native messaging component for web browsers, when combined with command-line redirection (< or >) or specific output file creation (e.g., prt_cookie.txt, formatted_nonce.txt). This behavior is characteristic of an attack designed to extract Primary Refresh Tokens (PRTs) or browser cookies, which can be used to bypass authentication mechanisms.
Detects an authentication event using the OAuth 2.0 Device Code grant flow, immediately followed by rapid access to multiple high-value cloud resources. This pattern is characteristic of consent phishing or device code phishing, where an adversary tricks a user into authorizing a malicious application, subsequently using that application's access token to programmatically enumerate or exfiltrate data from various services.
Detects the execution of the roadtx command-line utility, which is a component of the ROADtools framework used for OAuth device code flow interaction and token acquisition within Entra ID (formerly Azure AD) environments.
Detects Microsoft Graph API requests that query directory role assignments specifically looking for highly privileged roles such as Global Administrator, Exchange Administrator, or Security Administrator. This activity may indicate an adversary is enumerating privileged roles to identify potential targets for privilege escalation or lateral movement within an Azure/Microsoft 365 environment.
Detects spearphishing emails that contain both a link to the legitimate 'microsoft.com/devicelogin' page and the phrase 'device code'. This is a common social engineering tactic used to trick users into providing a device authorization code to an attacker, enabling them to bypass MFA and hijack user sessions via OAuth device code flow.
Detects successful authentication events in Azure SigninLogs that utilize the Device Code OAuth flow. Attackers may leverage this flow in phishing campaigns or to bypass MFA by tricking users into authorizing malicious devices, which can lead to subsequent token theft.
This rule detects the use of the OAuth 2.0 Device Code Authorization flow directed towards 'microsoft.com/devicelogin'. This authentication method is frequently abused by attackers in phishing campaigns to hijack device-based user sessions by tricking victims into entering a device code on a malicious site, effectively bypassing traditional password-based authentication.
Detects the presence of specific Microsoft Entra (formerly Azure AD) authentication session cookies (ESTSAUTH, ESTSAUTHPERSISTENT, ESTSAUTHLIGHT) in web proxy traffic. This activity is indicative of session cookie theft and potential replay attacks (Pass-the-Cookie) where an adversary attempts to authenticate to Microsoft services using stolen session material from an unauthorized or non-enrolled device.
Page 1 of 3
