Microsoft XDR, KQL, real-world security engineering, and other fun stuff from DevSecOpsDad, your friendly neighbourhood Attack Surface Samurai.
-
-
Kql Detection Of The Week: A Meeting In 2050 (detecting Project Cav3rn's Outlook Calendar C2 And Dns Aaaa Recovery Channel)
There is a meeting on your calendar for 13 May 2050. Nobody will ever attend it. Nobody has ever scrolled there — a quarter-century out, in a fixed one-hour window between 22:00 and 23:00 UTC, parked in the most-synced, least-read database in your tenant. [Read More] -
Kql Detection Of The Week: The Dog That Didn't Bark
This week’s six briefs produced 29 KQL candidates (the Friday automation decided to take a personal day) across continued Flowise CSV-agent exploitation, a GigaWiper destructor, HTML phishing from first-time external senders, live internet scanning for exposed MCP servers and AI assistant credentials, ShinyHunters OAuth consent and guest-account abuse, a SharePoint... [Read More] -
Kql Detection Of The Week: Nice Costume, Wrong Address
This week’s seven briefs produced 27 KQL candidates across a Vidar-plus-XMRig malvertising wave hiding behind a forged code-signing certificate and a 491 MB null-byte suit, device-code phishing that sails straight past URL filters, an SMB session quietly upgraded into Meterpreter, a Peyara Remote Mouse RCE, Armored Likho’s BusySnake Python stealer, a... [Read More] -
Kql Detection Of The Week: The Login Was Never The Point
This week’s seven briefs produced 29 KQL candidates across ToddyCat’s Umbrij OAuth tooling raiding Google Workspace, a trojanized-ScreenConnect campaign dropping AsyncRAT, Armored Likho’s BusySnake Python stealer arriving on AI-generated phishing loaders, a photo-themed ZIP delivering a Node.js implant into hospitality, a malicious Chromium extension quietly redirecting search, and two Rapid7... [Read More]