Microsoft XDR, KQL, real-world security engineering, and other fun stuff from DevSecOpsDad, your friendly neighbourhood Attack Surface Samurai.

  • Kql Detection Of The Week: A Name Is A Claim, Not A Fact

    This week’s six briefs produced 30 KQL candidates across an NTLM-relay-to-Shadow-Credentials privilege chain, the WhatsApp VBScript RMM dropper, an npm postinstall implant, SharkLoader staging Cobalt Strike under the StrikeShark campaign, StealC and Amadey infostealers raiding browser credential stores, a photo-themed ZIP delivering a Node.js implant, and a fresh batch of... [Read More]
  • Kql Of The Week: The Attack That Stayed Under The Threshold

    This week’s five briefs produced 20 KQL candidates across an Oracle PeopleSoft zero-day (CVE-2026-35273), evil MSI loaders, the VHDX-to-Remcos delivery chain, Dropping Elephant’s Fondue.exe side-loading, a Tor-speaking crypto clipper, the Mastra npm supply-chain compromise, an AI-agent RCE, and a pile of SSH brute force. [Read More]
  • Kql Of The Week: Detecting Cloud Logging Suppression T1562 008

    Every day our Detection Engineering Brief turns fresh threat intel into deployable detection content — KQL for Microsoft Sentinel and Defender XDR, ATT&CK mappings, triage runbooks, and deployment-readiness calls. This week’s five briefs produced 21 KQL candidates across Apache ActiveMQ and Gogs RCE, a Check Point VPN zero-day (CVE-2026-50751), PAN-OS... [Read More]
  • Kql Of The Week: Argamal Beaconing

    Every day our Detection Engineering Brief turns fresh threat intel into deployable detection content — KQL for Microsoft Sentinel and Defender XDR, ATT&CK mappings, triage runbooks, and deployment-readiness calls. This week’s five briefs produced 23 KQL candidates across npm supply-chain attacks, NetSupport RAT, a macOS FlutterShell dropper chain, a Key... [Read More]