Sign in

securityaura.bsky.social

@securityaura.bsky.social
421 followers 205 following 126 posts

GCIH, GCFE | DFIR, Threat Hunting, Detection Engineering | @CuratedIntel DFIR Member SecurityAura.com infosec.exchange/@SecurityAura

PostsRepliesMedia
securityaura.bsky.social @securityaura.bsky.social · 02/06/2025
#KQL query that looks for network connections to these domains via #MDE DeviceNetworkEvents (Connection or DNS Query). github.com/SecurityAura... Huge thanks to @RacWatchin8872 (on Twitter/X) for making the data available in a way that can be accessed via externaldata 🙏
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 25/05/2025
Forgot to post it here but: Finally took the time to write a quick blog post on my #100DaysOfKQL challenge. medium.com/@securityaur... tl;dr: I'm never doing anything like this again, at least, not before I have a LOT more free time than I have now. But very happy to have gone through with it!
medium.com
Looking Back On #100DaysOfKQL
Living your life, 1 query a day, for 100 days
110
securityaura.bsky.social @securityaura.bsky.social · 13/04/2025
#100DaysOfKQL Day 100 - CScript.exe, WScript.exe or MSHTA.exe Executed from Web Browser Process IT'S FINALLY OVER! I had another query in store for today, but I feel like this challenge wouldn't be complete without that one. (cont) t.co/lwO1hmrqUk
t.co
https://github.com/SecurityAura/DE-TH-Aura/blob/main/100DaysOfKQL/Day%20100%20-%20CScript.exe%2C%20WScript.exe%20or%20MSHTA.exe%20Executed%20from%20Web%20Browser%20Process.md
251
securityaura.bsky.social @securityaura.bsky.social · 12/04/2025
#100DaysOfKQL Day 99 - RDP Connection to X New Devices In The Last X Day by User One more to go! Basic investigative query that you can use as a starting point to dig into recent, new RDP activity per user. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 11/04/2025
#100DaysOfKQL Day 98 - Execution from a Low Prevalence, Non-Signed or Invalidly Signed Binary from C:\Windows I promise you I'm going somewhere with all these FileProfile() queries. Gotta wait a bit more. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 10/04/2025
#100DaysOfKQL Day 97 - PowerShell ComObject Interaction I wish I was getting some $ kickbacks from ClickFix for their queries 🥲 In the latest variant that I've seen, they basically throw everything in the book: PowerShell curl WScript[.]Shell cscript github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 09/04/2025
#100DaysOfKQL Day 96 - certutil.exe Used to Decode a File into a PE Harshly remembered that this technique exists ... because of a CSAT tool. IYKYK. github.com/SecurityAura...
github.com
020
securityaura.bsky.social @securityaura.bsky.social · 08/04/2025
#100DaysOfKQL Day 95 - Logon Attempts from LDAP Bind Accounts to Systems other than DCs MDI query will be provided later because life throws unexpected stuff at you sometime. Perfect for those edge devices that keeps getting popped, uh, keeping TAs out github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 07/04/2025
#100DaysOfKQL Day 94 - Archive Created at the Root of a Drive Another query to detect something threat actors do which I consider more of a default (to not say lazy) behavior than anything else. Always fun to see if these archives still exists in an IR github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 06/04/2025
#100DaysOfKQL Day 93 - PowerShell IEX or Invoke-Expression Today's query is sponsored by ClickFix and that one purple EDR who looks even more shady than ClickFix because of what you can catch it doing with this. github.com/SecurityAura...
github.com
020
securityaura.bsky.social @securityaura.bsky.social · 05/04/2025
#100DaysOfKQL Day 92 - Low Prevalence Unsigned DLL Sideloaded in AppData Folder Thanks to today's #ClickFix / #Lumma (#LummaStealer) infection combo for giving me an idea! github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 04/04/2025
#100DaysOfKQL Day 91 - Large EXE or MSI File Observed in User Downloads Folder Featuring a shoutout to debloat by the awesome @squiblydoo.bsky.social ! Go check it out (and also his certReport tool, #ImposeCost as they say) github.com/SecurityAura...
github.com
030
securityaura.bsky.social @securityaura.bsky.social · 03/04/2025
#100DaysOfKQL Day 90 - Network Connection from MSBuild.exe with ASN Enrichment 10 more days (and queries) to go! We're almost at the finish line! Seen MSBuild.exe being (ab)used so many times. Spotted in a random SecTopRAT incident today. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 02/04/2025
#100DaysOfKQL Day 89 - WmiPrvSE.exe Launching Command Executed Remotely May be renamed in the future because now that I look at it, it's weird but whatever. Probably the first (?) non-Defender XDR, Entra ID or M365 centric entry in my 100DaysOfKQL. github.com/SecurityAura...
github.com
011
securityaura.bsky.social @securityaura.bsky.social · 01/04/2025
#100DaysOfKQL Day 88 - ESENTUTL Used to Copy a File Another one for the "man, ntds.dit is locked, how can i access it and get it out of that system?" Threat Actor crowd. Or OffSec crowd, I don't judge. Or Blue Team wanting to get dem Web DBs out👀 github.com/SecurityAura...
github.com
001
securityaura.bsky.social @securityaura.bsky.social · 31/03/2025
#100DaysOfKQL Day 87 - Command Line Interpreter Launched as Service Cobalt Strike goes brrrr. Probably one of the most basic thing you can observe from it if you're lucky enough to have EDR, Sysmon or EID 4688 on IRs. PS: I'm never that lucky. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 30/03/2025
#100DaysOfKQL Day 86 - Summarized Processes Launched by PowerShell or Command Line Scripts More of an investigative query which gives you a "clean" output which makes it easier to see and understand what a script (or multiple scripts) does. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 29/03/2025
#100DaysOfKQL Day 85 - Command Line Spawned by Microsoft SQL Server The thing that almost ruined my Friday night. Remember kids, deconflicting between OffSec and Defenders is important 🤝 github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 27/03/2025
#100DaysOfKQL Day 84 - CLR DLLs Loaded by Process with Low Prevalence The day FileProfile() becomes available in Sentinel is the day everyone is going to abuse the hell out of it. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 26/03/2025
#100DaysOfKQL Day 83 - Password Accessed By User in Google Chrome or Microsoft Edge Little behavior I learned about while doing some Threat Hunting for runas-like events. You can spot users within your orgs that uses these browsers' Password Managers github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 25/03/2025
#100DaysOfKQL Day 82 - File Downloaded from Uncommon TLD A little follow-up, with a twist, to Day 81 query. A bit different now since we have more events with URLs to play with. Can also play with FileOriginReferrerUrl if needed? 👀 github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 24/03/2025
#100DaysOfKQL Day 81 - Executable File or Script Fetched during Network Connection Fun little query which can be expanded upon (winkwink DeviceFileEvents) to see files that are fetched during network connections (HTTP only AFAIK). github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 23/03/2025
#100DaysOfKQL Day 80 - mshta.exe Executing Raw Script From Command Line Some something about mshta.exe today that reminded me this. Poweliks used to be all the rage back when I was on teh forums and it used that as persistence in the Run key. Memories. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 22/03/2025
#100DaysOfKQL Day 79 - PowerShell Process Launching PowerShell Process with Encoded Command Similar to PowerShell launching cmd.exe, seeing encoded PowerShell launching itself, or PowerShell launching another PowerShell with -Encoded is interesting. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 21/03/2025
#100DaysOfKQL Day 78 - Sign-In Events From IP Address Associated With Malicious Domain A rare investigative query appears in front of your eyes with a very ugly hack that I'll fix later but this week has been quite draining so pls forgive. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 20/03/2025
#100DaysOfKQL Day 77 - Database Dump To Disk via sqlcmd.exe First time seeing this from a Ransomware actor, so quite interesting. Not talking about using sqlcmd.exe, but using it to dump tables to disk and then exfil them. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 19/03/2025
#100DaysOfKQL Day 76 - Cloudflared Usage This query of the day may or may not be sponsored by the current ransomware engagement I'm working on. Will let you guess (but not confirm) which group that is. Also: no metadata on cloudflared.exe :( github.com/SecurityAura...
github.com
020
securityaura.bsky.social @securityaura.bsky.social · 18/03/2025
#100DaysOfKQL Day 75 - Activity From Suspicious User-Agent I think I have one last after this piggybacking on @lethalforensics.bsky.social / @Evild3ad79 awesome CSV blacklists then I'm done. Remember: if it can be done in the UAL, it can be done in Sentinel or MCAS. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 17/03/2025
All the credits go to @lethalforensics.bsky.social for providing the list I'm using in a handy CSV format! Go check out their amazing Microsoft-Analyzer-Suite on GitHub! github.com/LETHAL-FOREN...
github.com
GitHub - LETHAL-FORENSICS/Microsoft-Analyzer-Suite: A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID - LETHAL-FORENSICS/Microsoft-Analyzer-Suite
021
securityaura.bsky.social @securityaura.bsky.social · 17/03/2025
All the credits go to @lethalforensics.bsky.social for providing the list I'm using in a handy CSV format! Go check out their amazing Microsoft-Analyzer-Suite on GitHub! github.com/LETHAL-FOREN...
github.com
GitHub - LETHAL-FORENSICS/Microsoft-Analyzer-Suite: A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID
A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID - LETHAL-FORENSICS/Microsoft-Analyzer-Suite
010
securityaura.bsky.social @securityaura.bsky.social · 17/03/2025
#100DaysOfKQL Day 74 - Consent to Application With Dangerous Delegated Permissions Another one that uses a very helpful blacklist (CSV <3) from @LETHAL_DFIR / @Evild3ad79 (on Twitter). Anything that can be found in UAL can be found in Sentinel logging. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 16/03/2025
#100DaysOfKQL Day 73 - Activity From Known Abused Application in Entra ID All credits for the blacklist used (CSV <3) goes to @LETHAL_DFIR / @evild3ad79 (on Twitter) I once again invite you to explore the amazing tool that is Microsoft-Analyzer-Suite on Github. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 15/03/2025
#100DaysOfKQL Day 72 - New Service Principal Added Following Consent to Application User being able to consent to apps and creating Service Principals is bad mmmmkay? You don't want to have TAs add eM Client, PERFECTDATA, rclone, etc. through BECs. github.com/SecurityAura...
github.com
020
securityaura.bsky.social @securityaura.bsky.social · 14/03/2025
#100DaysOfKQL Day 71 - cscript.exe or wscript.exe Launched with Script Engine Parameter Not gonna lie, mostly a #TBT query though there seems to still be some malware that uses it today. Haven't encountered any in a while though. github.com/SecurityAura...
github.com
001
securityaura.bsky.social @securityaura.bsky.social · 13/03/2025
#100DaysOfKQL Day 70 - Famatech Advanced IP Scanner or Advanced Port Scanner Usage Honestly, probably did this one out of spite because it's as rampant as netscan.exe. Added difficulty here is that a lot of SysAdmins uses it in my experience. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 12/03/2025
#100DaysOfKQL Day 69 - Potential Terminal Server or TermService Tampering via RDPWrap The virus I have caught up to my family yesterday and it was not possible for me to post a query. Hopefully we'll get through it soon. #MissedStreak github.com/SecurityAura...
github.com
011
securityaura.bsky.social @securityaura.bsky.social · 10/03/2025
#100DaysOfKQL Day 68 - SSH Used For Reverse Tunnel on Windows Will expand more on that one once I get better since there are other variants (Plink for instance can also be used and has been seen being used for that purpose). github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 09/03/2025
#100DaysOfKQL Day 67 - Potential Discovery via PowerShell Test-Connection and Test-NetConnection Getting better slowly but surely. Been seeing that cmdlet being used in one-time commands and homemade discovery PS1 scripts for years now. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 08/03/2025
#100DaysOfKQL Day 66 - Sysinternals Usage Still sick so another lazy one but hey, if it's also used by APTs (e.g.: AdExplorer by RedCurl/RedWolf), it's still worth looking into these. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 07/03/2025
#100DaysOfKQL Day 65 - Network Connections Coming From VPN Ranges Still sick as a dog, hopefully I'll get better this weekend and will be able to enhance these KQL queries I have to past hastily. Everybody claims to have network segmentation. Few does. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 06/03/2025
#100DaysOfKQL Day 64 - Emails With Company Name in Display Name Sent From Non-Company Domains tl;dr: Currently sick and fighting sleepiness + banging headache. Page is a bit empty of content, will update later on. github.com/SecurityAura...
github.com
100
securityaura.bsky.social @securityaura.bsky.social · 05/03/2025
#100DaysOfKQL Day 63 - File Added to Startup Folder I know it's not a #TBT yet, though that query does remind me of better days when I started and persistence was as simple (common) as dropping an EXE directly in one of these. Run keys worked too yo. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 04/03/2025
#100DaysOfKQL Day 62 - PortableApps Application Observed This is way less documented online than I thought it would be, even though it is something you can see from time to time. I can't be the only one to have seen PortableApps (.paf.exe) being used? github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 03/03/2025
#100DaysOfKQL Day 61 - SoftPerfect Network Scanner Usage A low quality query for a low quality fan-uh threat actor's favorite. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 02/03/2025
#100DaysOfKQL Day 60 - DeviceNetworkEvents From WinSCP with Enriched IP Information People who read the description knew this was coming mmmm? 😏 With this, the trifecta of rclone, FileZilla and WinSCP is covered. github.com/SecurityAura...
github.com
010
securityaura.bsky.social @securityaura.bsky.social · 01/03/2025
#100DaysOfKQL Day 59 - DeviceNetworkEvents From FileZilla with Enriched IP Information Pretty straightforward. May or may not have been inspired by the current RansomHub IR I'm working on. ICYMI: The rclone was also inspired by a // RansomHub IR. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 28/02/2025
#100DaysOfKQL Day 58 - regsvr32.exe or rundll32.exe Loading a DLL with an Invalid Signature I do love me some FileProfile() action. Wish it could be used in Microsoft Sentinel. Maybe one day ... github.com/SecurityAura...
github.com
030
securityaura.bsky.social @securityaura.bsky.social · 27/02/2025
#100DaysOfKQL Day 57 - Non-Sucking Service Manager (nssm) Usage Another one that works (or worked at this point) quite well with ngrok (or your all-time favorite: XMRig). Had to post this quickly today, will add more queries later as usual. Sorry. github.com/SecurityAura...
github.com
000
securityaura.bsky.social @securityaura.bsky.social · 26/02/2025
#100DaysOfKQL Day 56 - ngrok Usage Simple queries (multiple ones) to help identify basic usage of ngrok. Feeling inspired by that #RansomHub IR I'm working on maybe, who knows, that just uses that raw ngrok. No attempt to hide it at all. github.com/SecurityAura...
github.com
011
securityaura.bsky.social @securityaura.bsky.social · 25/02/2025
#100DaysOfKQL Day 55 - Executable File With Short Numerical Name Observed As far as budget hunting queries/detection goes ... this one is on sale right now even* *Until supplies last Challenge: modify the regex for an alphanumerical match. Still cheap github.com/SecurityAura...
github.com
010