Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting
Use at your own risk. Some queries have been tested and verified within the lab. Others have resulted from research into threat reports or those shared by researchers with the community.
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Turla Snake malware hunt queries | Potential SNAKE Malware Installation CLI Arguments Indicator | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Turla Snake malware hunt queries | SNAKE Malware Installer Name Indicators | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Turla Snake malware hunt queries | Potential SNAKE Malware Installation Binary Indicator | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Batloader Execution Procedures | Suspicious BatLoader Malware Execution by Use of Powershell (via cmdline) | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md | |
Batloader Execution Procedures | Suspicious BatLoader Malware Execution by Use of Powershell (via cmdline) | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md | |
Batloader Execution Procedures | Possible Batloader Malware Execution by Gpg4Win Tool (via process creation) | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md |
Name | Description | Link | Tag |
---|---|---|---|
Turla Snake malware hunt queries | SNAKE Malware Service Persistence | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Turla Snake malware hunt queries | SNAKE Malware WerFault Persistence File Creation | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Turla Snake malware hunt queries | SNAKE Malware Covert Store Registry Key | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Turla Snake malware hunt queries | SNAKE Malware Service Persistence | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md | |
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Technique | Description | Link | Tag |
---|---|---|---|
Name | Description | Link | Tag |
---|---|---|---|
CVE-2023-23397 | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/CVE-2023-23397_kusto_queries.md | ||
CVE-2023-21554 | https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/CVE-2023-21554-Queuejump.md | ||
Name | Description | Link | Tag |
---|---|---|---|
3CX DLL Side Loading | |||
Name | Description | Link | Tag |
---|---|---|---|
3CX DLL Side Loading | |||