Steven Lim (@0x534c) 's Twitter Profile
Steven Lim

@0x534c

#Cybersecurity #Sentinel #DefenderXDR #KQL #KQLWizard

ID: 42794499

linkhttps://github.com/SlimKQL/Hunting-Queries-Detection-Rules calendar_today27-05-2009 02:33:40

133 Tweet

1,1K Followers

865 Following

Steven Lim (@0x534c) 's Twitter Profile Photo

๐ŸชฑLateral Movement Analysis KQL Automatic Attack Disruption: A KQL query designed to provide statistics on the number of hosts and ports that the rogue quarantine device has connected to, supporting lateral movement investigation. detections.ai/rules/162280b5โ€ฆ

๐ŸชฑLateral Movement Analysis KQL

Automatic Attack Disruption: A KQL query designed to provide statistics on the number of hosts and ports that the rogue quarantine device has connected to, supporting lateral movement investigation.

detections.ai/rules/162280b5โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

Blind Eagle infrastructure exclusively leverages VBS files as its initial attack vector, relies heavily on free Dynamic DNS (DDNS) services, and deploys read RATs as a second-stage malware. trustwave.com/en-us/resourceโ€ฆ KQL: detections.ai/rules/75867a1fโ€ฆ

Blind Eagle infrastructure exclusively leverages VBS files as its initial attack vector, relies heavily on free Dynamic DNS (DDNS) services, and deploys read RATs as a second-stage malware.

trustwave.com/en-us/resourceโ€ฆ

KQL:
detections.ai/rules/75867a1fโ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

SlimKQL Community Group Hi all, I have migrated all my 338 KQLs from the GitHub Repo to Detections.ai SlimKQL Community Group. If you would like to get updates on my latest KQL detections, please do "FOLLOW" this community group. Thank you! Steven ๐Ÿ˜„

SlimKQL Community Group

Hi all, I have migrated all my 338 KQLs from the GitHub Repo to Detections.ai SlimKQL Community Group. If you would like to get updates on my latest KQL detections, please do "FOLLOW" this community group. Thank you!

Steven ๐Ÿ˜„
Steven Lim (@0x534c) 's Twitter Profile Photo

Mail Bomb Mayhem? KQL to the Rescue. Spotted a mail bomb attack originating from 30+ sender IPs. Leveraged KQL to trace the source and identify the ISPs involved. Visibility matters.๐Ÿ›ก๏ธ detections.ai/rules/e6a47fe9โ€ฆ

Mail Bomb Mayhem? KQL to the Rescue.

Spotted a mail bomb attack originating from 30+ sender IPs. Leveraged KQL to trace the source and identify the ISPs involved. Visibility matters.๐Ÿ›ก๏ธ

detections.ai/rules/e6a47fe9โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

A KQL behavioural detection of the new #DEVMAN ransomware. Link: detections.ai/rules/8aa75dedโ€ฆ #Cybersecurity #DefenderXDR

Steven Lim (@0x534c) 's Twitter Profile Photo

Storm 1811 SE Attack Detection 1: Email Bombing 2: Microsoft Teams Impersonation 3: Remote Access via Quick Assist 4: Deploy Black Basta ransomware detections.ai/rules/8d713b74โ€ฆ

Storm 1811 SE Attack Detection

1: Email Bombing
2: Microsoft Teams Impersonation
3: Remote Access via Quick Assist
4: Deploy Black Basta ransomware 

detections.ai/rules/8d713b74โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿš€ detections.ai launched ~1.5 weeks ago and already hit: ๐Ÿ‘ฅ 3K+ members ๐Ÿ›ก๏ธ 182+ detections (KQL, Sigma, YARA, Splunk, Elastic...) Thatโ€™s ~18 detections/day! ๐Ÿ”ฅ Join the global defender community & contribute! ๐Ÿ”— Use invite code: Slim2025 #DefenderUnite

๐Ÿš€ detections.ai  launched ~1.5 weeks ago and already hit: ๐Ÿ‘ฅ 3K+ members   ๐Ÿ›ก๏ธ 182+ detections (KQL, Sigma, YARA, Splunk, Elastic...)

Thatโ€™s ~18 detections/day! ๐Ÿ”ฅ
Join the global defender community & contribute! 

๐Ÿ”— Use invite code: Slim2025

#DefenderUnite
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿ•ต๏ธโ€โ™‚๏ธ New Detection Drop "You enumerate. I correlate. You exfil. I alert." ๐Ÿ”ฅ Just shipped a Sentinel KQL detection for NauthNRPC โ€” a stealthy RPC-based AD recon tool. github.com/sud0Ru/NauthNRโ€ฆ ๐Ÿ” Built to catch the quiet ones before they get loud. detections.ai/rules/f2769974โ€ฆ

๐Ÿ•ต๏ธโ€โ™‚๏ธ New Detection Drop   "You enumerate. I correlate. You exfil. I alert." ๐Ÿ”ฅ

Just shipped a Sentinel KQL detection for NauthNRPC โ€” a stealthy RPC-based AD recon tool. 
github.com/sud0Ru/NauthNRโ€ฆ

๐Ÿ” Built to catch the quiet ones before they get loud.
detections.ai/rules/f2769974โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

Hunting Exposed JDWP ๐Ÿšจ New from Wiz: Attackers are actively exploiting exposed Java Debug Wire Protocol (JDWP) ports in the wild. Misconfigured dev-mode deployments are giving threat actors RCE on cloud workloads. wiz.io/blog/exposed-jโ€ฆ KQL Code: detections.ai/rules/d4a19448โ€ฆ

Hunting Exposed JDWP

๐Ÿšจ New from Wiz: Attackers are actively exploiting exposed Java Debug Wire Protocol (JDWP) ports in the wild. Misconfigured dev-mode deployments are giving threat actors RCE on cloud workloads.
wiz.io/blog/exposed-jโ€ฆ

KQL Code:
detections.ai/rules/d4a19448โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿšจ Scattered Spider is backโ€”and bolder. Check Point reveals 500+ phishing domains mimicking legit portals (e.g. victimname-okta[.]com) targeting aviation, tech, and more. No sector is safe. ๐Ÿ•ท๏ธโœˆ๏ธ blog.checkpoint.com/research/exposโ€ฆ

๐Ÿšจ Scattered Spider is backโ€”and bolder. Check Point reveals 500+ phishing domains mimicking legit portals (e.g. victimname-okta[.]com) targeting aviation, tech, and more. No sector is safe. ๐Ÿ•ท๏ธโœˆ๏ธ

blog.checkpoint.com/research/exposโ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿ•ท๏ธThe Hunt for Spidy Phishing Domains๐ŸŽฃ The "KQL" to sniff out the web across your MDE & MDO telemetry ๐Ÿคฃ blog.checkpoint.com/research/exposโ€ฆ KQL: detections.ai/rules/1fb925e9โ€ฆ

๐Ÿ•ท๏ธThe Hunt for Spidy Phishing Domains๐ŸŽฃ

The "KQL" to sniff out the web across your MDE & MDO telemetry ๐Ÿคฃ

blog.checkpoint.com/research/exposโ€ฆ

KQL:
detections.ai/rules/1fb925e9โ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿšจ 2.3M users compromised. 18 Chrome & Edge extensionsโ€”once trusted, verified, even featuredโ€”turned into malware via silent updates. No phishing. No clicks. Just stealthy version bumps. blog.koi.security/google-and-micโ€ฆ KQL Code: detections.ai/rules/39c4afceโ€ฆ

๐Ÿšจ 2.3M users compromised.

18 Chrome & Edge extensionsโ€”once trusted, verified, even featuredโ€”turned into malware via silent updates. No phishing. No clicks. Just stealthy version bumps.

blog.koi.security/google-and-micโ€ฆ

KQL Code:
detections.ai/rules/39c4afceโ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐ŸšจNew web spun alert! ๐Ÿ•ท๏ธ The domain auth-sso[.]com just popped up yesterday and itโ€™s giving off major Scattered Spider vibes. Defender stay vigilant!๐Ÿซก #Cybersecurity #ThreatIntel #Checkpoint #ScatteredSpider

๐ŸšจNew web spun alert! 

๐Ÿ•ท๏ธ The domain auth-sso[.]com just popped up yesterday and itโ€™s giving off major Scattered Spider vibes. Defender stay vigilant!๐Ÿซก

#Cybersecurity #ThreatIntel #Checkpoint #ScatteredSpider
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿšจ New table alert for hashtag#AdvancedHunting in hashtag#DefenderXDR: GraphApiAuditEvents (Preview) Track Microsoft Entra ID API calls to Graph APIโ€”see who accessed what, when, and how. Perfect for auditing Graph API usage & spotting anomalies.๐Ÿซก learn.microsoft.com/en-us/defenderโ€ฆ

๐Ÿšจ New table alert for hashtag#AdvancedHunting in hashtag#DefenderXDR: GraphApiAuditEvents (Preview)

Track Microsoft Entra ID API calls to Graph APIโ€”see who accessed what, when, and how. Perfect for auditing Graph API usage & spotting anomalies.๐Ÿซก 

learn.microsoft.com/en-us/defenderโ€ฆ
Steven Lim (@0x534c) 's Twitter Profile Photo

๐Ÿ”ฅ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ ๐—™๐—ถ๐—ฟ๐˜€๐˜ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ๐—ซ๐——๐—ฅ ๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต ๐—”๐—ฃ๐—œ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐Ÿซก Monitoring Copilot Data Exfiltration via Graph API detections.ai/share/rule/uv6โ€ฆ

๐Ÿ”ฅ๐—ช๐—ผ๐—ฟ๐—น๐—ฑ ๐—™๐—ถ๐—ฟ๐˜€๐˜ ๐——๐—ฒ๐—ณ๐—ฒ๐—ป๐—ฑ๐—ฒ๐—ฟ๐—ซ๐——๐—ฅ ๐—š๐—ฟ๐—ฎ๐—ฝ๐—ต ๐—”๐—ฃ๐—œ ๐—ง๐—ต๐—ฟ๐—ฒ๐—ฎ๐˜ ๐——๐—ฒ๐˜๐—ฒ๐—ฐ๐˜๐—ถ๐—ผ๐—ป๐Ÿซก

Monitoring Copilot Data Exfiltration via Graph API
detections.ai/share/rule/uv6โ€ฆ