Some of the most important (in my opinion) columns from AADSignInEventsBeta, which aren't provided in IdentityLogonEvents include:
DeviceTrustType, IsManaged, IsCompliant
ConditionalAccessStatus
NetworkLocationDetails
SessionId, CorrelationId
RiskLevelAggregated and RiskDetails
Working on a new blog in the MDE internals series, should be out tomorrow.
"Microsoft Defender for Endpoint Internals 0x05 — Telemetry for sensitive actions" including a tool drop
While I put some stuff together a long time ago, things have changed since the original integration. Would folks be interested in continuing to integrate @securityonion and @limacharlieio?
https://t.co/hTMymQ6QIY
https://t.co/iJxTrl6xUf
#DFIR#Infosec#ThreatHunting
Lol - 4 open source projects and 1 commercial C2 framework
I case you don’t remember: it’s better when it’s open source because everyone can write detections for it and it’ll be less of a threat … oh wait
We worked very hard with @SentinelOne to secure and to gift a person a nice prize, a MacBook Pro, for their novel research.
However, based on the lack of material received, in the future we will instead offer a 1-year subscription to Crunchyroll for you dweebs.
Is there a way to access the InitiatingProcessParentParent in KQL via DeviceProcessEvents? This entity gets returned when viewing the Device Timeline (detectionDeviceTimeline)
#KQL#MDE#MicrosoftDefender
Does MDE Advanced Hunting have a way to store "global" functions? Similar to a splunk macro, can I call a "to_timeline" function that has a defined | project format? #kql
#TR aka #TA577 is back after a 3 month vacation. They made some changes to their infrastructure and are no longer delivering #Qbot. Anyone have an idea of what this might be?
https://t.co/x0wEmVnkbq
@malwrhunterteam This one's fetched from e0de615d0a78b69b3b81bfac60bf037d (dokumentacja.xls) that is being sent out as DHL malspam. Gets further payload from
https//paste[.]ee/r/zv8f8
https//paste[.]ee/r/A0Ecd