KustQueryLanguage_kql

May 27, 2023 ยท View on GitHub

Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting

Use at your own risk. Some queries have been tested and verified within the lab. Others have resulted from research into threat reports or those shared by researchers with the community.

MITRE ATT&CK Mapping

Initial Access

TechniqueDescriptionLinkTag

Execution

TechniqueDescriptionLinkTag
Turla Snake malware hunt queriesPotential SNAKE Malware Installation CLI Arguments Indicatorhttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Turla Snake malware hunt queriesSNAKE Malware Installer Name Indicatorshttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Turla Snake malware hunt queriesPotential SNAKE Malware Installation Binary Indicatorhttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Batloader Execution ProceduresSuspicious BatLoader Malware Execution by Use of Powershell (via cmdline)https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md
Batloader Execution ProceduresSuspicious BatLoader Malware Execution by Use of Powershell (via cmdline)https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md
Batloader Execution ProceduresPossible Batloader Malware Execution by Gpg4Win Tool (via process creation)https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/MDE_Execution_BatloaderTTPs.md

Persistence

NameDescriptionLinkTag
Turla Snake malware hunt queriesSNAKE Malware Service Persistencehttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Turla Snake malware hunt queriesSNAKE Malware WerFault Persistence File Creationhttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Turla Snake malware hunt queriesSNAKE Malware Covert Store Registry Keyhttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md
Turla Snake malware hunt queriesSNAKE Malware Service Persistencehttps://github.com/m4nbat/KustQueryLanguage_kql/blob/main/APT_turla_snake_hunt.md

Privilege Escalation

TechniqueDescriptionLinkTag

Defense Evasion

TechniqueDescriptionLinkTag

Credential Access

TechniqueDescriptionLinkTag

Discovery

TechniqueDescriptionLinkTag

Lateral Movement

TechniqueDescriptionLinkTag

Collection

TechniqueDescriptionLinkTag

Command and Control

TechniqueDescriptionLinkTag

Exfiltration

TechniqueDescriptionLinkTag

Impact

TechniqueDescriptionLinkTag

Other Mappings

CVE's

NameDescriptionLinkTag
CVE-2023-23397https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/CVE-2023-23397_kusto_queries.md
CVE-2023-21554https://github.com/m4nbat/KustQueryLanguage_kql/blob/main/CVE-2023-21554-Queuejump.md

APT

NameDescriptionLinkTag
3CX DLL Side Loading

Uncategorised

NameDescriptionLinkTag
3CX DLL Side Loading