Microsoft XDR, KQL, real-world security engineering, and other fun stuff from DevSecOpsDad, your friendly neighbourhood Attack Surface Samurai.

  • Kql Detection Of The Week: The Dog That Didn't Bark

    This week’s six briefs produced 29 KQL candidates (the Friday automation decided to take a personal day) across continued Flowise CSV-agent exploitation, a GigaWiper destructor, HTML phishing from first-time external senders, live internet scanning for exposed MCP servers and AI assistant credentials, ShinyHunters OAuth consent and guest-account abuse, a SharePoint... [Read More]
  • Kql Detection Of The Week: Nice Costume, Wrong Address

    This week’s seven briefs produced 27 KQL candidates across a Vidar-plus-XMRig malvertising wave hiding behind a forged code-signing certificate and a 491 MB null-byte suit, device-code phishing that sails straight past URL filters, an SMB session quietly upgraded into Meterpreter, a Peyara Remote Mouse RCE, Armored Likho’s BusySnake Python stealer, a... [Read More]
  • Kql Detection Of The Week: The Login Was Never The Point

    This week’s seven briefs produced 29 KQL candidates across ToddyCat’s Umbrij OAuth tooling raiding Google Workspace, a trojanized-ScreenConnect campaign dropping AsyncRAT, Armored Likho’s BusySnake Python stealer arriving on AI-generated phishing loaders, a photo-themed ZIP delivering a Node.js implant into hospitality, a malicious Chromium extension quietly redirecting search, and two Rapid7... [Read More]
  • Kql Detection Of The Week: A Name Is A Claim, Not A Fact

    This week’s six briefs produced 30 KQL candidates across an NTLM-relay-to-Shadow-Credentials privilege chain, the WhatsApp VBScript RMM dropper, an npm postinstall implant, SharkLoader staging Cobalt Strike under the StrikeShark campaign, StealC and Amadey infostealers raiding browser credential stores, a photo-themed ZIP delivering a Node.js implant, and a fresh batch of... [Read More]
  • Kql Of The Week: The Attack That Stayed Under The Threshold

    This week’s five briefs produced 20 KQL candidates across an Oracle PeopleSoft zero-day (CVE-2026-35273), evil MSI loaders, the VHDX-to-Remcos delivery chain, Dropping Elephant’s Fondue.exe side-loading, a Tor-speaking crypto clipper, the Mastra npm supply-chain compromise, an AI-agent RCE, and a pile of SSH brute force. [Read More]