<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>df00tech Blog</title>
    <link>https://df00tech.com/detections/blog</link>
    <atom:link href="https://df00tech.com/detections/blog/rss.xml" rel="self" type="application/rss+xml" />
    <description>Detection engineering insights, MITRE ATT&amp;CK guides, and KQL/SPL threat hunting tutorials for SOC analysts and security teams.</description>
    <language>en-us</language>
    <lastBuildDate>Thu, 23 Jul 2026 09:39:57 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-50522: SharePoint Deserialization Flaw Under Active Exploitation (CISA KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-50522</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-50522</guid>
      <pubDate>Thu, 23 Jul 2026 09:39:57 GMT</pubDate>
      <description>CVE-2026-50522 is a CISA KEV-listed deserialization flaw (CWE-502) in Microsoft SharePoint enabling RCE via crafted serialized payloads, actively exploited in the wild. Our detection spans Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Microsoft</category>
      <category>CVE-2026-50522</category>
    </item>
    <item>
      <title>CVE-2026-16232: Improper Authentication in Check Point SmartConsole (CISA KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-16232</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-16232</guid>
      <pubDate>Thu, 23 Jul 2026 09:39:53 GMT</pubDate>
      <description>CVE-2026-16232 is a KEV-listed authentication bypass in Check Point SmartConsole (CWE-287) that lets attackers access management sessions without valid credentials. We cover detection across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Check Point</category>
      <category>CVE-2026-16232</category>
    </item>
    <item>
      <title>CVE-2026-54052: Cross-Tenant Workflow Backup Access in n8n-MCP Exposes Embedded Credentials</title>
      <link>https://df00tech.com/detections/blog/cve-2026-54052</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-54052</guid>
      <pubDate>Thu, 23 Jul 2026 09:39:50 GMT</pubDate>
      <description>CVE-2026-54052 is a critical (CVSS 9.9) authorization bypass in n8n-mcp &lt;= 2.56.0 that lets attackers read other tenants&apos; workflow backups, potentially exposing embedded credentials and secrets. A public PoC exists and no patch is currently available.</description>
      <category>vuln-intel</category>
      <category>npm</category>
      <category>CVE-2026-54052</category>
    </item>
    <item>
      <title>CVE-2026-0770: Untrusted Component Execution in Langflow Actively Exploited in the Wild</title>
      <link>https://df00tech.com/detections/blog/cve-2026-0770</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-0770</guid>
      <pubDate>Wed, 22 Jul 2026 09:54:33 GMT</pubDate>
      <description>CVE-2026-0770 is a KEV-listed, actively exploited flaw in Langflow that lets attackers trigger execution of untrusted components. Our detection catches it via anomalous outbound connections, child process spawns, and untrusted calls to flow-execution endpoints.</description>
      <category>vuln-intel</category>
      <category>Langflow</category>
      <category>CVE-2026-0770</category>
    </item>
    <item>
      <title>CVE-2021-27137: DD-WRT Stack-Based Buffer Overflow Under Active Exploitation (CISA KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2021-27137</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2021-27137</guid>
      <pubDate>Wed, 22 Jul 2026 09:54:31 GMT</pubDate>
      <description>CVE-2021-27137 is a KEV-listed stack-based buffer overflow in DD-WRT&apos;s web management interface enabling RCE or DoS. Our detection covers abnormal HTTP requests, httpd crashes, and post-exploitation IoT segment activity across seven SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>DD-WRT</category>
      <category>CVE-2021-27137</category>
    </item>
    <item>
      <title>CVE-2026-60137: Actively Exploited SQL Injection in WordPress Core (KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-60137</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-60137</guid>
      <pubDate>Wed, 22 Jul 2026 09:54:30 GMT</pubDate>
      <description>CVE-2026-60137 is a CISA KEV-listed SQL injection vulnerability in WordPress Core, actively exploited in the wild against wp-admin, wp-json, and xmlrpc.php. WordPress 7.0.2 patches the flaw; our detection ships across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>WordPress</category>
      <category>CVE-2026-60137</category>
    </item>
    <item>
      <title>CVE-2026-50566: Fission SecurityContext Bypass Enables Privileged Pod Creation</title>
      <link>https://df00tech.com/detections/blog/cve-2026-50566</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-50566</guid>
      <pubDate>Tue, 21 Jul 2026 10:25:19 GMT</pubDate>
      <description>A critical (CVSS 9.9) flaw in Fission &lt;= 1.23.0 lets attackers with Environment/Function access bypass SecurityContext hardening and deploy privileged pods, risking node or cluster compromise. PoC is public.</description>
      <category>vuln-intel</category>
      <category>go</category>
      <category>CVE-2026-50566</category>
    </item>
    <item>
      <title>CVE-2026-44935: Cross-Namespace Secret Disclosure in Rancher Fleet&apos;s Helm Deployer</title>
      <link>https://df00tech.com/detections/blog/cve-2026-44935-3</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-44935-3</guid>
      <pubDate>Tue, 21 Jul 2026 10:25:15 GMT</pubDate>
      <description>CVE-2026-44935 (CVSS 9.9) lets low-privileged users in Rancher Fleet exfiltrate Secrets/ConfigMaps from arbitrary namespaces via unvalidated Helm valuesFrom references. A public PoC exists; see our KQL, SPL, and other SIEM detections for exploitation attempts.</description>
      <category>vuln-intel</category>
      <category>go</category>
      <category>CVE-2026-44935</category>
    </item>
    <item>
      <title>CVE-2026-52831: Critical Command Injection in Nuclio Cron Trigger Enables Unauthenticated RCE</title>
      <link>https://df00tech.com/detections/blog/cve-2026-52831</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-52831</guid>
      <pubDate>Tue, 21 Jul 2026 10:25:10 GMT</pubDate>
      <description>CVE-2026-52831 is a critical (CVSS 10.0) command injection flaw in Nuclio&apos;s cron trigger handling that allows unauthenticated RCE via unsanitized event headers/body. A public PoC exists; our detection covers seven SIEMs, watching for shell metacharacter injection and anomalous CronJob-spawned proces</description>
      <category>vuln-intel</category>
      <category>go</category>
      <category>CVE-2026-52831</category>
    </item>
    <item>
      <title>CVE-2026-48939: iCagenda Unrestricted File Upload Leads to RCE in Joomla (KEV, Active Exploitation)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-48939</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-48939</guid>
      <pubDate>Mon, 20 Jul 2026 10:02:05 GMT</pubDate>
      <description>CVE-2026-48939 is a KEV-listed unrestricted file upload flaw in Joomla&apos;s iCagenda component enabling web shell uploads and RCE; our detection covers the exploitation pattern across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>iCagenda</category>
      <category>CVE-2026-48939</category>
    </item>
    <item>
      <title>Detecting Web Shells (T1505.003): KQL and SPL Queries for IIS, Apache, and Tomcat</title>
      <link>https://df00tech.com/detections/blog/detecting-web-shells-t1505-003-kql-spl-iis-apache-tomcat</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-web-shells-t1505-003-kql-spl-iis-apache-tomcat</guid>
      <pubDate>Mon, 20 Jul 2026 09:04:28 GMT</pubDate>
      <description>Web shells give attackers persistent, hands-on-keyboard access to compromised web servers. Learn to detect T1505.003 with practical KQL and SPL queries covering process lineage, webroot file writes, and IIS access-log anomalies.</description>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>CVE-2026-50564: Fission Environment CRD PodSpec Passthrough Enables Node Escape (CVSS 9.9)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-50564</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-50564</guid>
      <pubDate>Sat, 18 Jul 2026 09:49:00 GMT</pubDate>
      <description>CVE-2026-50564 (CVSS 9.9) lets Fission Environment CRD authors inject privileged, host-namespace PodSpec fields into builder/executor pods, enabling node compromise in multi-tenant clusters. A public PoC exists; df00tech ships detection across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and Cr</description>
      <category>vuln-intel</category>
      <category>go</category>
      <category>CVE-2026-50564</category>
    </item>
    <item>
      <title>CVE-2026-50551: Stored XSS-to-RCE Chain in SiYuan Kernel Attribute View Asset Cells</title>
      <link>https://df00tech.com/detections/blog/cve-2026-50551</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-50551</guid>
      <pubDate>Sat, 18 Jul 2026 09:48:56 GMT</pubDate>
      <description>CVE-2026-50551 is a critical (CVSS 9.9) stored XSS-to-RCE chain in SiYuan&apos;s kernel via unsanitized attribute view asset cells, with a public PoC available. Our detection covers the injection, API abuse, and post-exploitation stages across seven SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>go</category>
      <category>CVE-2026-50551</category>
    </item>
    <item>
      <title>CVE-2026-25089: OS Command Injection in Fortinet FortiSandbox (KEV, Actively Exploited)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-25089</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-25089</guid>
      <pubDate>Sat, 18 Jul 2026 09:48:55 GMT</pubDate>
      <description>CVE-2026-25089 is a KEV-listed OS command injection flaw in Fortinet FortiSandbox enabling arbitrary command execution. We cover detection across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Fortinet</category>
      <category>CVE-2026-25089</category>
    </item>
    <item>
      <title>Fortinet FortiSandbox OS Command Injection (CVE-2026-39808): KEV-Listed Command Injection Under Active Exploitation</title>
      <link>https://df00tech.com/detections/blog/cve-2026-39808</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-39808</guid>
      <pubDate>Fri, 17 Jul 2026 10:17:34 GMT</pubDate>
      <description>CVE-2026-39808 is a KEV-listed OS command injection flaw in Fortinet FortiSandbox&apos;s management interface. Our detection catches it via anomalous process execution and shell-metacharacter requests across KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Fortinet</category>
      <category>CVE-2026-39808</category>
    </item>
    <item>
      <title>CVE-2026-58644: Actively Exploited Deserialization Flaw in Microsoft SharePoint</title>
      <link>https://df00tech.com/detections/blog/cve-2026-58644</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-58644</guid>
      <pubDate>Fri, 17 Jul 2026 10:17:33 GMT</pubDate>
      <description>CVE-2026-58644 is a KEV-listed deserialization flaw in Microsoft SharePoint enabling remote code execution. Our detections cover post-exploitation indicators like w3wp.exe anomalies, webshell drops, and LSASS access across seven SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>Microsoft</category>
      <category>CVE-2026-58644</category>
    </item>
    <item>
      <title>CVE-2026-45262: Authenticated SQL Injection in FacturaScripts REST API via Where::sqlColumn Parenthesis Bypass</title>
      <link>https://df00tech.com/detections/blog/cve-2026-45262</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-45262</guid>
      <pubDate>Fri, 17 Jul 2026 10:17:31 GMT</pubDate>
      <description>CVE-2026-45262 is a critical (CVSS 9.9) authenticated SQL injection in FacturaScripts&apos;s REST API filter parameter, with public PoC code and potential for SSRF-driven database host compromise. We ship detection coverage across seven major SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>composer</category>
      <category>CVE-2026-45262</category>
    </item>
    <item>
      <title>CVE-2026-56291: Unrestricted File Upload in Balbooa Forms for Joomla (KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-56291</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-56291</guid>
      <pubDate>Thu, 16 Jul 2026 23:17:00 GMT</pubDate>
      <description>CVE-2026-56291 is a KEV-listed unrestricted file upload flaw in Balbooa Forms for Joomla, letting attackers upload web shells for RCE. Our detection ships across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Balbooa</category>
      <category>CVE-2026-56291</category>
    </item>
    <item>
      <title>CISA KEV Alert: CVE-2023-4346 – Overly Restrictive Account Lockout in KNX Connection Authorization Enables Brute-Force of Building Automation Systems</title>
      <link>https://df00tech.com/detections/blog/cve-2023-4346</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2023-4346</guid>
      <pubDate>Thu, 16 Jul 2026 23:16:59 GMT</pubDate>
      <description>CVE-2023-4346, a CISA KEV-listed flaw in KNX&apos;s connection authorization lockout, lets attackers brute-force building automation access keys. Our KQL, SPL, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike detections flag the repeated failed auth attempts that reveal it.</description>
      <category>vuln-intel</category>
      <category>KNX Association</category>
      <category>CVE-2023-4346</category>
    </item>
    <item>
      <title>SonicWall SMA1000 SSRF Under Active Exploitation: What CVE-2026-15409 Means for Your Perimeter (CVE-2026-15409)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-15409</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-15409</guid>
      <pubDate>Thu, 16 Jul 2026 23:16:58 GMT</pubDate>
      <description>CVE-2026-15409 is a KEV-listed SSRF flaw in SonicWall SMA1000 appliances letting attackers pivot into internal networks and cloud metadata. Our detection catches it via SIEM correlation of anomalous outbound requests across seven platforms.</description>
      <category>vuln-intel</category>
      <category>SonicWall</category>
      <category>CVE-2026-15409</category>
    </item>
    <item>
      <title>CISA KEV Alert: Oracle E-Business Suite Privilege Escalation Under Active Exploitation (CVE-2026-46817)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-46817</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-46817</guid>
      <pubDate>Thu, 16 Jul 2026 23:15:10 GMT</pubDate>
      <description>CVE-2026-46817, a CISA KEV-listed privilege escalation flaw in Oracle E-Business Suite, enables authentication bypass and escalation to APPS/SYSADMIN roles. df00tech ships detections across Sentinel, Splunk, Elastic, QRadar, Sumo Logic, Chronicle, and CrowdStrike.</description>
      <category>vuln-intel</category>
      <category>Oracle</category>
      <category>CVE-2026-46817</category>
    </item>
    <item>
      <title>CVE-2026-56155: Actively Exploited Access Control Flaw in Microsoft AD FS</title>
      <link>https://df00tech.com/detections/blog/cve-2026-56155</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-56155</guid>
      <pubDate>Thu, 16 Jul 2026 23:15:07 GMT</pubDate>
      <description>CVE-2026-56155 is a KEV-listed access control flaw in Microsoft AD FS that lets limited-privilege actors obtain unauthorized federated access. Our detection tracks anomalous token issuance, claims rule changes, and AD FS admin activity across seven SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>Microsoft</category>
      <category>CVE-2026-56155</category>
    </item>
    <item>
      <title>CVE-2026-56164: Unauthenticated SharePoint Server RCE Actively Exploited in the Wild (KEV)</title>
      <link>https://df00tech.com/detections/blog/cve-2026-56164</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cve-2026-56164</guid>
      <pubDate>Thu, 16 Jul 2026 23:15:01 GMT</pubDate>
      <description>CVE-2026-56164 is a KEV-listed unauthenticated access flaw in Microsoft SharePoint Server enabling RCE and webshell deployment; our detection covers anonymous endpoint access, anomalous IIS child processes, and webshell drops across seven SIEM platforms.</description>
      <category>vuln-intel</category>
      <category>Microsoft</category>
      <category>CVE-2026-56164</category>
    </item>
    <item>
      <title>Detecting BYOVD Attacks (T1068): KQL and SPL Queries for Vulnerable Driver Abuse</title>
      <link>https://df00tech.com/detections/blog/detecting-byovd-vulnerable-driver-abuse-t1068-kql-spl</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-byovd-vulnerable-driver-abuse-t1068-kql-spl</guid>
      <pubDate>Thu, 16 Jul 2026 23:04:44 GMT</pubDate>
      <description>Bring Your Own Vulnerable Driver (BYOVD) attacks let adversaries kill EDR from kernel space before your detections ever fire. This guide gives SOC analysts concrete KQL and SPL queries to catch driver loads, service creation, and kernel tampering mapped to MITRE ATT&amp;CK T1068.</description>
      <category>Detection Engineering</category>
      <category>MITRE ATT&amp;CK</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Threat Hunting</category>
    </item>
    <item>
      <title>Detecting Kerberos Attacks (T1558): Kerberoasting, AS-REP Roasting &amp; Forged Tickets in KQL and SPL</title>
      <link>https://df00tech.com/detections/blog/detecting-kerberos-attacks-kerberoasting-as-rep-roasting-kql-spl-t1558</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-kerberos-attacks-kerberoasting-as-rep-roasting-kql-spl-t1558</guid>
      <pubDate>Mon, 08 Jun 2026 12:00:00 GMT</pubDate>
      <description>Production KQL (Microsoft Sentinel) and SPL (Splunk) detections for MITRE ATT&amp;CK T1558 — Kerberoasting, AS-REP Roasting, Golden and Silver Tickets — with Event 4769/4768 logic and tuning guidance for SOC teams.</description>
      <category>T1558</category>
      <category>Kerberoasting</category>
      <category>AS-REP Roasting</category>
      <category>Golden Ticket</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Splunk</category>
      <category>MITRE ATT&amp;CK</category>
      <category>Active Directory</category>
      <category>Threat Hunting</category>
    </item>
    <item>
      <title>Detecting RMM Tool Abuse (T1219): A SOC Analyst&apos;s KQL &amp; SPL Playbook</title>
      <link>https://df00tech.com/detections/blog/detecting-rmm-tool-abuse-remote-access-software-t1219-kql-spl</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-rmm-tool-abuse-remote-access-software-t1219-kql-spl</guid>
      <pubDate>Mon, 01 Jun 2026 12:00:00 GMT</pubDate>
      <description>How threat actors weaponize legitimate remote access software like AnyDesk, ScreenConnect, and Atera — and the production KQL and SPL detection rules SOC teams need to catch T1219 abuse before ransomware lands.</description>
      <category>T1219</category>
      <category>RMM</category>
      <category>remote access software</category>
      <category>AnyDesk</category>
      <category>ScreenConnect</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Splunk</category>
      <category>MITRE ATT&amp;CK</category>
      <category>Threat Hunting</category>
      <category>Scattered Spider</category>
    </item>
    <item>
      <title>Detecting Process Injection (T1055): A SOC Analyst&apos;s KQL &amp; SPL Guide</title>
      <link>https://df00tech.com/detections/blog/detecting-process-injection-t1055-kql-spl-guide</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-process-injection-t1055-kql-spl-guide</guid>
      <pubDate>Mon, 18 May 2026 12:00:00 GMT</pubDate>
      <description>Production KQL and SPL detection rules for MITRE ATT&amp;CK T1055 process injection — DLL injection, process hollowing, thread hijacking, PE injection, and Early Bird APC — with tuning guidance for SOC teams.</description>
      <category>T1055</category>
      <category>process injection</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Splunk</category>
      <category>MITRE ATT&amp;CK</category>
      <category>Threat Hunting</category>
    </item>
    <item>
      <title>CISA KEV Detection Rules: KQL &amp; SPL Queries for the CVEs Attackers Are Actually Exploiting</title>
      <link>https://df00tech.com/detections/blog/cisa-kev-detection-rules-kql-spl-critical-cves</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/cisa-kev-detection-rules-kql-spl-critical-cves</guid>
      <pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
      <description>Production-grade KQL and SPL detection queries for five critical vulnerabilities in the CISA Known Exploited Vulnerabilities catalog. Map KEV to MITRE ATT&amp;CK, prioritise alerts, and close the gap between patch lag and detection coverage.</description>
      <category>CISA KEV</category>
      <category>CVE detection</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>vulnerability management</category>
      <category>threat intelligence</category>
    </item>
    <item>
      <title>Detecting EDR Tampering: KQL and SPL Queries for T1562.001</title>
      <link>https://df00tech.com/detections/blog/edr-tamper-detection-kql-spl-t1562-001</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/edr-tamper-detection-kql-spl-t1562-001</guid>
      <pubDate>Mon, 04 May 2026 12:00:00 GMT</pubDate>
      <description>Every ransomware deployment starts with killing the AV. KQL queries for Microsoft Sentinel and SPL for Splunk to catch Defender disablement, service stops, taskkill abuse, and unauthorized exclusion additions before encryption begins.</description>
      <category>T1562.001</category>
      <category>EDR tampering</category>
      <category>defense evasion</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Windows Defender</category>
      <category>MITRE ATT&amp;CK</category>
      <category>ransomware detection</category>
    </item>
    <item>
      <title>Detecting Living-off-the-Land (LOLBin) Attacks: KQL and SPL Queries for Microsoft Sentinel and Splunk</title>
      <link>https://df00tech.com/detections/blog/detecting-living-off-the-land-lolbin-attacks-kql-spl</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-living-off-the-land-lolbin-attacks-kql-spl</guid>
      <pubDate>Mon, 27 Apr 2026 12:00:00 GMT</pubDate>
      <description>Real KQL and SPL detection rules for catching LOLBin abuse — mshta, regsvr32, rundll32, WMI, and BITS Jobs — using MITRE ATT&amp;CK T1218, T1047, and T1197 mapped queries from the df00tech library.</description>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Splunk</category>
      <category>LOLBins</category>
      <category>MITRE ATT&amp;CK</category>
      <category>Threat Hunting</category>
      <category>defense evasion</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Building Your First SOC Detection Library with MITRE ATT&amp;CK</title>
      <link>https://df00tech.com/detections/blog/building-first-soc-detection-library-mitre-attack</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/building-first-soc-detection-library-mitre-attack</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>A practical guide to building your first SOC detection library: required logs, MITRE ATT&amp;CK prioritisation, starter KQL and SPL queries, and a development loop that works.</description>
      <category>SOC</category>
      <category>detection library</category>
      <category>MITRE ATT&amp;CK</category>
      <category>Detection Engineering</category>
      <category>KQL</category>
      <category>SPL</category>
    </item>
    <item>
      <title>Command and Control Detection: Beaconing, DNS Tunneling, and C2 Frameworks</title>
      <link>https://df00tech.com/detections/blog/command-and-control-detection-beaconing-dns-tunneling-c2</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/command-and-control-detection-beaconing-dns-tunneling-c2</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>A practical C2 detection rule guide for SOCs: beaconing analysis, DNS tunneling, Cobalt Strike, Sliver, and protocol tunneling with KQL and SPL queries.</description>
      <category>C2</category>
      <category>beaconing</category>
      <category>DNS tunneling</category>
      <category>Cobalt Strike</category>
      <category>T1071</category>
      <category>T1572</category>
      <category>KQL</category>
      <category>SPL</category>
    </item>
    <item>
      <title>Credential Dumping Detection: Mimikatz, LSASS, and SAM (T1003) Queries</title>
      <link>https://df00tech.com/detections/blog/credential-dumping-detection-mimikatz-lsass-sam-t1003</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/credential-dumping-detection-mimikatz-lsass-sam-t1003</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>Credential dumping detection for T1003.001 LSASS, SAM, and NTDS extraction. KQL and SPL queries to catch Mimikatz, ProcDump, comsvcs.dll, and DCSync in your environment.</description>
      <category>credential dumping</category>
      <category>T1003</category>
      <category>Mimikatz</category>
      <category>LSASS</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Detecting Lateral Movement in Microsoft Sentinel: KQL Queries for T1021</title>
      <link>https://df00tech.com/detections/blog/detecting-lateral-movement-microsoft-sentinel-kql-t1021</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/detecting-lateral-movement-microsoft-sentinel-kql-t1021</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>Production-tested lateral movement detection KQL queries for Microsoft Sentinel and Defender for Endpoint covering T1021 — RDP, SMB admin shares, and WinRM.</description>
      <category>KQL</category>
      <category>lateral movement</category>
      <category>T1021</category>
      <category>Microsoft Sentinel</category>
      <category>Defender for Endpoint</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Phishing Detection Rules for Microsoft Defender and Sentinel (T1566)</title>
      <link>https://df00tech.com/detections/blog/phishing-detection-microsoft-defender-sentinel-t1566</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/phishing-detection-microsoft-defender-sentinel-t1566</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>A practical phishing detection rule guide for T1566 covering spearphishing attachments, links, and service-based phishing with KQL queries for Microsoft Defender and Sentinel.</description>
      <category>phishing</category>
      <category>T1566</category>
      <category>spearphishing</category>
      <category>Microsoft Defender for Office 365</category>
      <category>Sentinel</category>
      <category>KQL</category>
    </item>
    <item>
      <title>How to Detect PowerShell Execution Attacks: T1059.001 Complete Guide</title>
      <link>https://df00tech.com/detections/blog/powershell-detection-rule-t1059-001-complete-guide</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/powershell-detection-rule-t1059-001-complete-guide</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>Build a PowerShell detection rule for T1059.001 with production KQL for Microsoft Sentinel and SPL for Splunk. Covers encoded commands, AMSI bypass, and tuning.</description>
      <category>PowerShell</category>
      <category>T1059.001</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Microsoft Sentinel</category>
      <category>Splunk</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Ransomware Detection: TTPs, Indicators, and KQL Queries for 2026</title>
      <link>https://df00tech.com/detections/blog/ransomware-detection-ttps-kql-queries-2026</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/ransomware-detection-ttps-kql-queries-2026</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>A ransomware detection rule playbook for 2026: TTPs, KQL queries, and LockBit, BlackCat, Akira tells — catch mass file encryption and shadow copy deletion pre-detonation.</description>
      <category>ransomware</category>
      <category>LockBit</category>
      <category>BlackCat</category>
      <category>T1486</category>
      <category>T1490</category>
      <category>T1562.001</category>
      <category>KQL</category>
      <category>SPL</category>
    </item>
    <item>
      <title>Scheduled Task Persistence Detection with KQL and SPL (T1053.005)</title>
      <link>https://df00tech.com/detections/blog/scheduled-task-persistence-detection-kql-spl-t1053-005</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/scheduled-task-persistence-detection-kql-spl-t1053-005</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>Scheduled task detection for T1053.005 with production KQL and SPL queries for Microsoft Sentinel and Splunk — covering schtasks.exe, at.exe, cron, 4698/4700/4702 events, and hidden task persistence.</description>
      <category>scheduled tasks</category>
      <category>T1053.005</category>
      <category>persistence</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Splunk SPL vs Microsoft KQL: Detection Rule Syntax Comparison</title>
      <link>https://df00tech.com/detections/blog/splunk-spl-vs-microsoft-kql-detection-rule-syntax-comparison</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/splunk-spl-vs-microsoft-kql-detection-rule-syntax-comparison</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>SPL vs KQL for detection engineering — side-by-side Splunk and Microsoft Sentinel syntax with real queries for PowerShell, LSASS, and scheduled task detections.</description>
      <category>SPL</category>
      <category>KQL</category>
      <category>Splunk</category>
      <category>Microsoft Sentinel</category>
      <category>Detection Engineering</category>
      <category>comparison</category>
    </item>
    <item>
      <title>Top 20 Most Important MITRE ATT&amp;CK Techniques for SOC Analysts to Detect</title>
      <link>https://df00tech.com/detections/blog/top-20-mitre-attack-techniques-soc-analysts-detect</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/top-20-mitre-attack-techniques-soc-analysts-detect</guid>
      <pubDate>Thu, 16 Apr 2026 12:00:00 GMT</pubDate>
      <description>The most important MITRE ATT&amp;CK techniques every SOC analyst must detect, prioritized by real-world frequency with KQL detection coverage for each.</description>
      <category>MITRE ATT&amp;CK</category>
      <category>SOC</category>
      <category>Detection Engineering</category>
      <category>prioritization</category>
      <category>top techniques</category>
    </item>
    <item>
      <title>Complete MITRE ATT&amp;CK Detection Coverage: 704 KQL and SPL Queries</title>
      <link>https://df00tech.com/detections/blog/mitre-attack-detection-coverage-704-kql-spl-queries</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/mitre-attack-detection-coverage-704-kql-spl-queries</guid>
      <pubDate>Wed, 08 Apr 2026 12:00:00 GMT</pubDate>
      <description>df00tech provides 704 production-ready KQL and SPL detection rules mapped to the MITRE ATT&amp;CK framework. Learn how comprehensive detection coverage protects your environment.</description>
      <category>MITRE ATT&amp;CK</category>
      <category>detection rules</category>
      <category>KQL</category>
      <category>SPL</category>
      <category>Detection Engineering</category>
    </item>
    <item>
      <title>Building a Detection Engineering Program with MITRE ATT&amp;CK</title>
      <link>https://df00tech.com/detections/blog/building-detection-engineering-program-mitre-attack</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/building-detection-engineering-program-mitre-attack</guid>
      <pubDate>Mon, 06 Apr 2026 12:00:00 GMT</pubDate>
      <description>A practical guide for SOC teams on using the MITRE ATT&amp;CK framework to identify detection gaps, prioritise rule development, and measure coverage improvements over time.</description>
      <category>Detection Engineering</category>
      <category>MITRE ATT&amp;CK</category>
      <category>SOC</category>
      <category>security operations</category>
      <category>threat detection</category>
    </item>
    <item>
      <title>KQL Threat Hunting Queries for Microsoft Sentinel: A Practical Guide</title>
      <link>https://df00tech.com/detections/blog/kql-threat-hunting-queries-microsoft-sentinel</link>
      <guid isPermaLink="true">https://df00tech.com/detections/blog/kql-threat-hunting-queries-microsoft-sentinel</guid>
      <pubDate>Sat, 04 Apr 2026 12:00:00 GMT</pubDate>
      <description>Hands-on KQL threat hunting queries for Microsoft Sentinel, covering credential dumping, UAC bypass, log tampering, ingress tool transfer, and password spraying detection.</description>
      <category>KQL</category>
      <category>Microsoft Sentinel</category>
      <category>Threat Hunting</category>
      <category>Defender for Endpoint</category>
      <category>Detection Engineering</category>
    </item>
  </channel>
</rss>