Dikshant Lather · Sep 25, 2026 Detecting Shadow IT and Massive Cloud Storage Uploads in Enterprise Networks Monitor unauthorized data transfers to personal cloud storage providers (MEGA, Dropbox, WeTransfer) using byte-count aggregation in KQL. Network Security 1 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Suspicious Microsoft 365 Inbox Forwarding Rules Using OfficeActivity Halt Business Email Compromise (BEC) fraud by catching covert Exchange Online inbox rules forwarding emails to external domains. Cloud Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Uncovering Local Windows Account Creation via Command Line with KQL Spot unauthorized backdoor user accounts created on endpoints via net.exe, net1.exe, and PowerShell local user management cmdlets. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Monitoring Azure Key Vault Unauthorized Enumeration and Secret Access with KQL Detect adversaries enumerating and dumping secrets, certificates, and API keys from Azure Key Vault using diagnostic log queries in Sentinel. Cloud Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Hunting for Cobalt Strike and C2 Periodic Beaconing Using DeviceNetworkEvents Detect outbound Command and Control beaconing patterns with low interval variance using statistical time-delta functions in Defender XDR KQL. Network Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Spotting Web Shell Execution: Web Server Spawning Suspicious Child Processes Detect web server compromises and web shell activity by identifying suspicious interactive shells spawned by IIS (w3wp.exe), Nginx, or Apache. Endpoint Detection 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL Catch lateral movement and persistence tools (PsExec, Cobalt Strike PsExec service) by monitoring new Windows Service installations with KQL. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Brute Force Attacks Followed by Successful Logon in Microsoft Sentinel Correlate failed sign-ins followed by a successful authentication within a short time window to immediately flag compromised user accounts. Incident Response 2 min read 0 0