Dikshant Lather · Sep 25, 2026 Uncovering Local Windows Account Creation via Command Line with KQL Spot unauthorized backdoor user accounts created on endpoints via net.exe, net1.exe, and PowerShell local user management cmdlets. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Spotting Web Shell Execution: Web Server Spawning Suspicious Child Processes Detect web server compromises and web shell activity by identifying suspicious interactive shells spawned by IIS (w3wp.exe), Nginx, or Apache. Endpoint Detection 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries. Endpoint Detection 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL. Endpoint Detection 2 min read 0 0