Dikshant Lather · Sep 25, 2026 Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries. Endpoint Detection 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL. Endpoint Detection 2 min read 0 0