Detecting AD CS #subjectAltName (SAN) Abuse Using #KQL & #MicrosoftSentinel
Problems tackled:
1️⃣ #ADCS logging is poor...
2️⃣ How do we map events that have no correlating fields?
3️⃣ Can logical thinking be expressed through KQL?
We've been promoting #LOLBAS detection using #MicrosoftSentinel and #KQL in our defensive training over the past few years, and it’s proven to be a popular query
Check out the details in our new article!
in.security/2023/02/01/kql…
⭐️ The Path to Pwnage ⭐️
Use the LOLBAS API to grab a list of known programs, then perform a check to see if the binary exists on the endpoint
If a match is found the full path of the identified item will be written to a text file for later review 🤟
in.security/2023/01/24/the…