Detections¶
KQL detection queries from rorywag/KQL-Detections, rebuilt into these pages each time the site is published. Browse them by tactic or use the table below.
| Name | Tactic | Technique | Date |
|---|---|---|---|
| Guest Account Activated | Privilege Escalation | T1078.001 | 2025-10-15 |
| Malicious Browser Extension Installation | Persistence | T1176.001 | 2026-08-26 |
| Potential COM Hijacking and Registry-Based Persistence | Persistence | T1546.015 | 2025-08-29 |
| Potential Persistence via IFEO and SilentProcessExit Registry Keys | Persistence | T1546.012 | 2025-08-29 |
| Suspicious Modifications to Windows Startup Registry Keys | Persistence | T1547.001 | 2025-08-29 |
| Suspicious Outbound HTTP UserAgent | Exfiltration, Command and Control | T1041, T1071 | 2025-10-15 |
| Suspicious Shortcut and File Creation in Windows Startup Directories | Persistence | T1547.009 | 2025-08-29 |
| System Binary Masquerading via Non-Standard Execution Path | Defense Evasion | T1036.005 | 2026-08-14 |