Detection rules › Kusto Query Language

RecordedFuture Threat Hunting Hash All Actors

Source
upstream

'Recorded Future Threat Hunting hash correlation for all actors.'

MITRE ATT&CK coverage

TacticTechniques
Initial AccessT1189 Drive-by Compromise
ExecutionT1059 Command and Scripting Interpreter
PersistenceT1554 Compromise Host Software Binary

Event coverage

ProviderEvent IDTitle
Sysmon11FileCreate
Sysmon23FileDelete (File Delete archived)
Sysmon26FileDeleteDetected (File Delete logged)
Security-Auditing4663An attempt was made to access an object.

Stages and Predicates

Stage 1: source

imFileEvent

Stage 2: where

Hash is_not_null

Stage 3: extend

Stage 4: join

Stage 5: mv-expand

Stage 6: project