Detection rules › Kusto Query Language
VTI - High Severity SHA1 Collision Detection
This will alert when a collision is detected for DeviceFileEvents events with VTI high severity SHA1 IoCs
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Execution | T1204 User Execution |
Event coverage
| Provider | Event ID | Title |
|---|---|---|
| Sysmon | 11 | FileCreate |
| Security-Auditing | 4663 | An attempt was made to access an object. |
| Defender-DeviceFileEvents | 9002000 | File activity (any) |
Stages and Predicates
Stage 1: source
DeviceFileEvents