logo

SIEM Bypasses: Diffracting the “CreepyDrive URLs” Sentinel Rule

ID: be948d0e-7285-5363-9fe3-281a47e32d25

STIX ID: report--be948d0e-7285-5363-9fe3-281a47e32d25

Feed Name: Detect FYI

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: Nikolas Bielski

...
...

This article reviews and stress-tests a community Microsoft Sentinel analytic for detecting the CreepyDrive OneDrive-based C2 (linked to POLONIUM), identifying six classes of detection logic bugs—case-sensitivity, URL-encoding, hardcoded paths/filenames/extensions, alternate Graph addressing modes, version handling, and TLS-visibility/data-collection assumptions—and proposes a corrected, coverage-complete regex layer and a behavioral UEBA scoring layer to reduce false negatives and false positives.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.