SIEM Bypasses: Diffracting the “CreepyDrive URLs” Sentinel Rule
ID: be948d0e-7285-5363-9fe3-281a47e32d25
STIX ID: report--be948d0e-7285-5363-9fe3-281a47e32d25
Feed Name: Detect FYI
This article reviews and stress-tests a community Microsoft Sentinel analytic for detecting the CreepyDrive OneDrive-based C2 (linked to POLONIUM), identifying six classes of detection logic bugs—case-sensitivity, URL-encoding, hardcoded paths/filenames/extensions, alternate Graph addressing modes, version handling, and TLS-visibility/data-collection assumptions—and proposes a corrected, coverage-complete regex layer and a behavioral UEBA scoring layer to reduce false negatives and false positives.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
