logo

Identifying Ransomware Final Stage activities with KQL Queries

ID: ccb70b19-8d11-5c0b-ae89-2bc282b4201c

STIX ID: report--ccb70b19-8d11-5c0b-ae89-2bc282b4201c

Feed Name: Detect FYI

Date Published: 2025-07-04

Date Updated: 2026-04-19

Author: Sergio Albea

...
...

This report provides a practical set of KQL detections for spotting final-stage ransomware activity in Defender XDR/Sentinel, including boot configuration edits (bcdedit), attempts to disable security services, data export and RDP enablement, log and Prefetch cleanup, encryption indicators (known ransomware extensions and shadow copy deletion), and ransom notification artifacts (wallpaper changes and public ransom notes), enabling rapid late-stage detection and response.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.