logo

Whose endpoint is this… kali?!

ID: d2c29baf-dab9-52bb-b8b2-378046c067dc

STIX ID: report--d2c29baf-dab9-52bb-b8b2-378046c067dc

Feed Name: Detect FYI

Date Published: 2026-02-23

Date Updated: 2026-04-19

Author: Alex Teixeira

...
...

This report outlines practical methods to detect post-exploitation activity and unauthorized devices by correlating rich telemetry from Windows Event Logs and Microsoft Defender XDR. It explains how stealthy frameworks (e.g., LOLBins, in-memory execution) can still leave traces such as workstation names and remote session metadata, and provides SPL/KQL prototypes for identifying anomalous origins and rogue hosts via baselining and CMDB lookups. The piece emphasizes high-fidelity, late-stage detections and offers considerations to minimize false positives and operational noise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.