Skip to content

Rare Custom Script Extension - Hunting Query #13342

@vdabhi123

Description

@vdabhi123

For the cx the ask is to have an analytical rule for "Rare Custom Script Extension" -(Which is a Hunting Query as of now):

The Kql seems to be old hence I have updated the OperationNameValue in the KQL.

The first part is trying to extract for value FileURL and CommandToExecute in the Setting value.

but the Settings value which is loading up in the output has only have ********

in it which means the value are redacted/masked unable to get the actual values of FileURL and CommandToExecute..

I also tried projecting the output for values FileURL and CommandToExecute and it confirmed no extraction from settings:

Link:
https://github.com/Azure/Azure-Sentinel/commits/master/Solutions/Azure%20Activity/Hunting%20Queries/Rare_Custom_Script_Extension.yaml

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions