Tag: MDE hunting

Sigma-to-MDE Query Conversion: DNS Detection for Katz Stealer via Uncoder AI
Sigma-to-MDE Query Conversion: DNS Detection for Katz Stealer via Uncoder AI

  How It Works Uncoder AI reads a Sigma detection rule designed to identify DNS queries to malicious domains linked with the Katz Stealer malware family. It then automatically rewrites the logic into a fully compatible Microsoft Defender for Endpoint (MDE) Advanced Hunting query using the Kusto Query Language (KQL). Left Panel – Sigma Rule: […]

Read More