Tag: Microsoft Defender

URL-Based IOC Validation for Microsoft Defender KQL
URL-Based IOC Validation for Microsoft Defender KQL

How It Works This feature in Uncoder AI demonstrates how to validate and optimize URL-based detection logic for Microsoft Defender for Endpoint, using Kusto Query Language (KQL). In the example shown, the input consists of remote access indicators from CERT-UA#11689 (WRECKSTEEL), which include phishing domains and command-and-control endpoints. Detection Pattern: The KQL query performs the […]

Read More