Tag: sysinfo syscall

Detect Linux Reconnaissance in Microsoft Sentinel with Sigma-to-KQL Conversion
Detect Linux Reconnaissance in Microsoft Sentinel with Sigma-to-KQL Conversion

How It Works The showcased feature translates a Linux-based Sigma rule — specifically targeting the sysinfo system call — into Microsoft Sentinel KQL. This system call provides an attacker with system metadata like uptime, memory usage, and load averages — commonly abused during reconnaissance. Left Panel – Sigma Rule: Targets Linux auditd telemetry for syscall […]

Read More