Skip to content

Instantly share code, notes, and snippets.

@Shivammalaviya
Last active July 28, 2021 03:57
Show Gist options
  • Save Shivammalaviya/3b968ead5f0e78d46d3ec1dc78baa84f to your computer and use it in GitHub Desktop.
Save Shivammalaviya/3b968ead5f0e78d46d3ec1dc78baa84f to your computer and use it in GitHub Desktop.
//Advrsaries can scan your system with some penetration tools
union DeviceProcessEvents, DeviceFileEvents
, DeviceNetworkEvents
| where (InitiatingProcessFileName contains 'Nessus'
or InitiatingProcessFileName contains 'Netsparker'
or InitiatingProcessFileName contains 'curl'
or InitiatingProcessFileName contains 'wget'
or InitiatingProcessFileName contains 'dirbuster'
or InitiatingProcessFileName contains 'hydra'
or InitiatingProcessFileName contains 'sqlmap'
or InitiatingProcessFileName contains 'sqlninja'
or InitiatingProcessFileName contains 'nmap'
or InitiatingProcessFileName contains 'zenmap'
or InitiatingProcessFileName contains 'netsparker'
or InitiatingProcessFileName contains 'burp*'
or InitiatingProcessFileName contains 'acunetix*'
or InitiatingProcessFileName contains 'rapid7'
or InitiatingProcessFileName contains 'nexpose'
or InitiatingProcessFileName contains 'openvas'
or InitiatingProcessFileName contains 'qualys'
or InitiatingProcessFileName contains 'tenable'
or InitiatingProcessFileName contains 'tripwire'
or InitiatingProcessFileName contains 'saint'
or InitiatingProcessFileName contains 'nikto')
or InitiatingProcessFileName contains 'gfi*'
or InitiatingProcessFileName contains 'languard'
or InitiatingProcessFileName contains 'solarwind*'
or InitiatingProcessFileName contains 'retina'
or InitiatingProcessFileName contains 'aircrack*'
or InitiatingProcessFileName contains 'cwatch'
or InitiatingProcessFileName contains 'portswigger'
or InitiatingProcessFileName contains 'sonarqube'
or InitiatingProcessFileName contains 'vulcan'
or InitiatingProcessFileName contains 'kali'
or InitiatingProcessFileName contains 'commando*'
or InitiatingProcessFileName contains 'shredkit'
or InitiatingProcessFileName contains 'hashcat'
or InitiatingProcessFileName contains 'fiddler'
or InitiatingProcessFileName contains 'intruder'
or InitiatingProcessFileName contains 'zmap'
or InitiatingProcessFileName contains 'xray'
or InitiatingProcessFileName contains 'fuzzdb'
or InitiatingProcessFileName contains 'catfish'
or InitiatingProcessFileName contains 'coreimpact'
or InitiatingProcessFileName contains 'hackerone'
or InitiatingProcessFileName contains 'breachlock'
or InitiatingProcessFileName contains 'w3af'
or InitiatingProcessFileName contains 'johntheripper'
or InitiatingProcessFileName contains 'canvas'
or InitiatingProcessFileName contains 'nexfil'
or InitiatingProcessFileName contains 'osmedeus'
or InitiatingProcessFileName contains 'portscan'
| project Timestamp,DeviceName,FileName,FolderPath,InitiatingProcessVersionInfoCompanyName,InitiatingProcessAccountName
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment