Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Kustonomicon

  _              _                              _
 | |            | |                            (_)
 | | ___   _ ___| |_ ___  _ __   ___  _ __ ___  _  ___ ___  _ __
 | |/ / | | / __| __/ _ \| '_ \ / _ \| '_ ` _ \| |/ __/ _ \| '_ \
 |   <| |_| \__ \ || (_) | | | | (_) | | | | | | | (_| (_) | | | |
 |_|\_\\__,_|___/\__\___/|_| |_|\___/|_| |_| |_|_|\___\___/|_| |_|

A grimoire of KQL for cloud detection and response: documented detection, hunting, and posture queries for AWS and Azure control-plane logs, with matching Microsoft Sentinel analytic rules.

Focus

Most KQL content out there targets the endpoint. The Kustonomicon focuses on the cloud service provider control plane — CloudTrail, Azure Activity, Entra ID, and Azure diagnostics — where detections pair naturally with posture: many entries combine a detection query (catch the event) with an Azure Resource Graph query (find the exposure before the event).

Every query follows a single documented template with machine-readable frontmatter: platform, service, type (detection / hunt / posture), severity, tables, and MITRE ATT&CK mappings. CI validates all of it.

Repository layout

queries/        documented KQL queries — see the index below
  aws/          CloudTrail-based detections, organized by service
  azure/        Azure control plane, Entra ID, Key Vault, storage, …
  endpoint/     a few Microsoft Defender endpoint extras
detections/     Microsoft Sentinel analytic rules (YAML), mirroring queries/
learn/          notes on the KQL patterns these detections use (WIP)
docs/           the query template and conventions
scripts/        validation, index generation, YAML → ARM conversion

Query index

AWS

CloudTrail

Query Type Severity MITRE
Activity from New IP Not Seen in 90 Days hunt medium T1078.004
Activity from New User Agent Not Seen in 90 Days hunt medium T1078.004
Aviatrix Controller RCE CVE-2024-50603 hunt high T1190
CloudTrail Logging Stopped detection high T1562.008

EC2

Query Type Severity MITRE
EC2 Instance Exported to S3 detection high T1537
Unsanctioned EC2 Type Created detection low T1496

IAM

Query Type Severity MITRE
Access Key Created hunt low T1098, T1098.001
Access Key Created and Deleted in Short Period of Time hunt medium T1098, T1098.001, T1550
Access Key Deleted hunt low T1098, T1531
Actions from Federated User hunt medium T1078, T1078.004, T1550
Assume Role from Untrusted Account ID detection high T1078, T1078.004, T1199
Console Login Without MFA detection medium T1078, T1078.004
Failed Login from Root detection medium T1078, T1078.004, T1110
Federated User Created detection medium T1078, T1078.004, T1550
GetCallerIdentity from AWS CLI hunt low T1033, T1552
Large Volume of Access Keys Created in Short Time hunt medium T1098, T1098.001
Multiple Failed Logins from Single Source IP detection medium T1110, T1110.003
New Access Key Created for Root detection high T1098, T1098.001
Successful Login After Multiple Failed Logins detection high T1110, T1078, T1078.004

RDS

Query Type Severity MITRE
RDS Snapshot Exported to S3 detection medium T1537
RDS Snapshot Taken hunt low T1578.001

S3

Query Type Severity MITRE
Block Public Access Disabled detection high T1562.007
Bucket Deleted detection medium T1485
Objects Deleted hunt low T1485

Secrets Manager

Query Type Severity MITRE
Large Number of Secrets Accessed in Short Time detection high T1555.006
Large Number of Secrets Deleted in Short Time detection high T1485

SSM

Query Type Severity MITRE
SSM Document Configured as Public detection high T1078.004
SSM Document Executed hunt informational T1651
SSM Document Executed Not Seen in Last 90 Days hunt medium T1651
SSM Document Executed on Multiple Instances hunt medium T1651

VPC

Query Type Severity MITRE
Dangerous Ingress Rule detection high T1562.007
IOC Security Group Created detection high T1562.007
Security Group Deleted hunt low T1562.007

Azure

Compute

Query Type Severity MITRE
Disk Export SAS URL Generated detection high T1530
Multiple VMs Deleted in Short Time detection high T1578.003, T1485
Run Command Started detection medium T1651
VMAccess Extension Executed detection high T1651, T1098

Entra ID

Query Type Severity MITRE
Admin Consent to Risky Permission detection high T1528
Admin Reset Password for Another Admin detection high T1098, T1531
BitLocker Key Accessed detection medium T1555
Conditional Access Policy Deleted detection high T1556.009
Conditional Access Policy Modified detection medium T1556.009
Cross-Tenant Access Setting Modified detection medium T1484.002
Device Code Flow Authentication hunt medium T1528
Failed Logins Followed by Successful Login detection high T1110.001, T1110.003
Guest Account Added as App Owner detection medium T1098
Large Number of Groups Deleted in Short Time detection medium T1531
MFA Method Added by Different Caller detection high T1098.005
MFA Method Updated detection medium T1098.005
Multiple Valid Users Failing Auth from Same IP detection medium T1110, T1110.003, T1110.004
Named Location Modified detection medium T1556.009
New Credential Added to Service Principal detection high T1098.001
New Tenant Added to Cross-Tenant Access Settings detection high T1484.002
New Trusted Location Created detection high T1556.009
Owner Added to App hunt low T1098
Privileged Role Assigned to External Guest detection high T1098.003
Privileged Role Assigned via PIM detection medium T1098.003
Risky Sign-In to Azure Portal detection high T1078.004
Role Assigned to Group detection medium T1098.003
Role Assigned to Guest detection high T1098.003
Self-Service Password Reset hunt informational T1098
Successful Sign-In from Break-Glass Account detection high T1078.004
Trusted Location Modified detection high T1556.009
Uncommon User Agent hunt informational T1078.004

Key Vault

Query Type Severity MITRE
Access Configuration Modified detection medium T1555.006, T1556
Access Policy Self-Assignment detection high T1555.006, T1556
Large Number of Items Accessed in Short Time detection high T1555.006
Large Number of Items Deleted in Short Time detection high T1485, T1555.006
Large Number of Items Listed in Short Time hunt medium T1555.006
New IP Added to Firewall detection medium T1562.007, T1555.006
Potential Privilege Escalation detection high T1555.006, T1556
Vaults Without RBAC Authorization posture medium T1555.006, T1556

Monitor

Query Type Severity MITRE
Activity from New IP Not Seen in 90 Days hunt low T1078.004
Diagnostic Setting Deleted detection high T1562.008
Diagnostic Setting Modified detection medium T1562.008
Uncommon Caller IP Addresses hunt low T1078.004

Network

Query Type Severity MITRE
Firewall Policy Updated detection medium T1562.007
NIC Modified hunt low T1578
NSG Deleted detection medium T1562.007
NSG Inbound Rule Allowing Management Ports detection high T1562.007

RBAC

Query Type Severity MITRE
Privileged Role Assigned detection high T1098.003, T1548
Privileged Role Assigned to Subscription detection high T1098.003, T1548

Sentinel

Query Type Severity MITRE
Analytic Rule Deleted detection high T1562.001
Analytic Rule Modified detection medium T1562.001

Storage

Query Type Severity MITRE
Mass Blob Download detection high T1530
Multiple Storage Account Keys Accessed in Short Time detection medium T1552, T1530
New IP Added to Storage Account Firewall detection medium T1562.007, T1530
Public Access Enabled on Storage Account detection high T1562.007, T1530
Storage Account Container Deleted detection medium T1485
Storage Account Keys Accessed hunt low T1552, T1530
Storage Account Keys Listed hunt low T1530
Storage Accounts with Public Access posture medium T1562.007

Endpoint

Microsoft Defender

Query Type Severity MITRE
Antivirus Exclusion Added detection medium T1562.001
Rundll32 With No Command Line detection medium T1218.011, T1055

About

A series of cloud focused KQL queries for threat hunting and DFIR

Topics

Resources

Stars

13 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages