-
Identifies shells, LOLBins, GTFOBins, and scripting runtimes connecting to the Azure WireServer / HostGAPlugin address 168.63.129.16 on ports 80 or 32526. The guest agent uses this fabric endpoint for GoalState, certificates, and vmSettings. Adversaries with code execution on an Azure VM (including via Run Command) use curl, PowerShell, openssl, bun, or similar tools to enumerate versions, pull transport certificates, and read HostGAPlugin /vmSettings. Azure guest-agent binaries and system python used by waagent are excluded. Descendants of the guest agent are not excluded: Run Command payloads execute in that tree.
Read More -
AzCopy or Azure Storage Explorer Usage on Unusual Host
Sep 10, 2026 · Domain: Endpoint OS: Windows Platform: Windows Use Case: Threat Detection Tactic: Exfiltration Tactic: Collection Tactic: Execution Rule Type: New Terms Threat: Rhysida Use Case: Ransomware Resources: Investigation Guide Data Source: Elastic Defend Data Source: Sysmon Data Source: Microsoft Defender XDR Data Source: Crowdstrike ·Identifies the first time, in a historical window, a host runs AzCopy copy or sync to Azure Blob, Data Lake, or File storage, or starts Azure Storage Explorer. These Microsoft utilities are legitimate data-transfer tools; ransomware and cloud-ransomware operators drop portable copies and use SAS-authenticated jobs to pull data from victim storage and push it to attacker-controlled accounts.
Read More -
Potential Entra ID PRT Extraction via BrowserCore
Sep 4, 2026 · Domain: Endpoint OS: Windows Platform: Windows Use Case: Threat Detection Tactic: Credential Access Resources: Investigation Guide Rule Type: ESQL Data Source: Elastic Defend Data Source: Sysmon Data Source: Windows Security Event Logs Data Source: Crowdstrike Data Source: SentinelOne Data Source: Microsoft Defender XDR ·Identifies anomalous execution of BrowserCore.exe, the Windows component used by Chromium-based browsers for native messaging with the Web Account Manager (WAM). Adversaries abuse BrowserCore to extract Entra ID Primary Refresh Tokens (PRTs) without interactive browser context, enabling session hijacking. Legitimate BrowserCore launches carry a chrome-extension:// argument from the browser native-messaging host.
Read More -
PKINIT Followed by Same-Principal U2U Service Ticket
Identifies a successful PKINIT ticket-granting ticket request followed within five seconds on the same domain controller and source address by a successful user-to-user service-ticket request whose service SID matches the PKINIT principal SID. This sequence is consistent with the KDC-visible ticket requests used in an UnPAC-the-Hash attack, before client-side PAC credential decryption and NT hash recovery. The certificate used for PKINIT may have been obtained through CertiGhost or another certificate-abuse path.
Read More