menu
techminis

A naukri.com initiative

google-web-stories
source image

Socprime

2d

read

67

img
dot

Image Credit: Socprime

Zip Archive & C2 Domain Detection in Microsoft Sentinel via Uncoder AI

  • Uncoder AI feature generates KQL detection query for Microsoft Sentinel based on indicators from DarkCrystal RAT threat report.
  • Query searches logs for strings like 'Розпорядження.zip' and 'imgurl.ir' across all available data tables.
  • Uncoder AI extracts high-confidence indicators from threat reports, reducing manual IOC integration and query crafting workload for analysts.
  • Benefits include broad IOC discovery, accelerated detection engineering, and improved SOC efficiency for faster incident response and detection logic authoring.

Read Full Article

like

4 Likes

For uninterrupted reading, download the app