INNER CODE UNIT · Python

generate_kql_detection

magicsword-io/LOLRMM · bin/generate_detections.py:276

def generate_kql_detection():
    """Generate a KQL detection for Microsoft Defender for Endpoint"""

    kql_detection = {
        "name": "Generic RMM Domain Detection for Microsoft Defender for Endpoint",
        "id": "kql-rmm-001",
        "description": "Detects network connections to known RMM domains",
        "author": "LOLRMM Project",
        "date": datetime.now().strftime("%Y/%m/%d"),
        "query": """// Detecting Unauthorized RMM Instances in Your MDE Environment
// Note: this query targets Microsoft Defender for Endpoint (DeviceNetworkEvents.Timestamp).
// For Microsoft Sentinel, replace both `Timestamp` references with `TimeGenerated`.
// Wildcard CSV entries are normalized to domain suffixes, then matched with a host boundary.
let SanctionRMM = dynamic([\"bomgarcloud.com\"]); // Replace with your approved RMM domains, e.g. dynamic([\"teamviewer.com\", \"anydesk.com\"])
let RMMList = externaldata(URI: string, RMMTool: string)
    [h'https://raw.githubusercontent.com/magicsword-io/LOLRMM/main/website/public/api/rmm_domains.csv']
    with (format=\"csv\", ignoreFirstRecord=true)
    | extend RawURI = tolower(trim(@\"[ \\t\\r\\n]+\", URI))

View source record →

📰 Research Paper
Loading…
⏳ Fetching content…