INNER CODE UNIT · Python
generate_kql_detection
magicsword-io/LOLRMM · bin/generate_detections.py:276
def generate_kql_detection():
"""Generate a KQL detection for Microsoft Defender for Endpoint"""
kql_detection = {
"name": "Generic RMM Domain Detection for Microsoft Defender for Endpoint",
"id": "kql-rmm-001",
"description": "Detects network connections to known RMM domains",
"author": "LOLRMM Project",
"date": datetime.now().strftime("%Y/%m/%d"),
"query": """// Detecting Unauthorized RMM Instances in Your MDE Environment
// Note: this query targets Microsoft Defender for Endpoint (DeviceNetworkEvents.Timestamp).
// For Microsoft Sentinel, replace both `Timestamp` references with `TimeGenerated`.
// Wildcard CSV entries are normalized to domain suffixes, then matched with a host boundary.
let SanctionRMM = dynamic([\"bomgarcloud.com\"]); // Replace with your approved RMM domains, e.g. dynamic([\"teamviewer.com\", \"anydesk.com\"])
let RMMList = externaldata(URI: string, RMMTool: string)
[h'https://raw.githubusercontent.com/magicsword-io/LOLRMM/main/website/public/api/rmm_domains.csv']
with (format=\"csv\", ignoreFirstRecord=true)
| extend RawURI = tolower(trim(@\"[ \\t\\r\\n]+\", URI))