<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1562.001 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1562.001/</link><description>Recent content in T1562.001 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Wed, 27 May 2026 13:42:33 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1562.001/index.xml" rel="self" type="application/rss+xml"/><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Hunting Query: Rootkit Network Evasion Detection via Firewall-EDR Telemetry Delta</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</link><pubDate>Wed, 27 May 2026 08:36:31 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14337/</guid><description>New hunting query detects kernel-level rootkits bypassing EDR network telemetry by comparing perimeter firewall logs against Microsoft Defender for Endpoint data streams.</description></item><item><title>Entra ID Hunting Pack: Defense Weakening and Privilege Abuse Detection</title><link>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</link><pubDate>Tue, 26 May 2026 06:12:52 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-26-pr-14240/</guid><description>Three hunting queries targeting silent defense weakening techniques and off-hours privilege escalation in Entra ID environments.</description></item><item><title>ETW-Resistant .NET Fileless Injection Detection via Kernel-Level CLR Loading</title><link>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</link><pubDate>Thu, 21 May 2026 12:14:25 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-21-pr-14314/</guid><description>New hunting query detects fileless .NET execution even when attackers patch ETW by monitoring kernel-level .NET runtime DLL loading in native processes and untrusted paths.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Entra ID Attack Chain Detection: 5 New Hunting Queries Target Application Layer Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</link><pubDate>Wed, 13 May 2026 10:29:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</guid><description>Five hunting queries expose OAuth consent abuse, privileged escalation, and Conditional Access evasion used in Midnight Blizzard and Storm-0558 campaigns.</description></item><item><title>SOC Prime CCF: Three New Detection Rules for Platform Security Events</title><link>http://sentinelchangelog.net/posts/2026-04-08-pr-13636/</link><pubDate>Wed, 08 Apr 2026 09:50:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-08-pr-13636/</guid><description>SOC Prime solution adds Analytic Rules detecting platform administration events including tenant deletion and successful logins from malicious IPs.</description></item><item><title>Microsoft Security Copilot: Six New Detections for AI Assistant Abuse</title><link>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</link><pubDate>Fri, 27 Mar 2026 05:01:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</guid><description>New analytic rules target jailbreak attempts, external access, plugin tampering, and file upload disabling - covering major AI security attack vectors.</description></item></channel></rss>