Skip to content

Add next MDE detection-first content batch for DetLab #2

Description

@egrexsec

Objective

Expand the detection-first markdown knowledge library with the next MDE-focused content batch so DetLab can render a fuller investigation chain beyond the current four entries.

Why this next

Current MDE entries cover:

  • Encoded PowerShell
  • Office Spawned PowerShell
  • Suspicious Rundll32
  • Scheduled Task Creation

The next useful batch should fill the obvious adjacent investigation pivots still missing from that chain.

Scope

Add 4 new markdown entries under mde/advanced-hunting/detections/ using templates/detlab-detection-template.md:

  1. PowerShell Download Cradle

    • direct ATT&CK mapping
    • executable KQL query
    • triage steps
    • investigation steps
    • false positives
    • related detections linking back to DET-3101, DET-3102, DET-3103, and DET-3104 where appropriate
  2. Certutil Download

    • direct ATT&CK mapping
    • executable KQL query
    • triage + investigation guidance
    • artifact collection notes
    • response actions
  3. LSASS Access

    • direct ATT&CK mapping
    • executable KQL query
    • DFIR artifact guidance
    • escalation guidance
    • related detections for credential-access follow-on investigation
  4. Network Beaconing

    • direct ATT&CK mapping
    • executable KQL query
    • hunting guidance
    • cloud/telemetry notes if relevant
    • graph edges from execution / staging detections into follow-on C2 behavior

Content rules

  • Keep stable DET-#### IDs.
  • Use the shared frontmatter schema already adopted in the repo.
  • Ensure each entry parses cleanly through DetLab markdown ingestion.
  • Prefer relationships that form a usable analyst flow rather than isolated detections.
  • Keep queries executable-style, not placeholder prose.

Suggested PR scope

A single PR should include:

  • the 4 new markdown entries
  • README touch-ups only if needed for discoverability
  • no schema churn unless a real parser/rendering gap is found

Verification

  • DetLab markdown load from mde/advanced-hunting returns 8 total detections.
  • Each new entry builds a non-empty workspace.
  • Query language renders correctly for each new entry.
  • Related detection graph is non-empty where relationships are declared.
  • Existing 4 MDE entries remain intact.

Nice-to-have

  • If one of the four needs unmapped supporting context, document it with explicit rationale instead of over-claiming ATT&CK certainty.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions