Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
Sentinel / Microsoft Defender hunting queries built from each ransomware group's known tools and MITRE ATT&CK techniques. Use them as starting points for threat hunting — validate table/column names against your own workspace schema before turning any of these into a production alert rule.
T1489
T1574.001
T1482
T1486
T1548.002
T1211
T1110.003
T1482
T1021.001
T1574.001
T1219
T1211
T1484.001
T1090
T1486
T1055.001
T1190
T1482
T1021.002
T1021.002
T1567.002
T1018
T1071.001
T1649
T1190
T1567.002
T1490
T1048
T1482
T1567.002
T1486
T1484.001
T1087.002
T1490
T1486
T1567.002
T1489
T1572
T1537
T1083
T1211
T1489
T1003.001
T1087.002
T1105
T1046
T1211
T1564.006
T1486
T1211
T1219
T1211
T1021.002
T1070
T1071.001
T1557.001
T1218.010
T1083
T1190
T1489
T1505.003
T1557
T1135
T1219
T1021.002
T1537