Offensive SIEM
Practical techniques for leveraging SIEM as an offensive discovery tool, helping defenders think like attackers to strengthen security from within.
Queries
See above - queries.md file.
Will keep getting updated when needed. The idea is to have layer on layer coverage using different event.codes/event.providers.
- Released queries for environmental PATHS, Kernel Drivers and Logon/Startup scripts etc during february 2026!
- Released queries for OpenSSL libraries and Schedule task / Services with missing binary paths during mars 2026!
Vulnerability Management
Queries for Vulnerability Management in file: vulnerabilitymanagement.md
Gives you an idea how you can enumerate
- Windows OS version and build status
- Attack Surface Reduction (ASR) Rules and find misconfigurations
- Windows Defender exclusions and find misconfigurations
- Windows Applocker rules and find misconfigurations
Ping us if/when you find something
We hope that you liked the presentation. Ping us if you (i would say when you) find vulnerabilities by using this method. A simple message like "one of your queries cathed good stuff".. is more then enough :) do it by commiting to the ping.md file or contact us in alternative ways! We would be happy to share your success!
The repo will assist you in having offensive mindset.
Repo is to share the material and queries that we talked about in our presentation:
Offensive SIEM - When The Blue Team Switches Perspective
SEC-T september 2025
⭐ https://www.youtube.com/watch?v=5nfL_4ek4dY
x33fcon updated talk june 2026 covering some new areas
⭐ https://youtu.be/dD_7AdEoj0k?is=CMp22Q9evBcqZe7L
We have included the most interesting ACL related parts and have tips & tricks.
Check out the outstanding webinars about windows local privilege escalation and windows endpoint misconfigurations which will assist you further on. There are more areas to look into.. This is only the starting point. If you build good queries in other areas - please share it with us so more in the community can use them.
The queries with ⭐ mark is extra highly relevant.
The topics down below with ⭐ is really good content.
Webinars
Oddvar Moes Windows Client Privilege Escalation ⭐
a must to watch, specially the ACL for binaries, services and schedule tasks.
Spencers Windows Endpoint Misconfigs ⭐
Topic 2 (Insecurely installed/conf Software) And Topic 5 (Insecure Services And Tasks)
password: P3yGQ+1y
DLL Hijacking
PATH entries and User-writable directories in the system PATH --> DLL Hijacking
SCCM / Software Center ⭐
Arbitrary File deletion --> Local privilege escalation
Other file operations
Logon scripts
Kernel drivers and privilege escalation
OpenSSLs openssl.cnf and privilege escalation
NSIS installer/uninstaller vulnerability
DotLocal Redirection vulnerability
Example of interesting areas to look into that we have not covered in presentation but we have queries for some of them.
- weak passwords in command_line - that are not following best practices / policies
- weak passwords or sensitive information in powershell admin scripts scriptblock event code: 4104. Search for strings: "SecureString","PSCredential","Password", "passwd"......
- weak passwords in registry - that are not following best practices / policies
- file creations/deletions of typical files holding sensitive information like passwords.txt, passwords.xslx, unattend.xml etc.
- AlwaysInstallElevated in Registry, Autologons (look if passwords is set)
- Windows Privileges - Look at 4672 (logon with special privileges) And 4704/4705 (assignment/removal of rights)
- Event code 5136 and 5137, AD objects.. look in to the fields: description, info and adminComment, if they have any plaintext passwords.
- Using process creation events and look for sc.exe setting services security descriptor using sdset or sysmons registry event code 13 and checking the ACL value (in binary format of SDDL) and converting it to readable ACL looking for weak ACL permissions set on the service it self.
- Do not assume that Program Files and similar admin-protected directories always have correct ACLs (Access Control Lists). It does happen that applications set incorrect default permissions and are far too permissive. CWE-732, CWE-284, CWE-276
- SeImpersonatePrivilege token on "Network Service or Local Service" accounts running processes in user writable paths --> Potato like attack to get SYSTEM
- etc..