
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
IMPORTANT: All code and detection logic in this repository is AI-generated. There is no guarantee that these scripts are correct, complete, safe, or suitable for any environment. Use these scripts entirely at your own risk. The repository author is not liable or responsible for any damage, outage, data loss, false positive, false negative, operational impact, or other harm caused by use of this content. Every script must be reviewed, tested, tuned, and verified by qualified personnel before deployment to any live production environment.
This repository, redsun-bluehammer-undefend-detection-pack, contains Microsoft Defender XDR Advanced Hunting queries written in Kusto Query Language (KQL). The queries are organized as technical detection packages for proof-of-concept attack chains involving RedSun, BlueHammer, UnDefend, Huntress-observed shared intrusion tooling, Microsoft Defender, Cloud Files, Volume Shadow Copy Service (VSS), Windows service behavior, local account manipulation, symbolic links, reparse points, and related Windows telemetry.
The content is designed for security research, detection engineering, lab validation, and controlled hunting workflows. It is not a drop-in production detection set. Each environment has different Defender XDR sensor coverage, event volumes, endpoint baselines, software inventory, and legitimate administrative behavior. You must validate both syntax and detection quality in your own tenant before enabling these queries as scheduled custom detections.
Source review verified on 2026-05-05 maps BlueHammer to CVE-2026-33825. NVD affected-platform data and Microsoft Defender release notes identify Microsoft Defender Antimalware Platform versions before 4.18.26030.3011 as affected. No public Microsoft CVE or vendor patch was verified for RedSun or UnDefend during this review; Huntress reported both remained unpatched as of 2026-04-20. This repository detects behaviors and Defender telemetry; it does not determine patch compliance by itself.
2026-05-05CVE-2026-33825; treat Defender Antimalware Platform 4.18.26030.3011 or later as the minimum verified patched baseline documented in this repository.The repository uses package folders for both detection content and support content. KQL-bearing folders use sequential numbering that starts at 01.
| Folder | Main Query | Standalone Queries | Purpose |
|---|---|---|---|
RedSun | 01_redsun_full_attack_chain.kql | 02 through 11 | Correlates Cloud Files, temporary payload staging, reparse or oplock telemetry, Storage Tiers COM activation, Defender-origin file writes, SYSTEM execution artifacts, and Microsoft detection names. |
BlueHammer | 01_bluehammer_full_attack_chain.kql | 02 through 17 | Correlates Defender update abuse, Cloud Files callbacks, VSS/SAM access, offline registry activity, password changes, service creation, token/process behavior, and Microsoft detection names. |
UnDefend | 01_undefend_full_attack_chain.kql | 02 through 09 | Correlates Defender registry reconnaissance, signature file access, update directory monitoring, WinDefend service monitoring, update or engine failure, MRT directory access, and health or staleness evidence after suspicious access. |
CrossFamily | 01_crossfamily_full_attack_chain.kql | 02 through 04 | Correlates Huntress-observed tooling execution from suspicious paths, BeigeBurrow follow-on tunnel activity, and recon commands near suspicious tooling. Hunting only. |
Exposure | 01_bluehammer_defender_platform_exposure.kql | none | Template exposure reporting for BlueHammer platform-version validation using a tenant-verified inventory source. |
ExternalTelemetry | n/a | n/a | Documentation-only VPN, firewall, identity, and SIEM correlation guidance that is intentionally kept out of endpoint KQL. |
The four full-chain detection packages (RedSun, BlueHammer, UnDefend, and CrossFamily) follow the same structure:
01_*_full_attack_chain.kql is the composite hunt. It runs all stage logic together and correlates evidence on the same device within a defined time window.| order by Timestamp desc.Stage, StageDescription, ProcessName, ProcessCommandLine, AccountName, Evidence, AdditionalContext, and ReportRefs so cross-stage output is easier to review.production/ subdirectory and are stricter than the top-level hunting queries.Exposure is a support package for inventory-driven exposure reporting, not a full-chain behavior hunt. ExternalTelemetry is documentation-only and does not contain endpoint KQL.
These queries are intended for Microsoft Defender XDR Advanced Hunting. They rely on table and column availability from Defender for Endpoint and related Defender XDR telemetry.
Commonly used tables include:
| Table | Typical Use |
|---|---|
DeviceFileEvents | File creation, modification, access, reads, path evidence, VSS or Defender file interactions. |
DeviceProcessEvents | Process creation, parent process context, command line, token and account context. |
DeviceImageLoadEvents | DLL loads such as cldapi.dll, wuapi.dll, samlib.dll, and offreg.dll. |
DeviceRegistryEvents | Registry key and value access, Cloud Files sync root registration, Defender path reconnaissance. |
DeviceNetworkEvents | Defender update package download signals and CDN URL access. |
DeviceEvents | Miscellaneous endpoint telemetry including named pipes, service events, antivirus detections, Microsoft detection names, service changes, FSCTL-like details, and sensor-dependent additional fields. |
Telemetry is not uniform across all tenants. Some low-level primitives, especially raw oplock, reparse point, object manager symbolic link, and service query telemetry, may not appear as explicit events. The queries therefore include opportunistic matching against ActionType and AdditionalFields where Defender XDR exposes those details.
Before production use, validate each full-chain detection package in this order: