Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
redsun-bluehammer-undefend-detection-pack — Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors. | Kitploit
Tools/GitHubGitHub/letlaka/redsun-bluehammer-undefend-detection-pack
Defensive ToolsVulnerability AnalysisCloud SecurityThreat IntelligenceIntrusion DetectionIncident ResponseLog Analysis
GitHubletlaka/redsun-bluehammer-undefend-detection-pack

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

redsun-bluehammer-undefend-detection-pack

Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.

View Repository
93235 months agoNot yet reviewed
Share

RedSun, BlueHammer, UnDefend, and CrossFamily Detection Pack

IMPORTANT: All code and detection logic in this repository is AI-generated. There is no guarantee that these scripts are correct, complete, safe, or suitable for any environment. Use these scripts entirely at your own risk. The repository author is not liable or responsible for any damage, outage, data loss, false positive, false negative, operational impact, or other harm caused by use of this content. Every script must be reviewed, tested, tuned, and verified by qualified personnel before deployment to any live production environment.

Overview

This repository, redsun-bluehammer-undefend-detection-pack, contains Microsoft Defender XDR Advanced Hunting queries written in Kusto Query Language (KQL). The queries are organized as technical detection packages for proof-of-concept attack chains involving RedSun, BlueHammer, UnDefend, Huntress-observed shared intrusion tooling, Microsoft Defender, Cloud Files, Volume Shadow Copy Service (VSS), Windows service behavior, local account manipulation, symbolic links, reparse points, and related Windows telemetry.

The content is designed for security research, detection engineering, lab validation, and controlled hunting workflows. It is not a drop-in production detection set. Each environment has different Defender XDR sensor coverage, event volumes, endpoint baselines, software inventory, and legitimate administrative behavior. You must validate both syntax and detection quality in your own tenant before enabling these queries as scheduled custom detections.

Source review verified on 2026-05-05 maps BlueHammer to CVE-2026-33825. NVD affected-platform data and Microsoft Defender release notes identify Microsoft Defender Antimalware Platform versions before 4.18.26030.3011 as affected. No public Microsoft CVE or vendor patch was verified for RedSun or UnDefend during this review; Huntress reported both remained unpatched as of 2026-04-20. This repository detects behaviors and Defender telemetry; it does not determine patch compliance by itself.

Verified Research Baseline

  • Last verified: 2026-05-05
  • BlueHammer: CVE-2026-33825; treat Defender Antimalware Platform 4.18.26030.3011 or later as the minimum verified patched baseline documented in this repository.
  • RedSun: no public Microsoft CVE or vendor patch was verified during the 2026-05-05 source review. Keep this package behavior-focused.
  • UnDefend: no public Microsoft CVE or vendor patch was verified during the 2026-05-05 source review. Keep this package behavior-focused.
  • Cross-family intrusion context: Huntress documented shared observed tooling, BeigeBurrow follow-on activity, and recon commands that are useful for hunting and enrichment, not deterministic proof by themselves.

Repository Layout

The repository uses package folders for both detection content and support content. KQL-bearing folders use sequential numbering that starts at 01.

FolderMain QueryStandalone QueriesPurpose
RedSun01_redsun_full_attack_chain.kql02 through 11Correlates Cloud Files, temporary payload staging, reparse or oplock telemetry, Storage Tiers COM activation, Defender-origin file writes, SYSTEM execution artifacts, and Microsoft detection names.
BlueHammer01_bluehammer_full_attack_chain.kql02 through 17Correlates Defender update abuse, Cloud Files callbacks, VSS/SAM access, offline registry activity, password changes, service creation, token/process behavior, and Microsoft detection names.
UnDefend01_undefend_full_attack_chain.kql02 through 09Correlates Defender registry reconnaissance, signature file access, update directory monitoring, WinDefend service monitoring, update or engine failure, MRT directory access, and health or staleness evidence after suspicious access.
CrossFamily01_crossfamily_full_attack_chain.kql02 through 04Correlates Huntress-observed tooling execution from suspicious paths, BeigeBurrow follow-on tunnel activity, and recon commands near suspicious tooling. Hunting only.
Exposure01_bluehammer_defender_platform_exposure.kqlnoneTemplate exposure reporting for BlueHammer platform-version validation using a tenant-verified inventory source.
ExternalTelemetryn/an/aDocumentation-only VPN, firewall, identity, and SIEM correlation guidance that is intentionally kept out of endpoint KQL.

Query Design Pattern

The four full-chain detection packages (RedSun, BlueHammer, UnDefend, and CrossFamily) follow the same structure:

  1. 01_*_full_attack_chain.kql is the composite hunt. It runs all stage logic together and correlates evidence on the same device within a defined time window.
  2. Numbered standalone scripts isolate individual stages. These are intended for troubleshooting, baseline analysis, custom detection prototyping, and false-positive review.
  3. Standalone scripts are expected to match the corresponding stage block in the full-chain query, except for final display-only ordering such as | order by Timestamp desc.
  4. Main queries emit normalized fields such as Stage, StageDescription, ProcessName, ProcessCommandLine, AccountName, Evidence, AdditionalContext, and ReportRefs so cross-stage output is easier to review.
  5. Conservative scheduled-detection candidates, where present, live under each package's production/ subdirectory and are stricter than the top-level hunting queries.

Exposure is a support package for inventory-driven exposure reporting, not a full-chain behavior hunt. ExternalTelemetry is documentation-only and does not contain endpoint KQL.

Microsoft Defender XDR Requirements

These queries are intended for Microsoft Defender XDR Advanced Hunting. They rely on table and column availability from Defender for Endpoint and related Defender XDR telemetry.

Commonly used tables include:

TableTypical Use
DeviceFileEventsFile creation, modification, access, reads, path evidence, VSS or Defender file interactions.
DeviceProcessEventsProcess creation, parent process context, command line, token and account context.
DeviceImageLoadEventsDLL loads such as cldapi.dll, wuapi.dll, samlib.dll, and offreg.dll.
DeviceRegistryEventsRegistry key and value access, Cloud Files sync root registration, Defender path reconnaissance.
DeviceNetworkEventsDefender update package download signals and CDN URL access.
DeviceEventsMiscellaneous endpoint telemetry including named pipes, service events, antivirus detections, Microsoft detection names, service changes, FSCTL-like details, and sensor-dependent additional fields.

Telemetry is not uniform across all tenants. Some low-level primitives, especially raw oplock, reparse point, object manager symbolic link, and service query telemetry, may not appear as explicit events. The queries therefore include opportunistic matching against ActionType and AdditionalFields where Defender XDR exposes those details.

Recommended Validation Workflow

Before production use, validate each full-chain detection package in this order:

Download Tool