Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
-
Updated
May 5, 2026
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
CVE-2026-41091 RedSun | Microsoft Defender LPE exploit. Low-privileged users gain NT AUTHORITY\SYSTEM - via Cloud Files API + NTFS junction trickery. Forces Defender to write malicious payloads to System32 with SYSTEM rights - Actively exploited in wild. CVSS 7.8. Patch: Defender Engine 1.1.26040.8. Educational & Legal uses only.
Password Recovery Tool Based on CopyFail and RedSun as Main Exploits
To associate your repository with the redsun topic, visit your repo's landing page and select "manage topics."