Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
privilege-escalation windows-security detection-engineering microsoft-defender advanced-hunting redsun microsoft-defender-xdr defender-xdr kql-threathunting threat-detection-windows bluehammer undefend cve-2026-33825
-
Updated
Apr 20, 2026