A review of a community Microsoft Sentinel analytic for detecting CreepyDrive traffic found that the rule can be readily evaded because it relies on brittle, hardcoded URL and path matches tied to known samples. The detection was built to spot POLONIUM activity using OneDrive and the Microsoft Graph API for command-and-control, but researchers said attackers could bypass it through case changes, URL encoding, renamed folders or files, alternate Graph addressing methods such as item-ID access, and use of the beta API endpoint. The analysis also highlighted incomplete coverage for sovereign cloud Graph domains and dependence on TLS-inspected proxy logs.
Researchers proposed replacing sample-specific string matching with broader coverage of Graph paths and domains, including decoded URLs and case-insensitive matching across standard and alternate addressing patterns. They also recommended layering behavioral analytics to better distinguish malicious SaaS-based C2 from legitimate OneDrive use, including anomalous user agents, regular polling cadence, first-seen Graph activity, and consistent payload-size patterns. The findings underscore that detection for cloud-service abuse is more resilient when it focuses on attacker behavior rather than fixed URL indicators.

See real exploitation activity before you spend the cycle.
3 events from the most recent confirmed update back to the earliest known activity.
An article published on 2026-07-27 analyzed a community Microsoft Sentinel analytic for detecting POLONIUM-associated CreepyDrive traffic and argued it was easily bypassed through case changes, URL encoding, alternate Microsoft Graph paths, renamed files or folders, beta endpoints, and other gaps. The write-up also proposed broader URL coverage and behavioral analytics to improve detection of OneDrive-based C2.
Microsoft's Azure Sentinel repository published a community analytic rule named "CreepyDrive URLs" to detect Microsoft Graph API URL patterns associated with POLONIUM's CreepyDrive malware using OneDrive for command-and-control. The scheduled high-severity rule targets CommonSecurityLog data from supported network security connectors and is tagged to POLONIUM and ATT&CK techniques T1567.002 and T1102.002.
Microsoft published research detailing POLONIUM activity and infrastructure used to target organizations in Israel. The disclosure publicly documented the threat actor's operations and associated infrastructure.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedetect.fyi
Open sourcegithub.com
Open sourceattack.mitre.org
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.