Microsoft SentinelKQLThreat HuntingSOCSIEM
Threat Hunting in Azure: Essential KQL Patterns for SOC Analysts
Practical KQL query patterns for uncovering anomalous authentication, privilege escalation, and lateral movement in Microsoft Sentinel SIEM.
Proactive threat hunting differs from reactive alert triage. Rather than waiting for predefined analytics rules to trigger, threat hunters formulate hypotheses based on adversary TTPs and query large-scale telemetry data directly.
Detecting Password Spray Attacks
SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == "50126" // Invalid username or password
| summarize FailedCount = count(), TargetUsers = dcount(UserPrincipalName) by IPAddress, bin(TimeGenerated, 10m)
| where TargetUsers >= 5 and FailedCount >= 10
| project TimeGenerated, IPAddress, TargetUsers, FailedCount
| order by TargetUsers desc
Uncovering Rare Parent-Child Process Trees
Adversaries spawning interactive shells from web servers or database processes:
DeviceProcessEvents
| where TimeGenerated > ago(3d)
| where InitiatingProcessFileName in~ ("w3wp.exe", "nginx", "httpd", "sqlservr.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "sh", "bash", "whoami", "curl")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine