Susheel Thapa
Skip to content
>_ST
Microsoft SentinelKQLThreat HuntingSOCSIEM

Threat Hunting in Azure: Essential KQL Patterns for SOC Analysts

Practical KQL query patterns for uncovering anomalous authentication, privilege escalation, and lateral movement in Microsoft Sentinel SIEM.

Proactive threat hunting differs from reactive alert triage. Rather than waiting for predefined analytics rules to trigger, threat hunters formulate hypotheses based on adversary TTPs and query large-scale telemetry data directly.

Detecting Password Spray Attacks

SigninLogs
| where TimeGenerated > ago(7d)
| where ResultType == "50126" // Invalid username or password
| summarize FailedCount = count(), TargetUsers = dcount(UserPrincipalName) by IPAddress, bin(TimeGenerated, 10m)
| where TargetUsers >= 5 and FailedCount >= 10
| project TimeGenerated, IPAddress, TargetUsers, FailedCount
| order by TargetUsers desc

Uncovering Rare Parent-Child Process Trees

Adversaries spawning interactive shells from web servers or database processes:

DeviceProcessEvents
| where TimeGenerated > ago(3d)
| where InitiatingProcessFileName in~ ("w3wp.exe", "nginx", "httpd", "sqlservr.exe")
| where FileName in~ ("cmd.exe", "powershell.exe", "sh", "bash", "whoami", "curl")
| project TimeGenerated, DeviceName, InitiatingProcessFileName, FileName, ProcessCommandLine