{"id":59672,"date":"2026-06-03T12:40:12","date_gmt":"2026-06-03T12:40:12","guid":{"rendered":"https:\/\/www.eccentrix.ca\/?p=59672"},"modified":"2026-06-29T13:13:35","modified_gmt":"2026-06-29T13:13:35","slug":"microsoft-sentinel-kql","status":"publish","type":"post","link":"https:\/\/www.eccentrix.ca\/en\/eccentrix-corner\/microsoft-sentinel-kql\/","title":{"rendered":"Microsoft Sentinel KQL: An Introduction for Threat Hunting"},"content":{"rendered":"\t\t<div data-elementor-type=\"wp-post\" data-elementor-id=\"59672\" class=\"elementor elementor-59672 elementor-59659\" data-elementor-post-type=\"post\">\n\t\t\t\t<div class=\"elementor-element elementor-element-1a96984f e-flex e-con-boxed e-con e-parent\" data-id=\"1a96984f\" data-element_type=\"container\">\n\t\t\t\t\t<div class=\"e-con-inner\">\n\t\t\t\t<div class=\"elementor-element elementor-element-58bac4a elementor-widget elementor-widget-heading\" data-id=\"58bac4a\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Introduction to Microsoft Sentinel KQL<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4e9eab47 elementor-widget elementor-widget-text-editor\" data-id=\"4e9eab47\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Most organizations run \u201creactive\u201d detection: an alert fires, you investigate, you remediate. Threat hunting changes the logic: you form hypotheses, explore data, and look for weak signals at scale, at a time when attackers automate everything.<\/p><p>Microsoft Sentinel is particularly well suited to this work, as long as you have a basic command of KQL (Kusto Query Language). The goal of this article isn\u2019t to drown you in syntax: it\u2019s to give you a method, key commands, and \u201creusable\u201d queries to hunt effectively through logs.<\/p>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-bc4d7e8 elementor-widget elementor-widget-heading\" data-id=\"bc4d7e8\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">What you\u2019ll learn in this guide<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-2278df5 elementor-widget elementor-widget-text-editor\" data-id=\"2278df5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li>Understand the role of threat hunting in Sentinel<\/li><li>Know where to look: tables, time ranges, and useful fields<\/li><li>Master essential KQL commands (<em>search, where, project, summarize, join, parse, mv-expand<\/em>)<\/li><li>Build hunting queries to spot advanced behaviors<\/li><li>Analyze and interpret results to move into the \u201cinvestigation\u201d phase<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-59353c0 elementor-widget elementor-widget-heading\" data-id=\"59353c0\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">Threat hunting vs detection vs investigation (in 30 seconds)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e978d44 elementor-widget elementor-widget-text-editor\" data-id=\"e978d44\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><strong>Detection<\/strong>: rules\/analytics based on known events (alerts).<\/li><li><strong>Investigation<\/strong>: you follow an alert and reconstruct an event chain.<\/li><li><strong>Threat hunting<\/strong>: you start from a hypothesis (e.g., \u201cquiet lateral movement\u201d) and explore data to find traces.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a5dd235 elementor-widget elementor-widget-heading\" data-id=\"a5dd235\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Prerequisites (so hunting is actually useful)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-28554e7 elementor-widget elementor-widget-text-editor\" data-id=\"28554e7\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>Before writing queries, make sure you have:<\/p><ul><li><strong>Connectors<\/strong>\u00a0enabled (Microsoft 365, Azure, Defender, Windows, etc.)<\/li><li>Consistent\u00a0<strong>retention<\/strong>\u00a0(otherwise you hunt over 7 days and miss the signal)<\/li><li>A naming and tagging\u00a0<strong>convention<\/strong>\u00a0(workspaces, tables, VIP accounts)<\/li><li>A clear objective: \u201creduce time to detect,\u201d \u201cdetect exfiltration,\u201d etc.<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3b980f5 elementor-widget elementor-widget-heading\" data-id=\"3b980f5\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">SC-200 module to expand (what we\u2019ll cover)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-d7e403f elementor-widget elementor-widget-text-editor\" data-id=\"d7e403f\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The module \u201cCreate queries for Microsoft Sentinel using KQL\u201d aims to:<\/p><ul><li>Build KQL statements for Microsoft Sentinel<\/li><li>Analyze query results<\/li><li>Generate multi-table queries<\/li><li>Use Sentinel data through KQL<\/li><\/ul><div class=\"mb-1 mt-2 whitespace-pre-line leading-relaxed first:mt-0\" data-sentry-component=\"P\" data-sentry-source-file=\"p.tsx\">In this article, we take those objectives and apply them with a field-oriented, hunting-first approach.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-9ea72ee elementor-widget elementor-widget-heading\" data-id=\"9ea72ee\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">1) Where to hunt: understanding tables and the \u201cdatastore\u201d<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-4150c60 elementor-widget elementor-widget-text-editor\" data-id=\"4150c60\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>In Sentinel, your data is stored in Log Analytics as <strong>tables<\/strong>. Each connector feeds one or more tables.<\/p><p><strong>How to discover available tables<\/strong><\/p><p>Start by exploring your data ecosystem:<\/p><ol><li>Global search:<\/li><\/ol><ul><li><code class=\"not-prose rounded bg-neutral-100 px-1 py-0.5 font-mono text-sm text-neutral-800\">search \"keyword\"<\/code><\/li><\/ul><ol start=\"2\"><li>Quick time filter:<\/li><\/ol><ul><li><code class=\"not-prose rounded bg-neutral-100 px-1 py-0.5 font-mono text-sm text-neutral-800\">| where TimeGenerated &gt; ago(24h)<\/code><\/li><\/ul><ol start=\"3\"><li>Project only the fields you need:<\/li><\/ol><ul><li><code class=\"not-prose rounded bg-neutral-100 px-1 py-0.5 font-mono text-sm text-neutral-800\">| project TimeGenerated, Computer, Account, IPAddress, OperationName<\/code><\/li><\/ul><div class=\"mb-1 mt-2 whitespace-pre-line leading-relaxed first:mt-0\" data-sentry-component=\"P\" data-sentry-source-file=\"p.tsx\">Tip: avoid hunting without a time constraint. Start with 1 hour, then 24 hours, then 7 days.<\/div>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dcd436e elementor-widget elementor-widget-heading\" data-id=\"dcd436e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">2) Essential KQL commands (the hunter\u2019s \u201ckit\u201d)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-b35b6a0 elementor-widget elementor-widget-text-editor\" data-id=\"b35b6a0\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<div data-sentry-component=\"P\" data-sentry-source-file=\"p.tsx\">These are the commands you\u2019ll use 80% of the time.<\/div><div data-sentry-component=\"P\" data-sentry-source-file=\"p.tsx\">\u00a0<\/div><div data-sentry-component=\"P\" data-sentry-source-file=\"p.tsx\"><strong>where (filter)<\/strong><\/div><ul><li><code>| where Account contains \"admin\"<\/code><\/li><li><code>| where IPAddress startswith \"10.\"<\/code><\/li><\/ul><p><strong>project\u00a0(select columns)<\/strong><\/p><ul><li><code>| project TimeGenerated, Account, IPAddress, ActionType<\/code><\/li><\/ul><p><strong>extend\u00a0(create a field)<\/strong><\/p><ul><li><code>| extend Hour = datetime_part(\"hour\", TimeGenerated)<\/code><\/li><\/ul><p><strong>summarize\u00a0(aggregate)<\/strong><\/p><ul><li><code>| summarize count() by Account<\/code><\/li><li><code>| summarize dcount(IPAddress) by Account<\/code><\/li><\/ul><p><strong>order by and take<\/strong><\/p><ul><li><code>| order by TimeGenerated desc<\/code><\/li><li><code>| take 50<\/code><\/li><\/ul><p><strong>join\u00a0(correlate)<\/strong><\/p><ul><li><code>| join kind=inner (...) on DeviceId<\/code><\/li><\/ul><p><strong>parse\u00a0\/\u00a0extract\u00a0(extract)<\/strong><\/p><ul><li>Useful for semi-structured fields.<\/li><\/ul><p><strong>mv-expand (expand arrays)<\/strong><\/p><ul><li>Useful when a field contains a list (e.g., IPs, URLs).<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a2d183c elementor-widget elementor-widget-heading\" data-id=\"a2d183c\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">3) \u201cHunting\u201d query patterns (ready to copy)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-795c4bd elementor-widget elementor-widget-text-editor\" data-id=\"795c4bd\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p>The examples below are <strong>patterns<\/strong>. Adapt the tables based on your connectors (Defender, Azure AD\/Entra, M365, etc.).<\/p><p><strong>A) Detect abnormal authentication (impossible travel \/ unexpected country)<\/strong><\/p><p class=\"shiki one-light\" tabindex=\"0\"><code><span class=\"line\">SigninLogs<\/span><br \/>\n<span class=\"line\">| where TimeGenerated &gt; ago(24h)<\/span><br \/>\n<span class=\"line\">| where ResultType == 0<\/span><br \/>\n<span class=\"line\">| summarize Countries = make_set(LocationDetails.countryOrRegion) by UserPrincipalName<\/span><br \/>\n<span class=\"line\">| where array_length(Countries) &gt; 1<\/span><\/code><\/p><p><strong>B) Count MFA \/ sign-in failures (noise vs signal)<\/strong><\/p><p><code><span class=\"line\">SigninLogs<\/span><br \/>\n<span class=\"line\">| where TimeGenerated &gt; ago(24h)<\/span><br \/>\n<span class=\"line\">| summarize Failures = countif(ResultType != 0), Success = countif(ResultType == 0) by UserPrincipalName<\/span><br \/>\n<span class=\"line\">| where Failures &gt; 10 and Success &gt; 0<\/span><br \/>\n<span class=\"line\">| order by Failures desc<\/span><\/code><\/p><p><strong>C) Broad search (when you only have one clue)<\/strong><\/p><p class=\"shiki one-light\" tabindex=\"0\"><code><span class=\"line\">search \"rundll32\"<\/span><br \/>\n<span class=\"line\">| where TimeGenerated &gt; ago(7d)<\/span><br \/>\n<span class=\"line\">| take 200<\/span><\/code><\/p><p><strong>D) Spot suspicious PowerShell executions (example)<\/strong><\/p><p class=\"shiki one-light\" tabindex=\"0\"><code><span class=\"line\">DeviceProcessEvents<\/span><br \/>\n<span class=\"line\">| where TimeGenerated &gt; ago(24h)<\/span><br \/>\n<span class=\"line\">| where FileName in~ (\"powershell.exe\", \"pwsh.exe\")<\/span><br \/>\n<span class=\"line\">| where ProcessCommandLine has_any (\"-enc\", \"IEX\", \"DownloadString\", \"FromBase64String\")<\/span><br \/>\n<span class=\"line\">| project TimeGenerated, DeviceName, AccountName, ProcessCommandLine<\/span><br \/>\n<span class=\"line\">| order by TimeGenerated desc<\/span><\/code><\/p><p><strong>E) Correlate a user + a device (join)<\/strong><\/p><pre class=\"shiki one-light\" tabindex=\"0\"><code><span class=\"line\">let suspiciousUsers = SigninLogs<\/span>\n<span class=\"line\">| where TimeGenerated &gt; ago(24h)<\/span>\n<span class=\"line\">| where ResultType == 0<\/span>\n<span class=\"line\">| summarize by UserPrincipalName;<\/span>\n\n<span class=\"line\">DeviceLogonEvents<\/span>\n<span class=\"line\">| where TimeGenerated &gt; ago(24h)<\/span>\n<span class=\"line\">| join kind=inner suspiciousUsers on $left.AccountUpn == $right.UserPrincipalName<\/span>\n<span class=\"line\">| project TimeGenerated, DeviceName, AccountUpn, LogonType<\/span><\/code><\/pre>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-dc7296e elementor-widget elementor-widget-heading\" data-id=\"dc7296e\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h3 class=\"elementor-heading-title elementor-size-default\">4) How to analyze results (without fooling yourself)<\/h3>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-844c940 elementor-widget elementor-widget-text-editor\" data-id=\"844c940\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<p><strong>Avoid classic false positives:<\/strong><\/p><ul><li>Service accounts and automation accounts<\/li><li>VPN\/proxy hops (same user, different IP)<\/li><li>Internal scans (security tools)<\/li><\/ul><p><strong>Move from \u201clist\u201d to \u201cstory\u201d:<\/strong><\/p><p>A good hunting result should let you tell:<\/p><ul><li>Who? (account)<\/li><li>What? (action)<\/li><li>Where? (device, IP, country)<\/li><li>When? (timeline)<\/li><li>What next? (potential impact)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-ac2a5c4 elementor-widget elementor-widget-heading\" data-id=\"ac2a5c4\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">External links (useful references)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-a53757c elementor-widget elementor-widget-text-editor\" data-id=\"a53757c\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><a href=\"https:\/\/learn.microsoft.com\/en-ca\/kusto\/query\/?view=microsoft-fabric\" target=\"_blank\" rel=\"noopener\">KQL documentation (Microsoft Learn)<\/a><\/li><li><a href=\"https:\/\/learn.microsoft.com\/en-ca\/azure\/sentinel\/hunting?tabs=defender-portal\" target=\"_blank\" rel=\"noopener\">Microsoft Sentinel &#8211; \u201cHunting\u201d (concepts)<\/a><\/li><li><a href=\"https:\/\/learn.microsoft.com\/en-ca\/azure\/azure-monitor\/reference\/tables-category\" target=\"_blank\" rel=\"noopener\">Tables and schemas (Log Analytics)<\/a><\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e6f1e72 elementor-widget elementor-widget-heading\" data-id=\"e6f1e72\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Your next steps<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-962f181 elementor-widget elementor-widget-text-editor\" data-id=\"962f181\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ol><li>Pick onr hunting hypothesis (e.g., encoded PowerShell execution).<\/li><li>Run the query over 24 hours, then 7 days.<\/li><li>Add one correlation (<code class=\"not-prose rounded bg-neutral-100 px-1 py-0.5 font-mono text-sm text-neutral-800\">join<\/code>) to enrich context.<\/li><li>Turn your query into a reusable rule \/ workbook \/ hunting query.<\/li><\/ol>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-f703c45 elementor-widget elementor-widget-heading\" data-id=\"f703c45\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">Recommended certification & training paths (practical options)<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-e06f3a5 elementor-widget elementor-widget-text-editor\" data-id=\"e06f3a5\" data-element_type=\"widget\" data-widget_type=\"text-editor.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t\t\t<ul><li><strong>Microsoft Security Operations Analyst: <\/strong><a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/microsoft\/security\/microsoft-certified-security-operations-analyst-associate-sc200\/\" target=\"_blank\" rel=\"noopener\">SC-200<\/a>\u00a0(Sentinel, Defender, investigation)<\/li><li><strong>Security fundamentals: <\/strong><a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/microsoft\/security\/microsoft-certified-security-compliance-and-identity-fundamentals-sc900\/\" target=\"_blank\" rel=\"noopener\">SC-900<\/a>\u00a0(if you\u2019re starting out)<\/li><li><strong>Sentinel specialization: <\/strong><a href=\"https:\/\/www.eccentrix.ca\/en\/courses\/microsoft\/security\/configure-siem-security-operations-using-microsoft-sentinel-sc-5001\/\" target=\"_blank\" rel=\"noopener\">SC-5001<\/a>\u00a0(intermediate to advanced)<\/li><\/ul>\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-3099cda elementor-widget elementor-widget-heading\" data-id=\"3099cda\" data-element_type=\"widget\" data-widget_type=\"heading.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t<h2 class=\"elementor-heading-title elementor-size-default\">FAQ<\/h2>\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<div class=\"elementor-element elementor-element-7a5c4f7 elementor-widget elementor-widget-accordion\" data-id=\"7a5c4f7\" data-element_type=\"widget\" data-widget_type=\"accordion.default\">\n\t\t\t\t<div class=\"elementor-widget-container\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion\">\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1281\" class=\"elementor-tab-title\" data-tab=\"1\" role=\"button\" aria-controls=\"elementor-tab-content-1281\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Do I need to be a developer to use KQL?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1281\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"1\" role=\"region\" aria-labelledby=\"elementor-tab-title-1281\"><p>No. KQL is designed for log analysis. With just a few commands (where, project, summarize), you can already produce useful results.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1282\" class=\"elementor-tab-title\" data-tab=\"2\" role=\"button\" aria-controls=\"elementor-tab-content-1282\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">What is the difference between a hunting query and an analysis rule?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1282\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"2\" role=\"region\" aria-labelledby=\"elementor-tab-title-1282\"><p>A hunting query is exploratory (hypothesis, research). An analysis rule automatically generates alerts.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1283\" class=\"elementor-tab-title\" data-tab=\"3\" role=\"button\" aria-controls=\"elementor-tab-content-1283\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">Which tables should I use first?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1283\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"3\" role=\"region\" aria-labelledby=\"elementor-tab-title-1283\"><p>Start with the tables linked to your main connectors (SigninLogs, AuditLogs, DeviceProcessEvents, DeviceNetworkEvents, etc.).<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t<div class=\"elementor-accordion-item\">\n\t\t\t\t\t<h6 id=\"elementor-tab-title-1284\" class=\"elementor-tab-title\" data-tab=\"4\" role=\"button\" aria-controls=\"elementor-tab-content-1284\" aria-expanded=\"false\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon elementor-accordion-icon-left\" aria-hidden=\"true\">\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-closed\"><svg class=\"e-font-icon-svg e-fas-plus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H272V64c0-17.67-14.33-32-32-32h-32c-17.67 0-32 14.33-32 32v144H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h144v144c0 17.67 14.33 32 32 32h32c17.67 0 32-14.33 32-32V304h144c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t<span class=\"elementor-accordion-icon-opened\"><svg class=\"e-font-icon-svg e-fas-minus\" viewBox=\"0 0 448 512\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\"><path d=\"M416 208H32c-17.67 0-32 14.33-32 32v32c0 17.67 14.33 32 32 32h384c17.67 0 32-14.33 32-32v-32c0-17.67-14.33-32-32-32z\"><\/path><\/svg><\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t\t\t<\/span>\n\t\t\t\t\t\t\t\t\t\t\t\t<a class=\"elementor-accordion-title\" tabindex=\"0\">How to reduce false positives?<\/a>\n\t\t\t\t\t<\/h6>\n\t\t\t\t\t<div id=\"elementor-tab-content-1284\" class=\"elementor-tab-content elementor-clearfix\" data-tab=\"4\" role=\"region\" aria-labelledby=\"elementor-tab-title-1284\"><p>Create exception lists (service accounts, VPN IPs), add context (join), and use thresholds (summarize) adapted to your environment.<\/p><\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t\t\t\t<\/div>\n\t\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t\t\t<\/div>\n\t\t","protected":false},"excerpt":{"rendered":"<p>Introduction to Microsoft Sentinel KQL Most organizations run \u201creactive\u201d detection: an alert fires, you investigate, you remediate. Threat hunting changes the logic: you form hypotheses, explore data, and look for weak signals at scale, at a time when attackers automate everything. Microsoft Sentinel is particularly well suited to this work, as long as you have [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":59660,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jet_sm_ready_style":"","_jet_sm_style":"","_jet_sm_controls_values":"","_jet_sm_fonts_collection":"","_jet_sm_fonts_links":"","footnotes":""},"categories":[84],"tags":[159,97,99,104],"class_list":["post-59672","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-eccentrix-corner","tag-cloud","tag-certification","tag-cybersecurity","tag-microsoft-azure"],"_links":{"self":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59672","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/comments?post=59672"}],"version-history":[{"count":4,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59672\/revisions"}],"predecessor-version":[{"id":59685,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/posts\/59672\/revisions\/59685"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media\/59660"}],"wp:attachment":[{"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/media?parent=59672"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/categories?post=59672"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.eccentrix.ca\/en\/wp-json\/wp\/v2\/tags?post=59672"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}