Target Hunting Queries
Microsoft Sentinel's KQL (Kusto Query Language) enables defenders to craft precise, targeted queries that detect specific attack stages such as lateral movement or data exfiltration. By focusing on high-fidelity indicators and leveraging MITRE ATT&CK frameworks, hunters can reduce noise and prioritize critical threats. This section guides you through building structured, actionable queries for these scenarios.
Structuring Queries for Specific Attack Stages¶
Targeted queries should align with the MITRE ATT&CK framework to map tactics and techniques. For example, lateral movement often involves techniques like Remote Services or Pass the Hash, while data exfiltration may involve Data Transfer via DNS or Encrypted Communication.
Example 1: Detecting Lateral Movement via PSRemoting¶
// Identify suspicious PowerShell remoting commands
Process
| where Timestamp > ago(7d)
| where ProcessName == "powershell.exe"
| where CommandLine contains "Invoke-Command"
| where CommandLine contains "PSRemoting"
| project Timestamp, Computer, ProcessName, CommandLine, User
- Filters for PowerShell processes (
ProcessName == "powershell.exe").- Looks for
Invoke-Command with PSRemoting (common in lateral movement).- Projects relevant fields for analysis.
Contextual refinement:
Add filters for unusual users or hosts:
Example 2: Detecting Data Exfiltration via Large Outbound Traffic¶
// Identify large outbound network transfers
NetworkConnection
| where Timestamp > ago(24h)
| where Direction == "Outbound"
| where BytesTransferred > 10MB
| where RemoteIP != "192.168.0.0/16" and RemoteIP != "10.0.0.0/8"
| project Timestamp, SourceIP, DestinationIP, BytesTransferred, ProcessName
- Filters for outbound traffic (
Direction == "Outbound").- Detects transfers exceeding 10MB (adjust based on baseline).
- Excludes internal IPs to focus on external exfiltration.
Contextual refinement:
Check for encoded payloads or known malicious domains:
Best Practices for Targeted Query Development¶
- Define clear objectives: Start with a specific attack stage (e.g., "detect lateral movement using stolen credentials").
- Leverage MITRE ATT&CK: Map tactics (e.g., Lateral Movement) to techniques (e.g., Pass the Hash) for precise indicators.
- Combine multiple conditions: Use
and,or, andnotto narrow results. For example:
- Use temporal context: Filter by time ranges (
ago(7d),last 24h) to focus on recent activity. - Validate with context: Cross-check findings with logs (e.g.,
EventLogfor credential reuse) or process trees.
Key takeaways¶
- Targeted queries reduce noise by aligning with specific attack stages and MITRE ATT&CK techniques.
- Use precise filters (e.g.,
CommandLine,BytesTransferred) to identify suspicious behavior. - Combine conditions and contextual refinements to prioritize high-fidelity alerts.
- Regularly validate queries against your environment’s baseline to avoid false positives.
- Automate with correlation rules or custom log analytics rules for continuous monitoring.