Dikshant Lather · Sep 25, 2026 Detecting Persistence via Windows Scheduled Task Creation Using KQL Hunt for adversary persistence via unauthorized Windows Scheduled Tasks by parsing Security Event ID 4698 and DeviceProcessEvents in KQL. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries. Endpoint Detection 2 min read 0 0