Dikshant Lather.
Our Story Write Sign In Get Started
Home Our Story Stories Blueprints Advisory Resume Contact
Home / Stories / Topic

KQL

Topic • 20 Stories
Related: Cloud Security Azure DevSecOps Entra ID Microsoft Sentinel AI Security Threat Hunting DeviceProcessEvents
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Brute Force Attacks Followed by Successful Logon in Microsoft Sentinel

Correlate failed sign-ins followed by a successful authentication within a short time window to immediately flag compromised user accounts.

Incident Response 2 min read
0 0
Detecting Brute Force Attacks Followed by Successful Logon in Microsoft Sentinel
Dikshant Lather Dikshant Lather · Sep 25, 2026

Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL

Catch lateral movement and persistence tools (PsExec, Cobalt Strike PsExec service) by monitoring new Windows Service installations with KQL.

Threat Hunting 2 min read
0 0
Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Mass Exfiltration and File Downloads in SharePoint & OneDrive

Identify anomalous mass file download operations and data hoarding across SharePoint Online and OneDrive for Business using statistical KQL baseline thresholds.

Cloud Security 2 min read
0 0
Detecting Mass Exfiltration and File Downloads in SharePoint & OneDrive
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting MFA Fatigue and Push Notification Bombing in Microsoft Entra ID

Catch MFA push notification bombing attacks where attackers trigger repeated authentication requests until the victim accidentally approves access.

Identity Security 2 min read
0 0
Detecting MFA Fatigue and Push Notification Bombing in Microsoft Entra ID
Dikshant Lather Dikshant Lather · Sep 25, 2026

Hunting for Kerberoasting Attacks via Kerberos Service Ticket Requests (Event ID 4769)

Uncover Kerberoasting attacks targeting Active Directory Service Principal Names (SPNs) using KQL anomaly detection on Windows Security Event ID 4769.

Active Directory Security 2 min read
0 0
Hunting for Kerberoasting Attacks via Kerberos Service Ticket Requests (Event ID 4769)
Dikshant Lather Dikshant Lather · Sep 25, 2026

Identifying Rogue Azure Subscription Role Assignments and Privilege Escalation

Monitor high-privilege Azure RBAC grant operations (Owner, Contributor, User Access Administrator) in AzureActivity logs using proactive KQL alert rules.

Cloud Security 2 min read
0 0
Identifying Rogue Azure Subscription Role Assignments and Privilege Escalation
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Persistence via Windows Scheduled Task Creation Using KQL

Hunt for adversary persistence via unauthorized Windows Scheduled Tasks by parsing Security Event ID 4698 and DeviceProcessEvents in KQL.

Threat Hunting 2 min read
0 0
Detecting Persistence via Windows Scheduled Task Creation Using KQL
Dikshant Lather Dikshant Lather · Sep 25, 2026

Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL

Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL.

Endpoint Detection 2 min read
0 0
Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL

Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries.

Endpoint Detection 2 min read
0 0
Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL
« Previous Next »

Showing 10 to 18 of 20 results

1 2 3
Dikshant Lather.

Cybersecurity Consultant specializing in CSPM, Microsoft Defender for Cloud, and AI Security architecture. Open for consulting advisory.

Directory

  • Home
  • Our Story & Bio
  • Resume & Certs
  • Advisory Services
  • Security Blueprints
  • Contact & Inquiries

Publications

  • All Stories
  • Become a Contributor
  • RSS 2.0 Feed
  • Atom 1.0 Feed
  • XML Sitemap

Dispatch

Briefings on CSPM playbooks, Azure hardening, and AI defense patterns.

© 2026 Dikshant Lather • All rights reserved.

Privacy Terms Cookies
ESC
Navigate ↑↓ • Select ↵
Dikshant Lather.