Dikshant Lather.
Our Story Write Sign In Get Started
Home Our Story Stories Blueprints Advisory Resume Contact
Home / Stories / Topic

KQL

Topic • 20 Stories
Related: Cloud Security Azure DevSecOps Entra ID Microsoft Sentinel AI Security Threat Hunting DeviceProcessEvents
Dikshant Lather Dikshant Lather · Sep 25, 2026

Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL

Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries.

Endpoint Detection 2 min read
0 0
Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL
Dikshant Lather Dikshant Lather · Sep 25, 2026

Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL

Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL.

Endpoint Detection 2 min read
0 0
Spotting LSASS Memory Dumping via Comsvcs.dll and Procdump in KQL
« Previous Next »

Showing 19 to 20 of 20 results

1 2 3
Dikshant Lather.

Cybersecurity Consultant specializing in CSPM, Microsoft Defender for Cloud, and AI Security architecture. Open for consulting advisory.

Directory

  • Home
  • Our Story & Bio
  • Resume & Certs
  • Advisory Services
  • Security Blueprints
  • Contact & Inquiries

Publications

  • All Stories
  • Become a Contributor
  • RSS 2.0 Feed
  • Atom 1.0 Feed
  • XML Sitemap

Dispatch

Briefings on CSPM playbooks, Azure hardening, and AI defense patterns.

© 2026 Dikshant Lather • All rights reserved.

Privacy Terms Cookies
ESC
Navigate ↑↓ • Select ↵
Dikshant Lather.