Dikshant Lather · Sep 25, 2026 Uncovering Local Windows Account Creation via Command Line with KQL Spot unauthorized backdoor user accounts created on endpoints via net.exe, net1.exe, and PowerShell local user management cmdlets. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Persistence via Windows Scheduled Task Creation Using KQL Hunt for adversary persistence via unauthorized Windows Scheduled Tasks by parsing Security Event ID 4698 and DeviceProcessEvents in KQL. Threat Hunting 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Hunting for Kerberoasting Attacks via Kerberos Service Ticket Requests (Event ID 4769) Uncover Kerberoasting attacks targeting Active Directory Service Principal Names (SPNs) using KQL anomaly detection on Windows Security Event ID 4769. Active Directory Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Uncovering Malicious Windows Service Installation via Event ID 7045 and Defender KQL Catch lateral movement and persistence tools (PsExec, Cobalt Strike PsExec service) by monitoring new Windows Service installations with KQL. Threat Hunting 2 min read 0 0