Dikshant Lather · Sep 25, 2026 Detecting DNS Tunneling and High-Volume Data Exfiltration with Sentinel KQL Uncover covert C2 communication channels and DNS data exfiltration using string length thresholds and subdomain entropy analysis in KQL. Network Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Hunting for Cobalt Strike and C2 Periodic Beaconing Using DeviceNetworkEvents Detect outbound Command and Control beaconing patterns with low interval variance using statistical time-delta functions in Defender XDR KQL. Network Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detect Password Spray Attacks in Microsoft Entra ID Using KQL Learn how to detect distributed password spray attacks targeting Microsoft Entra ID using advanced KQL queries, threshold aggregation, and IP failure rate analysis. Identity Security 2 min read 0 0
Dikshant Lather · Sep 25, 2026 Detecting Suspicious Base64 Encoded PowerShell Commands with Defender XDR KQL Halt fileless execution and command obfuscation by spotting encoded PowerShell flags (-enc, -encodedcommand) with Defender for Endpoint KQL queries. Endpoint Detection 2 min read 0 0