Skip to content

Target Hunting Queries

Microsoft Sentinel's KQL (Kusto Query Language) enables defenders to craft precise, targeted queries that detect specific attack stages such as lateral movement or data exfiltration. By focusing on high-fidelity indicators and leveraging MITRE ATT&CK frameworks, hunters can reduce noise and prioritize critical threats. This section guides you through building structured, actionable queries for these scenarios.


Structuring Queries for Specific Attack Stages

Targeted queries should align with the MITRE ATT&CK framework to map tactics and techniques. For example, lateral movement often involves techniques like Remote Services or Pass the Hash, while data exfiltration may involve Data Transfer via DNS or Encrypted Communication.

Example 1: Detecting Lateral Movement via PSRemoting

// Identify suspicious PowerShell remoting commands
Process
| where Timestamp > ago(7d)
| where ProcessName == "powershell.exe"
| where CommandLine contains "Invoke-Command" 
| where CommandLine contains "PSRemoting"
| project Timestamp, Computer, ProcessName, CommandLine, User
Key logic:
- Filters for PowerShell processes (ProcessName == "powershell.exe").
- Looks for Invoke-Command with PSRemoting (common in lateral movement).
- Projects relevant fields for analysis.

Contextual refinement:
Add filters for unusual users or hosts:

| where User != "Administrator" and User != "ServiceAccount"

Example 2: Detecting Data Exfiltration via Large Outbound Traffic

// Identify large outbound network transfers
NetworkConnection
| where Timestamp > ago(24h)
| where Direction == "Outbound"
| where BytesTransferred > 10MB
| where RemoteIP != "192.168.0.0/16" and RemoteIP != "10.0.0.0/8"
| project Timestamp, SourceIP, DestinationIP, BytesTransferred, ProcessName
Key logic:
- Filters for outbound traffic (Direction == "Outbound").
- Detects transfers exceeding 10MB (adjust based on baseline).
- Excludes internal IPs to focus on external exfiltration.

Contextual refinement:
Check for encoded payloads or known malicious domains:

| where RemoteDomain contains "base64" or RemoteDomain contains "exfil-domain.com"


Best Practices for Targeted Query Development

  1. Define clear objectives: Start with a specific attack stage (e.g., "detect lateral movement using stolen credentials").
  2. Leverage MITRE ATT&CK: Map tactics (e.g., Lateral Movement) to techniques (e.g., Pass the Hash) for precise indicators.
  3. Combine multiple conditions: Use and, or, and not to narrow results. For example:
    where (ProcessName == "cmd.exe" and CommandLine contains "psexec") 
    and User != "Admin"
    
  4. Use temporal context: Filter by time ranges (ago(7d), last 24h) to focus on recent activity.
  5. Validate with context: Cross-check findings with logs (e.g., EventLog for credential reuse) or process trees.

Key takeaways

  • Targeted queries reduce noise by aligning with specific attack stages and MITRE ATT&CK techniques.
  • Use precise filters (e.g., CommandLine, BytesTransferred) to identify suspicious behavior.
  • Combine conditions and contextual refinements to prioritize high-fidelity alerts.
  • Regularly validate queries against your environment’s baseline to avoid false positives.
  • Automate with correlation rules or custom log analytics rules for continuous monitoring.