
0x673 - Teknik - Threat Hunting in KQL 101
Keywords
Summary
197 words
Critical Evaluation
Value of the Information & Strength of the Argument
The value of the information is high for practitioners, as it provides practical, real-world insights into threat hunting with KQL. The speaker’s experience in incident response lends credibility, and the examples (e.g., service account abuse, suspicious file locations) are concrete and actionable. The argumentation is solid, based on hands-on experience and a structured workshop design. However, it lacks formal evidence or references, and the discussion is somewhat conversational, which may reduce its rigor for academic purposes.
Scientific Rigor, Source Quality, Title Accuracy
The scientific rigor is moderate. The speaker is an expert, but the content is largely anecdotal and does not cite specific sources or studies. The description mentions the workshop and its components, but no external references are provided. The title accurately reflects the content, which is a technical discussion about threat hunting in KQL. The quality of sources is limited to the speaker’s experience and the workshop itself, which is not publicly accessible. No comments were provided for analysis.
170 words
Title / Content Match
The title accurately reflects the content, which is a technical discussion about threat hunting using KQL, as presented in a workshop.
Quality & Reliability
7/10
The speaker is a director at KPMG Canada with 12 years of experience in IT and 6 in cybersecurity, specializing in incident response and threat hunting. The content is based on practical experience and a real workshop, but it is largely anecdotal and lacks formal citations or peer-reviewed sources. The information is reliable for practical insights but not rigorously verified.
Key Moments
Markers derived by PSI from the transcript: the creator did not define chapters.
- Introduction of Yoan Schinck and his role at KPMG Canada.
- Overview of the threat hunting workshop at DEATHcon.
- Description of the lab infrastructure with two VMs and simulated attack.
- Explanation of the four categories covered in the workshop.
- Discussion on service account abuse and RDP connections.
- Insights on attackers placing files in less monitored directories.
- Use of 'distinct' function to reduce noise in hunting.
- Importance of human pattern recognition and environment knowledge.
- Accessibility of threat hunting for homelab setups.
- Observation that few organizations deploy Sysmon or collect Security Event Logs.
Cited Sources
- Living Off Trusted Sites — Mentioned as a source for external enrichment in network hunting.
Concurring Sources
- Microsoft Sentinel documentation — The video discusses threat hunting in Microsoft Sentinel, and this is the official documentation.
Contribution & Novelties
The video provides a practical, real-world perspective on threat hunting with KQL, based on the speaker’s experience in incident response. It offers concrete examples and techniques that are often not covered in theoretical tutorials. The workshop design, with a simulated attack and focus on Microsoft Defender telemetry, is a valuable hands-on approach for practitioners.
Pour aller plus loin :
- Kusto Query Language (KQL) documentation — Official documentation for KQL, essential for understanding the language.
- MITRE ATT&CK framework — A comprehensive framework for understanding attacker tactics and techniques, relevant to threat hunting.
- Sysmon documentation — Sysmon is a tool for logging system activity, often used in threat hunting; the video mentions its underutilization.
112 words
Radar Profile
The radar profile shows a balanced distribution across all dimensions, with slightly higher scores in information quantity and technical level, reflecting the practical and technical nature of the content. The lower score in reliability is due to the lack of formal citations and the anecdotal style.