0x673 - Teknik - Threat Hunting in KQL 101

0x673 - Teknik - Threat Hunting in KQL 101

🎙 PolySécure Podcast 👥 540 📅 December 3, 2025 ⏱ 25 min 👁 25 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

KQLThreat HuntingMicrosoft SentinelDefender for EndpointSysmon

Summary

In this podcast episode, Yoan Schinck, a director in KPMG Canada’s cyber response practice, discusses his workshop on threat hunting using Kusto Query Language (KQL) in Microsoft Sentinel. He explains the setup of the workshop, which involved two virtual machines (Windows client and server) with simulated attacks from initial access to data exfiltration. The telemetry from Microsoft Defender for Endpoint, along with Windows Event Logs and Sysmon, was sent to Sentinel. The workshop covered four categories: initial access vectors, Windows services, scheduled tasks, and network hunting with external source enrichment (Living Off Trusted Sites). Schinck shares real-world insights, such as attackers abusing service accounts for RDP connections and placing malicious files in less monitored directories like ProgramData or Users Public. He emphasizes the importance of using the ‘distinct’ function to reduce noise and relying on human pattern recognition. He also notes that while Microsoft stack is popular in Quebec, few organizations deploy Sysmon or collect Security Event Logs, despite their value. The workshop is accessible for homelab setups, requiring only two VMs, a Windows Event Collector, and Sentinel. Schinck concludes that once threat hunting concepts are mastered, they apply to any product, with only the syntax differing.

197 words

Critical Evaluation

Value of the Information & Strength of the Argument

The value of the information is high for practitioners, as it provides practical, real-world insights into threat hunting with KQL. The speaker’s experience in incident response lends credibility, and the examples (e.g., service account abuse, suspicious file locations) are concrete and actionable. The argumentation is solid, based on hands-on experience and a structured workshop design. However, it lacks formal evidence or references, and the discussion is somewhat conversational, which may reduce its rigor for academic purposes.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The speaker is an expert, but the content is largely anecdotal and does not cite specific sources or studies. The description mentions the workshop and its components, but no external references are provided. The title accurately reflects the content, which is a technical discussion about threat hunting in KQL. The quality of sources is limited to the speaker’s experience and the workshop itself, which is not publicly accessible. No comments were provided for analysis.

170 words

Title / Content Match

The title accurately reflects the content, which is a technical discussion about threat hunting using KQL, as presented in a workshop.

Quality & Reliability

7/10

The speaker is a director at KPMG Canada with 12 years of experience in IT and 6 in cybersecurity, specializing in incident response and threat hunting. The content is based on practical experience and a real workshop, but it is largely anecdotal and lacks formal citations or peer-reviewed sources. The information is reliable for practical insights but not rigorously verified.

Key Moments

Cited Sources

Concurring Sources

Contribution & Novelties

The video provides a practical, real-world perspective on threat hunting with KQL, based on the speaker’s experience in incident response. It offers concrete examples and techniques that are often not covered in theoretical tutorials. The workshop design, with a simulated attack and focus on Microsoft Defender telemetry, is a valuable hands-on approach for practitioners.

Pour aller plus loin :

112 words

Radar Profile

The radar profile shows a balanced distribution across all dimensions, with slightly higher scores in information quantity and technical level, reflecting the practical and technical nature of the content. The lower score in reliability is due to the lack of formal citations and the anecdotal style.

Reliability 6/10