KQL Kraken Hunt
Tools/Skills: KQL, Incident Investigation, Log Analysis, Decoding Base64-Encoded Powershell Commands
SYNOPSIS
SOLUTION & PROCESS
ONBOARDING
CASE 1
QUERIES
RESULT
CASE 2
QUERIES:
RESULT:
CASE 3
QUERY 1 (time):
RESULT 1 (time):
QUERY 2 (downloaded file):
RESULT 2 (downloaded file):
CASE 4
Endpoint IP Address from a created Remote Tunnel
QUERY
RESULT:
Time & Hostname
QUERY:
RESULT 1 (TIME when attacker enumerated network shares):
RESULT 2 (Hostname of lateral movement)
CASE 5
QUERY
RESULT
FURTHER STEPS
CASE 6
QUERY
RESULT
Example Prompts:
Last updated