topic
KQL
3 posts tagged “KQL”.
Detection-as-Code for Microsoft Sentinel and Defender XDR: A Technical Deep Dive
Microsoft's July 2026 Preview lets you manage Defender XDR custom detections as code — through the Microsoft Security Bicep extension, Microsoft.Security/detectionRules, and Sentinel Repositories. A technical walkthrough from KQL research to a deployable Bicep detection, validation, match-volume tuning, and CI/CD deployment.
What your DCR transform actually does to untrusted data (and why it matters now)
A CCF-authoring deep-dive: ingestion-time transform design quietly decides what your detections — and now your AI readers — actually see. What a transform really does to attacker-controlled text, the restricted-KQL gotchas that bite, and a non-destructive trust-tagging pattern you can adopt today.
Campaign-Centric Hunting with Microsoft Defender XDR and Microsoft Sentinel
Moving from a single suspicious email to full campaign impact — using Defender for Office 365 Campaign Views and the CampaignInfo table with EmailEvents, UrlClickEvents, and post-delivery data to see who was targeted, who clicked, and what to prioritize.