Weekly KQL. Copy-paste hunting queries. Analytics you can ship.
A new KQL detection from the DevSecOpsDad lab, every week.
One deep-dive KQL query per week for Microsoft Sentinel and Defender XDR — the logic behind it, what it catches, tuning notes, and how to adapt it for your environment.
-
-
KQL Detection of the Week: The Query That Wrote Itself Eight Times
Detecting SharePoint RCE When the Brief Wrote the Same Query All Week, the Correlation Has No Anchor, and the Best Detection in the Stack Is a Baseline
By DevSecOpsDad -
KQL Detection of the Week: Sins of the Grandfather
Detecting npm Lifecycle Worms When the Payload Is Two Generations Down and the C2 Is a Public Blockchain
By DevSecOpsDad -
KQL Detection of the Week: A Heap of Trouble
Detecting Spring Boot Heapdump Theft When the Exfiltration Is a GET Request
By DevSecOpsDad -
KQL Detection of the Week: A Meeting in 2050
Detecting Project CAV3RN's Outlook Calendar C2 and DNS AAAA Recovery Channel
By DevSecOpsDadThere is a meeting on your calendar for 13 May 2050. Nobody will ever attend it. Nobody has ever scrolled there — a quarter-century out, in a fixed one-hour window between 22:00 and 23:00 UTC, parked in the most-synced, least-read database in... [Read More] -
KQL Detection of the Week: The Dog That Didn't Bark
Detections built around the thing that should have happened and didn't
By DevSecOpsDadThis week’s six briefs produced 29 KQL candidates (the Friday automation decided to take a personal day) across continued Flowise CSV-agent exploitation, a GigaWiper destructor, HTML phishing from first-time external senders, live internet scanning for exposed MCP servers and AI assistant credentials,... [Read More] -
KQL Detection of the Week: Nice Costume, Wrong Address
Watching a disguise, then checking the one fact the disguise can't fake
By DevSecOpsDadThis week’s seven briefs produced 27 KQL candidates across a Vidar-plus-XMRig malvertising wave hiding behind a forged code-signing certificate and a 491 MB null-byte suit, device-code phishing that sails straight past URL filters, an SMB session quietly upgraded into Meterpreter, a Peyara Remote... [Read More] -
KQL Detection of the Week: The Login Was Never the Point
Watching the moment an attacker gets handed a key, and catching that key being used from places a key should never turn up
By DevSecOpsDadThis week’s seven briefs produced 29 KQL candidates across ToddyCat’s Umbrij OAuth tooling raiding Google Workspace, a trojanized-ScreenConnect campaign dropping AsyncRAT, Armored Likho’s BusySnake Python stealer arriving on AI-generated phishing loaders, a photo-themed ZIP delivering a Node.js implant into hospitality, a malicious... [Read More] -
KQL Detection of the Week: A Name Is a Claim, Not a Fact
Three detections that refused to trust a process name, a storage-bucket name, or a route's protection promise at face value
By DevSecOpsDadThis week’s six briefs produced 30 KQL candidates across an NTLM-relay-to-Shadow-Credentials privilege chain, the WhatsApp VBScript RMM dropper, an npm postinstall implant, SharkLoader staging Cobalt Strike under the StrikeShark campaign, StealC and Amadey infostealers raiding browser credential stores, a photo-themed ZIP delivering... [Read More] -
KQL Detection of the Week: The Attack That Stayed Under the Threshold
An attacker who read the detection rules over your shoulder and built the whole attack to live one inch underneath them
By DevSecOpsDadThis week’s five briefs produced 20 KQL candidates across an Oracle PeopleSoft zero-day (CVE-2026-35273), evil MSI loaders, the VHDX-to-Remcos delivery chain, Dropping Elephant’s Fondue.exe side-loading, a Tor-speaking crypto clipper, the Mastra npm supply-chain compromise, an AI-agent RCE, and a pile of SSH... [Read More] -
KQL Detection of the Week: Detecting Cloud Logging Suppression (T1562.008)
Catching the attacker who turns off the cameras before the exploitation even starts
By DevSecOpsDadEvery day our Detection Engineering Brief turns fresh threat intel into deployable detection content — KQL for Microsoft Sentinel and Defender XDR, ATT&CK mappings, triage runbooks, and deployment-readiness calls. This week’s five briefs produced 21 KQL candidates across Apache ActiveMQ and Gogs... [Read More] -
KQL Detection of the Week: Argamal Beaconing
Counting the rhythm in a low-and-slow C2 beacon, and fixing a leftanti join that silently suppressed a VPN auth-bypass alert
By DevSecOpsDadEvery day our Detection Engineering Brief turns fresh threat intel into deployable detection content — KQL for Microsoft Sentinel and Defender XDR, ATT&CK mappings, triage runbooks, and deployment-readiness calls. This week’s five briefs produced 23 KQL candidates across npm supply-chain attacks, NetSupport... [Read More]