Detection Engineering Dispatch

Episode 39: Top 10 KQL Queries Every Detection Engineer Should Know


Listen Later

In this episode, Alex sits down with Sergio Albea, an accomplished Threat Hunter, Researcher, User Behavior Analyst, and Senior Cloud Security Engineer/Architect, to share a must-have resource for detection engineers: the Top 10 KQL Queries of 2024.

From detecting DLL hijacking and MFA fatigue to uncovering anonymous file access in OneDrive and SharePoint, we’ll walk through each query and the data feeds/sources required for detection and discuss their practical uses. Whether you’re new to KQL or an experienced user, these queries are designed to elevate your detection capabilities.

Join our live conversation bi-weekly on Thursdays! You only have to register once:
➡️ Register Here

Stay in the loop! Connect with us on social:

  • Website: https://www.anvilogic.com/
  • LinkedIn: https://www.linkedin.com/company/anvilogic 
  • YouTube: https://www.youtube.com/@Anvilogic 

About Detection Engineering Dispatch
Detection Engineering Dispatch is a live series featuring open discussions and live case studies with security operations teams at leading companies on what it takes to build a great detection engineering program. Join your peers to share knowledge, deep dive into technical best practices, and engage in discussions relevant to the detection engineering community.

About Detection Engineering Dispatch
Detection Engineering Dispatch is a live series featuring open discussions and live case studies with security operations teams at leading companies on what it takes to build a great detection engineering program. Join your peers to share knowledge, deep dive into technical best practices, and engage in discussions relevant to the detection engineering community.

...more
View all episodesView all episodes
Download on the App Store

Detection Engineering DispatchBy Anvilogic