Home›Detection Engineering›Advanced hunting (KQL)
Section
Advanced hunting (KQL)
Investigation and detection queries in Defender / Sentinel KQL.
What the logs won't tell you: reading activity telemetry without over-reading it
Pulling someone's M365 activity to see whether they were “really working” — a tiered mental model (human work vs. auth moments vs. machine noise), the KQL pack across sign-ins, endpoint and mail, and the limitations that belong in every report.
Read →Linkable Token Identifiers: following an attacker across every M365 service
Session ID and Unique Token Identifier stitch scattered audit logs into one thread — track suspicious sign-ins, trace token misuse, enumerate sessions, and correlate activity across Exchange, SharePoint, Teams and Graph, plus hunting queries and an auto-revoke playbook.
Read →Investigating a phishing report with KQL, end to end
The complete Defender Advanced Hunting playbook — 14 queries across every email, identity, endpoint and cloud table, correlated into one timeline, plus a fill-in IR report template.
Read →