Lessons learned from threat investigation
Based on understanding acquired through years of experiences, failure, and learning from mistakes in this domain, here are some lessons learned that can be applied to write better queries for threat hunting:
- Start early: Do not wait for a security incident to start using the query explorer and KQL. Proactive threat hunting is more effective when you are familiar with the tools and techniques beforehand.
- Regular updates: Cloud environments change frequently due to new deployments and updates. Ensure that your queries and threat-hunting practices evolve to accommodate these changes.
- Context matters: While KQL is a powerful tool, it is essential to consider the context of your cloud environment. Anomalies that might be benign in one context could be significant threats in another. Understanding your specific use case is crucial.
- Data retention policies: Be aware of data retention policies in your cloud environment. Querying...