My KQL functions cover Entra sign-in context, VPN address attribution and Defender account actions. The accompanying runbooks explain investigation of NTLM/Kerberos brute force, Pass-the-Ticket, unwanted software, reconnaissance and Sysmon health. I also contributed investigation standards covering evidence, root cause, impact and response.
Viewed
UK Water Utility
Make recurring investigation questions reusable
Extend Defender Live Response with PowerShell and KQL
Return to the full story ←