← All work
Threat investigationThreat HuntingSecurity
Jojo's Hospital, KQL Threat Investigation
Documented Microsoft Sentinel investigation using KQL to correlate endpoint and user events, reconstruct attack timelines, and identify suspicious behaviour.
Threat investigationStart something like this
case study
Threat investigation/ the problem
Endpoint and identity telemetry only become useful when an analyst can join events, rebuild a timeline, and map findings to a known framework - not when logs stay siloed.
/ approach
The project demonstrates a Microsoft Sentinel investigation using KQL to correlate events and reconstruct attack timelines.
/ what we built
- Kusto Query Language investigations in Microsoft Sentinel
- Correlation of Microsoft Defender for Endpoint and user events
- Timeline reconstruction covering suspicious PowerShell, file downloads, and unauthorised user creation
- Analysis of phishing activity, privilege escalation indicators, and malicious network callbacks
- Findings and mitigation recommendations mapped toward MITRE ATT&CK
/ the outcome
A written threat-investigation case study showing how KQL joins, summarizations, and parses turn raw telemetry into an infection-chain narrative and actionable mitigations.
/ next case study
Network Security and Segmentation Lab
