Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRHard

A Microsoft 365 administrator is configuring custom detection rules in Microsoft Defender XDR using advanced hunting. The security team wants to be alerted whenever a specific PowerShell script, known to be used by a persistent threat actor, is executed on any endpoint in the organization. The script uses a unique command-line argument that can be identified. Which Kusto Query Language (KQL) operator should the administrator use to search for this specific command-line argument within the `CommandLine` field of `DeviceProcessEvents` table, ensuring case-insensitive matching?

  1. A`contains`
  2. B`matches regex`
  3. C`in`
  4. D`has`
Show answer & explanation

Correct answer: D. `has`

The `has` operator in KQL is optimized for searching for whole terms within string fields, providing better performance than `contains` for large datasets and is case-insensitive by default. It's ideal for identifying specific command-line arguments.

Why the other options are wrong

  • A. `contains` performs a substring search and is case-insensitive, but `has` is generally more performant for whole-word or term searches, especially in indexed columns.
  • B. `matches regex` allows for complex pattern matching, but for a simple specific string, it's overkill and less performant than `has`.
  • C. `in` is used to check if a value exists within a list of values, not for searching for a substring or term within a single string field.

KQL String Operators

Kusto Query Language (KQL) provides various operators for string manipulation and searching, including `contains`, `has`, and `matches regex`, each suited for different search criteria and performance considerations.

  • `has` is for case-insensitive whole-term search, optimized for performance.
  • `contains` is for case-insensitive substring search.
  • `matches regex` for complex pattern matching.
  • Choosing the right operator impacts query performance.

Memory trick: Searching text needs to be exact, partial, or pattern-based, and performance matters.

More Implement and manage Microsoft Defender XDR questions