Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst needs to create a custom detection rule in Microsoft Defender XDR to identify attempts to disable security services on endpoints. The rule should specifically look for processes attempting to stop or modify Windows Defender services. Which Kusto Query Language (KQL) operator is most effective for searching for specific strings within a column, such as 'WinDefend' or 'MsMpEng' in process command lines, while allowing for case-insensitive matching and partial string matches?

  1. A== (equality)
  2. Bcontains
  3. Cstartswith
  4. Dhas
Show answer & explanation

Correct answer: B. contains

The 'contains' operator in KQL performs a case-insensitive search for a specified substring within a column. This is ideal for finding partial matches like 'WinDefend' or 'MsMpEng' within a longer command line string, fulfilling the requirement for partial and case-insensitive matching.

Why the other options are wrong

  • A. The '==' operator requires an exact, case-sensitive match, which is not suitable for partial or case-insensitive searches.
  • C. The 'startswith' operator only matches if the string begins with the specified value, which is too restrictive for finding substrings.
  • D. The 'has' operator performs a case-insensitive search for a whole term, but it is optimized for indexed terms and might not catch partial strings effectively compared to 'contains' for general string matching.

KQL 'contains' operator

A Kusto Query Language operator used to search for a specified substring within a column value, performing a case-insensitive match.

  • Case-insensitive by default.
  • Useful for partial string matching.
  • Can be less performant than 'has' for large datasets if exact term matching is possible.

Memory trick: Contains checks if the string has a bit of what you're looking for, anywhere.

More Mitigate threats using Microsoft Defender XDR questions