Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst needs to create a custom detection rule in Microsoft Defender XDR to identify instances where a specific, highly sensitive executable (named 'SecretProject.exe') is launched from a non-standard directory on any endpoint. The rule should trigger an alert whenever this executable is run from any location other than 'C:\Program Files\SecretProject\' or 'C:\Program Files (x86)\SecretProject\'. Which KQL table and operator combination should the analyst primarily use for this Advanced Hunting query?

  1. ADeviceProcessEvents | where FileName == 'SecretProject.exe' and FolderPath !in ('C:\Program Files\SecretProject\', 'C:\Program Files (x86)\SecretProject\')
  2. BDeviceRegistryEvents | where RegistryKey contains 'SecretProject.exe' and RegistryValueData !in ('C:\Program Files\SecretProject\', 'C:\Program Files (x86)\SecretProject\')
  3. CDeviceFileEvents | where FileName == 'SecretProject.exe' and FolderPath !in ('C:\Program Files\SecretProject\', 'C:\Program Files (x86)\SecretProject\')
  4. DDeviceProcessEvents | where FileName == 'SecretProject.exe' and InitiatingProcessFolderPath !in ('C:\Program Files\SecretProject\', 'C:\Program Files (x86)\SecretProject\')
Show answer & explanation

Correct answer: A. DeviceProcessEvents | where FileName == 'SecretProject.exe' and FolderPath !in ('C:\Program Files\SecretProject\', 'C:\Program Files (x86)\SecretProject\')

The 'DeviceProcessEvents' table records process creation and execution, which is necessary to detect when an executable is launched. The 'FileName' column identifies the executable, and 'FolderPath' represents the directory from which it was run. Using the '!in' operator correctly excludes the allowed paths, identifying executions from non-standard directories.

Why the other options are wrong

  • B. DeviceRegistryEvents tracks registry changes, which is not directly related to executable launch paths.
  • C. DeviceFileEvents tracks file creation, modification, and deletion, not process execution.
  • D. InitiatingProcessFolderPath refers to the parent process, not the path of the 'SecretProject.exe' itself.

KQL: DeviceProcessEvents & FolderPath

The 'DeviceProcessEvents' table in Advanced Hunting captures process execution data, and the 'FolderPath' column within it specifies the directory from which the process was launched. Used with `!in` to exclude known good paths.

  • Records process creation and termination.
  • FolderPath identifies the execution directory.
  • Crucial for detecting anomalous program launches.

Memory trick: To track an 'exe' running, you need 'ProcessEvents' and its 'FolderPath' to see where it came from.

More Mitigate threats using Microsoft Defender XDR questions