A security operations center (SOC) needs to create a custom detection rule in Microsoft Defender XDR to identify a specific type of malicious PowerShell script. This script is known to contain a unique, non-standard string ('MaliciousPayloadIdentifier') that is not present in legitimate scripts. The rule should trigger an alert whenever a PowerShell process containing this string in its command line is executed on any endpoint. Which KQL operator is best suited for efficiently searching for this specific substring within the 'CommandLine' column of the 'DeviceProcessEvents' table?
- Acontains
- Bmatches regex
- Chas_any
- D==
Show answer & explanationAnswer & explanation
Correct answer: A. contains
The 'contains' operator in KQL is specifically designed for case-insensitive substring searching within text fields. Since the goal is to find a 'unique, non-standard string' ('MaliciousPayloadIdentifier') within the 'CommandLine' of a PowerShell process, 'contains' is the most efficient and appropriate operator. While 'matches regex' could work, 'contains' is simpler and more performant for a direct substring match.
Why the other options are wrong
- B. 'matches regex' is overkill and less performant for a simple fixed substring search, though it would technically work.
- C. 'has_any' checks if a column contains *any* of the specified values in a list, not a single substring within a larger string.
- D. '==' performs an exact match, which would fail if other arguments are present in the command line.
KQL 'contains' Operator
The KQL `contains` operator is used in Advanced Hunting queries to perform a case-insensitive substring search within a string column, efficiently finding a specific text pattern within a larger text value.
- Performs case-insensitive substring search.
- Efficient for finding text within logs.
- Useful for command lines, file paths, and other text fields.
Memory trick: To find a 'needle in a haystack' (substring in command line), 'contains' is your best magnet.