Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelMedium
A security analyst needs to perform a proactive threat hunt in Microsoft Sentinel to identify any instances of a specific, recently disclosed malware sample's hash across all ingested logs. The analyst wants to quickly search all relevant tables for this hash without knowing the exact table names where it might appear. Which Kusto Query Language (KQL) capability should the analyst use?
- AExecuting a 'search *' query.
- BRunning a 'find' operator with the 'in' keyword.
- CUsing a 'union' operator across all known tables.
- DCreating a custom function to iterate through tables.
Show answer & explanationAnswer & explanation
Correct answer: A. Executing a 'search *' query.
The 'search *' operator in KQL is designed for broad, open-ended searches across all tables in the current scope (e.g., the Log Analytics workspace). It's highly effective for hunting when the exact source table of a specific indicator of compromise (like a malware hash) is unknown.
Why the other options are wrong
- B. The 'find' operator is used for finding rows that match a predicate across multiple tables. While similar to 'search *', 'search *' is often more intuitive for a simple, broad string search.
- C. Using 'union' across all known tables would be cumbersome and inefficient, requiring the analyst to explicitly list every potential table.
- D. Creating a custom function to iterate through tables is overly complex and unnecessary for this common hunting scenario, as 'search *' provides this functionality natively.
KQL 'search *' operator
The 'search *' operator in KQL performs a full-text search across all tables and columns within the current scope (e.g., a Log Analytics workspace) for a specified term or pattern.
- Useful for broad, exploratory searches.
- Can be slower than targeted queries.
- Ideal for threat hunting when data source is unknown.
Memory trick: Search Star: Seek Everywhere, See Everything!