Microsoft Security Operations AnalystMitigate threats using Microsoft SentinelHard

A security operations team is configuring Microsoft Sentinel to detect advanced persistent threats (APTs). They want to create a custom detection rule that correlates events from multiple data sources, specifically looking for a low-and-slow exfiltration attempt over several days. This requires analyzing large volumes of historical data and performing complex statistical analysis. Which type of analytics rule is best suited for this scenario?

  1. AFusion rule
  2. BScheduled query rule
  3. CNRT (Near Real-time) rule
  4. DMicrosoft incident creation rule
Show answer & explanation

Correct answer: B. Scheduled query rule

Scheduled query rules are ideal for scenarios requiring analysis over large volumes of historical data and complex statistical operations, as they allow for longer lookback periods and more intricate KQL queries, perfect for detecting 'low-and-slow' threats.

Why the other options are wrong

  • A. Fusion rules are built-in, AI-powered rules that automatically correlate alerts across multiple products, but don't offer the custom KQL flexibility for specific 'low-and-slow' scenarios described.
  • C. NRT rules are for rapid detection over short timeframes (e.g., 5 minutes), not for 'low-and-slow' threats over 'several days'.
  • D. Microsoft incident creation rules are for ingesting incidents from other Microsoft security products, not for custom correlation.

Microsoft Sentinel Scheduled Query Rules

Scheduled query rules in Microsoft Sentinel run custom Kusto Query Language (KQL) queries at defined intervals over specified historical data to detect threats and create incidents.

  • Highly customizable with KQL.
  • Supports long lookback periods (up to 14 days).
  • Ideal for complex correlation and statistical analysis.

Memory trick: Schedule Queries for Slow Threats

More Mitigate threats using Microsoft Sentinel questions