Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
DeviceProcessEventsDeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName in~ ("mailpv.exe","iepv.exe","dialupass.exe","netpass.exe","rpv.exe")
| project Timestamp, DeviceName, FileName, ProcessCommandLine, AccountName
| union (
DeviceProcessEvents
| where Timestamp > ago(1d)
| where ProcessCommandLine has_any ("Brute Ratel","badger","bruteratel")
)
Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.