Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
DeviceFileEventsDeviceFileEvents
| where Timestamp > ago(1d)
| where ActionType in ("FileCopied","FileRenamed")
| summarize FilesTouched = count(), DistinctFolders = dcount(FolderPath) by DeviceName, InitiatingProcessAccountName, bin(Timestamp, 1h)
| where FilesTouched > 5000 and DistinctFolders > 20
Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.