Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
DeviceNetworkEventsDeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName has_any ("responder.py","responder.exe","inveigh.exe") or ProcessCommandLine has_any ("Responder.py","Invoke-Inveigh")
| project Timestamp, DeviceName, ProcessCommandLine, AccountName
Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.