Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
DeviceProcessEventsDeviceProcessEvents
| where Timestamp > ago(1d)
| where FileName has_any ("screenconnect.clientservice.exe","aterasagent.exe","ateraagent.exe","n-central.exe","splashtop.exe","tightvnc.exe","anydesk.exe")
| where DeviceName has_any ("srv","dc","sql","fs") // adjust to your server naming convention
| project Timestamp, DeviceName, FileName, ProcessCommandLine, InitiatingProcessFileName, AccountName
Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.