Hunt for Living-off-the-Land Attacks with KQL in Microsoft Sentinel
Write KQL hunting queries in Microsoft Sentinel to detect living-off-the-land attacks including encoded PowerShell and suspicious WMI activity.

Lab overview
Living-off-the-land attacks use legitimate system tools - PowerShell, WMI, certutil, and other built-in Windows utilities - that exist in every enterprise environment. Because these tools are trusted and expected by endpoint detection systems, attackers leverage them to blend malicious activity into normal operations, evading signature-based defenses entirely. Proactive threat hunting with Kusto Query Language (KQL) in Microsoft Sentinel is essential to surface these behavioral anomalies before they escalate into full-scale breaches.
In this lab, you will work with a pre-seeded Microsoft Sentinel workspace containing 30 days of simulated activity with hidden living-off-the-land indicators. You will write KQL queries to detect base64-encoded PowerShell command execution, hunt for suspicious WMI process creation using parent-child chain analysis, build time-series anomaly detection queries, create hunting bookmarks to preserve evidence, and promote validated findings to scheduled analytics rules.
Objectives
Upon completion of this advanced level lab, you will be able to:
- Write KQL queries to detect base64-encoded PowerShell command execution
- Hunt for suspicious WMI process creation using parent-child chain analysis
- Build time-series queries using make-series and series_decompose_anomalies
- Create hunting bookmarks to document and preserve evidence
- Promote a validated hunting query to a scheduled analytics rule
Who is this lab for?
This lab is designed for security analysts and SOC engineers preparing for the SC-200 certification or building proactive threat hunting skills. Familiarity with KQL fundamentals and Microsoft Sentinel navigation is recommended.
Verified against your live environment
An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.
More labs like this
Hunt Threats with KQL and Promote a Hunt to a Detection Rule in Microsoft Sentinel
Run KQL hunting queries against seeded telemetry, save a hunt and bookmark, work the MITRE view, then promote a hunt to a scheduled rule.
Detect Multi-Stage Attacks with Microsoft Sentinel Fusion Rules
Configure Fusion source signals, create entity-mapped analytics rules, and trace multi-stage attack chains using the investigation graph in Microsoft Sentinel.
Deploying Your First Microsoft Sentinel Workspace on Azure
Learn to set up Microsoft Sentinel workspace, connect it to a Log Analytics workspace, and prepare for advanced security monitoring and threat detection.
Related reading
Environment
Every lab includes
- Real environment, pre-credentialed
- Automated checks on every step
- Isolated sandbox, auto cleanup
- AI-recommended next steps
Lab curriculum
- 01
Logging into Azure Account using Azure Portal
- 02
Detect Encoded PowerShell Execution with KQL
1 automated check
- 03
Hunt for Suspicious WMI Process Creation Patterns
1 automated check
- 04
Build Time-Series Anomaly Detection Queries
1 automated check
- 05
Create Hunting Bookmarks and Promote to Analytics Rules
1 automated check
Skills validated
Not the lab you were looking for?
Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.