Hands-On LabAdvanced

Hunt for Living-off-the-Land Attacks with KQL in Microsoft Sentinel

Write KQL hunting queries in Microsoft Sentinel to detect living-off-the-land attacks including encoded PowerShell and suspicious WMI activity.

90 minEstimated time
5Guided steps
AutoVerification
IsolatedSandbox
Hunt for Living-off-the-Land Attacks with KQL in Microsoft Sentinel

Lab overview

Living-off-the-land attacks use legitimate system tools - PowerShell, WMI, certutil, and other built-in Windows utilities - that exist in every enterprise environment. Because these tools are trusted and expected by endpoint detection systems, attackers leverage them to blend malicious activity into normal operations, evading signature-based defenses entirely. Proactive threat hunting with Kusto Query Language (KQL) in Microsoft Sentinel is essential to surface these behavioral anomalies before they escalate into full-scale breaches.

In this lab, you will work with a pre-seeded Microsoft Sentinel workspace containing 30 days of simulated activity with hidden living-off-the-land indicators. You will write KQL queries to detect base64-encoded PowerShell command execution, hunt for suspicious WMI process creation using parent-child chain analysis, build time-series anomaly detection queries, create hunting bookmarks to preserve evidence, and promote validated findings to scheduled analytics rules.

Objectives

Upon completion of this advanced level lab, you will be able to:

  • Write KQL queries to detect base64-encoded PowerShell command execution
  • Hunt for suspicious WMI process creation using parent-child chain analysis
  • Build time-series queries using make-series and series_decompose_anomalies
  • Create hunting bookmarks to document and preserve evidence
  • Promote a validated hunting query to a scheduled analytics rule

Who is this lab for?

This lab is designed for security analysts and SOC engineers preparing for the SC-200 certification or building proactive threat hunting skills. Familiarity with KQL fundamentals and Microsoft Sentinel navigation is recommended.

Verified against your live environment

An automated validation engine inspects your actual resources and configurations as you work. Completion means the task was performed, not multiple choice, real-world proficiency.

[CHECK] validation_activelive
Inspecting deployed resources...
Verifying configuration state...
✓ Step requirements satisfied

More labs like this

Related reading

PremiumIncluded in Premium
Duration
90 min
Steps
5

Environment

Live Cloud Environment

Every lab includes

  • Real environment, pre-credentialed
  • Automated checks on every step
  • Isolated sandbox, auto cleanup
  • AI-recommended next steps

Lab curriculum

  1. 01

    Logging into Azure Account using Azure Portal

  2. 02

    Detect Encoded PowerShell Execution with KQL

    1 automated check

  3. 03

    Hunt for Suspicious WMI Process Creation Patterns

    1 automated check

  4. 04

    Build Time-Series Anomaly Detection Queries

    1 automated check

  5. 05

    Create Hunting Bookmarks and Promote to Analytics Rules

    1 automated check

Skills validated

Privileged Identity Management

Not the lab you were looking for?

Browse 200+ hands-on labs across AWS, Azure, Kubernetes, Docker, and cloud security.

Explore the catalog