Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks
DeviceProcessEventsDeviceProcessEvents
| where FileName in~ ("vssadmin.exe","wbadmin.exe","bcdedit.exe","wmic.exe")
| where ProcessCommandLine has_any ("delete shadows","delete catalog","recoveryenabled no","shadowcopy delete","resize shadowstorage")
| project Timestamp, DeviceName, AccountName, ProcessCommandLine
Hunting queries are starting points for threat hunting & detection engineering — validate table/column names against your own workspace schema and tune thresholds before turning any of these into a production alert rule.