BEFORE THE CUSTOMER SESSION
Give the activity a clear purpose.
Agree on the customer question and the expected outcome. Prepare synthetic data, confirm the test environment, and name the evidence you will capture. Finish with a short discussion of what the result means for the customer’s next decision.
Confirm the data source
Use a test endpoint with Defender for Endpoint telemetry available in Defender XDR advanced hunting. Confirm your account can read DeviceProcessEvents. Table availability depends on deployed services and access.
Choose a bounded hypothesis
Example: “Which PowerShell processes ran on this lab device in the last 24 hours?” This is an inventory question to establish context; it is not a verdict that PowerShell activity is malicious.
Run the query below
Replace LAB-PC with the device name as it appears in your data. Keep the time window narrow, then run the query in advanced hunting. An empty result can mean no matching activity, a device-name mismatch, missing telemetry, or insufficient access.
Read the process context
Compare timestamps, command lines, users, and parent processes with activity expected on the lab device. Investigate an unusual entry before calling it suspicious; administrative scripts and normal automation can explain many results.
Build a repeatable note
Preserve the query text, UTC time window, device, relevant rows, and your interpretation. Record the next source of evidence needed to resolve uncertainty.
Close the loop
If you decide a pattern merits detection, evaluate it against a broader representative baseline and document likely false positives. Keep containment and response changes separate from this read-only hunt.
Read-only KQL · replace LAB-PC
DeviceProcessEvents
| where Timestamp > ago(24h)
| where DeviceName =~ "LAB-PC"
| where FileName in~ ("powershell.exe", "pwsh.exe")
| project Timestamp, DeviceName, AccountName, FileName,
ProcessCommandLine, InitiatingProcessFileName,
InitiatingProcessCommandLine
| order by Timestamp descTHE CUSTOMER TAKEAWAY
Make the outcome easy to explain.
Close the workshop with a short record of the customer question, test scope, expected behavior, observed behavior, evidence, and next steps. Connect the finding to a control the customer can evaluate.