Hunting queries need more than the basics. This lesson covers the Kusto Query Language (KQL) operators that make searches fast, reusable and able to combine data from several tables. String matching comes first. has looks for a whole term using the index that Kusto builds from words in text, so it is fast. contains looks for any substring and has to scan the text, so it is slower. ProcessCommandLine has "mimikatz" matches the word mimikatz; contains "katz" would match inside a longer word. Both are case-insensitive; has_cs and contains_cs are the case-sensitive forms. Use has whenever you are searching for a complete term, and startswith or endswith when position matters. For lists, in checks exact equality against a set of values, for example FileName in ("psexec.exe", "wmic.exe"), and in~ does so case-insensitively. has_any checks whether a text column contains any of a list of terms, which suits command lines. let statements name a value, list or even a whole query so you can reuse it. A dynamic list looks like let SuspiciousTools = dynamic(["procdump", "rclone"]); and is then used in where ProcessCommandLine has_any (SuspiciousTools). Let statements end with a semicolon and make queries easier to read and maintain.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.