Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test
ID: bf021494-0b22-5061-9d32-b1e60e5777b2
STIX ID: report--bf021494-0b22-5061-9d32-b1e60e5777b2
Feed Name: Detect FYI
Threat Score
This post evaluates how two LLMs (OpenAI ChatGPT and Anthropic Claude) and a human analyst produce KQL hunt queries to find PowerShell attempts to add Microsoft Defender exclusion paths, demonstrating working and broken queries, path-normalization techniques, prevalence calculations, and practical comments on detection trade-offs and improvements.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
