_ _ _
| | | | (_)
| | ___ _ ___| |_ ___ _ __ ___ _ __ ___ _ ___ ___ _ __
| |/ / | | / __| __/ _ \| '_ \ / _ \| '_ ` _ \| |/ __/ _ \| '_ \
| <| |_| \__ \ || (_) | | | | (_) | | | | | | | (_| (_) | | | |
|_|\_\\__,_|___/\__\___/|_| |_|\___/|_| |_| |_|_|\___\___/|_| |_|
A grimoire of KQL for cloud detection and response: documented detection, hunting, and posture queries for AWS and Azure control-plane logs, with matching Microsoft Sentinel analytic rules.
Most KQL content out there targets the endpoint. The Kustonomicon focuses on the cloud service provider control plane — CloudTrail, Azure Activity, Entra ID, and Azure diagnostics — where detections pair naturally with posture: many entries combine a detection query (catch the event) with an Azure Resource Graph query (find the exposure before the event).
Every query follows a single documented template with machine-readable frontmatter: platform, service, type (detection / hunt / posture), severity, tables, and MITRE ATT&CK mappings. CI validates all of it.
queries/ documented KQL queries — see the index below
aws/ CloudTrail-based detections, organized by service
azure/ Azure control plane, Entra ID, Key Vault, storage, …
endpoint/ a few Microsoft Defender endpoint extras
detections/ Microsoft Sentinel analytic rules (YAML), mirroring queries/
learn/ notes on the KQL patterns these detections use (WIP)
docs/ the query template and conventions
scripts/ validation, index generation, YAML → ARM conversion
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Activity from New IP Not Seen in 90 Days | hunt | medium | T1078.004 |
| Activity from New User Agent Not Seen in 90 Days | hunt | medium | T1078.004 |
| Aviatrix Controller RCE CVE-2024-50603 | hunt | high | T1190 |
| CloudTrail Logging Stopped | detection | high | T1562.008 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| EC2 Instance Exported to S3 | detection | high | T1537 |
| Unsanctioned EC2 Type Created | detection | low | T1496 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Access Key Created | hunt | low | T1098, T1098.001 |
| Access Key Created and Deleted in Short Period of Time | hunt | medium | T1098, T1098.001, T1550 |
| Access Key Deleted | hunt | low | T1098, T1531 |
| Actions from Federated User | hunt | medium | T1078, T1078.004, T1550 |
| Assume Role from Untrusted Account ID | detection | high | T1078, T1078.004, T1199 |
| Console Login Without MFA | detection | medium | T1078, T1078.004 |
| Failed Login from Root | detection | medium | T1078, T1078.004, T1110 |
| Federated User Created | detection | medium | T1078, T1078.004, T1550 |
| GetCallerIdentity from AWS CLI | hunt | low | T1033, T1552 |
| Large Volume of Access Keys Created in Short Time | hunt | medium | T1098, T1098.001 |
| Multiple Failed Logins from Single Source IP | detection | medium | T1110, T1110.003 |
| New Access Key Created for Root | detection | high | T1098, T1098.001 |
| Successful Login After Multiple Failed Logins | detection | high | T1110, T1078, T1078.004 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| RDS Snapshot Exported to S3 | detection | medium | T1537 |
| RDS Snapshot Taken | hunt | low | T1578.001 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Block Public Access Disabled | detection | high | T1562.007 |
| Bucket Deleted | detection | medium | T1485 |
| Objects Deleted | hunt | low | T1485 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Large Number of Secrets Accessed in Short Time | detection | high | T1555.006 |
| Large Number of Secrets Deleted in Short Time | detection | high | T1485 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| SSM Document Configured as Public | detection | high | T1078.004 |
| SSM Document Executed | hunt | informational | T1651 |
| SSM Document Executed Not Seen in Last 90 Days | hunt | medium | T1651 |
| SSM Document Executed on Multiple Instances | hunt | medium | T1651 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Dangerous Ingress Rule | detection | high | T1562.007 |
| IOC Security Group Created | detection | high | T1562.007 |
| Security Group Deleted | hunt | low | T1562.007 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Disk Export SAS URL Generated | detection | high | T1530 |
| Multiple VMs Deleted in Short Time | detection | high | T1578.003, T1485 |
| Run Command Started | detection | medium | T1651 |
| VMAccess Extension Executed | detection | high | T1651, T1098 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Access Configuration Modified | detection | medium | T1555.006, T1556 |
| Access Policy Self-Assignment | detection | high | T1555.006, T1556 |
| Large Number of Items Accessed in Short Time | detection | high | T1555.006 |
| Large Number of Items Deleted in Short Time | detection | high | T1485, T1555.006 |
| Large Number of Items Listed in Short Time | hunt | medium | T1555.006 |
| New IP Added to Firewall | detection | medium | T1562.007, T1555.006 |
| Potential Privilege Escalation | detection | high | T1555.006, T1556 |
| Vaults Without RBAC Authorization | posture | medium | T1555.006, T1556 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Activity from New IP Not Seen in 90 Days | hunt | low | T1078.004 |
| Diagnostic Setting Deleted | detection | high | T1562.008 |
| Diagnostic Setting Modified | detection | medium | T1562.008 |
| Uncommon Caller IP Addresses | hunt | low | T1078.004 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Firewall Policy Updated | detection | medium | T1562.007 |
| NIC Modified | hunt | low | T1578 |
| NSG Deleted | detection | medium | T1562.007 |
| NSG Inbound Rule Allowing Management Ports | detection | high | T1562.007 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Privileged Role Assigned | detection | high | T1098.003, T1548 |
| Privileged Role Assigned to Subscription | detection | high | T1098.003, T1548 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Analytic Rule Deleted | detection | high | T1562.001 |
| Analytic Rule Modified | detection | medium | T1562.001 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Mass Blob Download | detection | high | T1530 |
| Multiple Storage Account Keys Accessed in Short Time | detection | medium | T1552, T1530 |
| New IP Added to Storage Account Firewall | detection | medium | T1562.007, T1530 |
| Public Access Enabled on Storage Account | detection | high | T1562.007, T1530 |
| Storage Account Container Deleted | detection | medium | T1485 |
| Storage Account Keys Accessed | hunt | low | T1552, T1530 |
| Storage Account Keys Listed | hunt | low | T1530 |
| Storage Accounts with Public Access | posture | medium | T1562.007 |
| Query | Type | Severity | MITRE |
|---|---|---|---|
| Antivirus Exclusion Added | detection | medium | T1562.001 |
| Rundll32 With No Command Line | detection | medium | T1218.011, T1055 |