Track weak signals at scale
via our KQL Multi-Tenant console.
Stealth attacks (APTs) require proactive investigation. Deploy your KQL queries simultaneously across all of your Microsoft 365 Defender tenants, without ever leaving your MSSP admin console.
Classic Threat Hunting MSSP is a time-consuming dead end
Individual connectionsto each customer portal to execute the same query. A 30 minute process for 10 clients.
Overall execution: Multi-Tenant selector to query all your Defender tenants simultaneously.
Absolute mastery of KQLrequired for each L1/N2 analyst, without input assistance or pre-written templates.
Query templates: pre-written templates for ProcessEvents, LogonEvents and NetworkEvents.
Manual CSV exportof each tenant to consolidate in Excel. Aggregated result in hours.
Dynamic results grid: centralized interactive and asynchronous table, result in seconds.
How Akuity SOC is revolutionizing Threat Hunting MSSP
Secure and Asynchronous KQL Terminal
Editing console in monospace font with syntax highlighting (emerald green). Executionasynchronous via Microsoft Advanced Hunting API. Strict Rate Limiting protection with translucent loading screen during recovery.
Integrated Multi-Tenant Selector
Switch between clients with one click from the Threat Hunting tab. Target precisely the tenant on which to run your search. The results are instantly displayed in ainteractive dynamic grid.
Quick Query Templates
Pre-written shortcuts for your analysts:Suspicious processes(PowerShell/CMD via DeviceProcessEvents),Failed Connections(DeviceLogonEvents) andSuspicious network(ports 4444, 8080 via DeviceNetworkEvents).
Neutralizing suspicious communications on port 4444
Proactive investigation with the 'Suspicious network' template
Threat HuntingThe analyst uses the templateDeviceNetworkEventsto scan port 4444 (Command & Control server) activity on a specific tenant.
Discovery and evaluation via the AlienVault OTX gauge
Risk Score 87/100The grid highlights several suspicious network events. Theredestination IP reputationis instantly assessed via our built-in AlienVault OTX gauge.
Remediation — Network isolation validated by MFA
SOAR RemediationThe analyst switches to the incident panel andisolates the network machine via Intuneto stop exfiltration. Action validated by the Microsoft Authenticator application (AAL2).
Master Threat Hunting KQL for MSSP
Why Threat Hunting KQL is time-consuming for an MSSP (and how to automate it)
Proactive investigation is vital but complex at scale. Learn how to automate Threat Hunting KQL across multiple Microsoft Defender tenants.
How to secure your global KQL executions with Rate Limiting
Microsoft's Advanced Hunting API is powerful but subject to quotas. Find out how Akuity SOC Rate Limiting protects your MSSP tenants.
The DeviceProcessEvents practical guide: Uncovering Fileless malware
Attackers use PowerShell and CMD to bypass antiviruses. Learn how to track down these Fileless malware with the KQL DeviceProcessEvents table.
Analyze network connection failures by IP: The KQL model to copy
Brute force and password spraying attacks target your Entra ID accounts. Learn how to track them using the KQL DeviceLogonEvents table.
Isolate suspicious communications: KQL for ports 4444 and 8080
Hackers use non-standard network ports to exfiltrate data. Learn how to block them with the DeviceNetworkEvents table in KQL.