Detecting network beacons via KQL using simple spread stats functions
8 min readApr 30, 2021
--
What’s a network beacon? Why is that important? Well, let’s start with a quick definition before jumping into detection design and KQL code.
As Google suggests, beacon is a visible object serving as a signal or warning. That’s what we, as detection engineers, are looking for when deploying a new detection or analytic rule.