Detecting network beacons via KQL using simple spread stats functions

Alex Teixeira
8 min readApr 30, 2021

What’s a network beacon? Why is that important? Well, let’s start with a quick definition before jumping into detection design and KQL code.

As Google suggests, beacon is a visible object serving as a signal or warning. That’s what we, as detection engineers, are looking for when deploying a new detection or analytic rule.

Alex Teixeira

I design and build threat detection models and triage/hunting interfaces for Enterprise #SecOps teams #DetectionEngineering http://opstune.com