Overview of Hunting Queries
Hunting queries are proactive, on-demand searches that help uncover suspicious patterns and potential threats in your KMIP environment. Four pre-built queries are available under Threat management → Hunting → Queries.
|
Query |
Purpose |
|---|---|
|
Rare KMIP users |
Detect newly provisioned or unknown service accounts |
|
New source IPs |
Surface unauthorized clients reaching the KMIP API |
|
High-volume key retrievals |
Identify credential harvesting or data exfiltration staging |
|
After-hours activity |
Catch insider or opportunistic activity outside business hours |
Hunting queries
Run queries weekly as part of your threat hunting routine to proactively search for emerging threats. Correlate findings with analytic alerts and workbook trends to build a complete picture of potential threats and validate your concerns.
How to Run the Queries
Follow these steps to execute a hunting query against your ESKM data.
-
Navigate to Threat management → Hunting → Queries.
-
Search for
Utimaco ESKMto find the available queries. -
Select a query to view its KQL logic.
-
Click Run Selected Queries to execute it against your data.
-
Click View results to review the results in the Log Analytics editor.
Using Results
After running a query, systematically review and action the results to strengthen your threat hunting process and incident response workflow:
-
Select significant result rows from the results table to review the details.
-
Link to incident from the toolbar options for findings that warrant investigation and team assignment.
-
Run queries weekly as part of your threat hunting routine to proactively search for emerging threats.