Run Hunting Queries

Overview of Hunting Queries

Hunting queries are proactive, on-demand searches that help uncover suspicious patterns and potential threats in your KMIP environment. Four pre-built queries are available under Threat managementHunting Queries.

Query

Purpose

Rare KMIP users

Detect newly provisioned or unknown service accounts

New source IPs

Surface unauthorized clients reaching the KMIP API

High-volume key retrievals

Identify credential harvesting or data exfiltration staging

After-hours activity

Catch insider or opportunistic activity outside business hours

Hunting queries

Run queries weekly as part of your threat hunting routine to proactively search for emerging threats. Correlate findings with analytic alerts and workbook trends to build a complete picture of potential threats and validate your concerns.

How to Run the Queries

Follow these steps to execute a hunting query against your ESKM data.

  1. Navigate to Threat management Hunting Queries.

  2. Search for Utimaco ESKM to find the available queries.

  3. Select a query to view its KQL logic.

  4. Click Run Selected Queries to execute it against your data.

  5. Click View results to review the results in the Log Analytics editor.

Using Results

After running a query, systematically review and action the results to strengthen your threat hunting process and incident response workflow:

  • Select significant result rows from the results table to review the details.

  • Link to incident from the toolbar options for findings that warrant investigation and team assignment.

  • Run queries weekly as part of your threat hunting routine to proactively search for emerging threats.