Testing AI Threat Hunting against Real-World KQL: A Side-by-Side Test (opens in new tab)
A real-world experiment revealing where AI excels and where it still struggles. Here’s an honest breakdown of the gap.The ones that follow this blog long enough know that I write SPL for a living. It's almost 10 years as an independent consultant since working for Splunk itself and I can't get enough of it.However, one thing has changed in the last 3–4 years: the Microsoft Defender ecosystem has grown massively. As a result, I now spend just as much time writing KQL as I do writing queries in...
Read the original article