Date of completion: 01/2026
Summary
I was able to get the SOC agent to give me what had gone wrong on the VM computers. Thereafter, I was able to feed that into a Ai online, and they gave me the story of what was wrong. Using this method and the Ai online, I was able to get the KQL code for searching the Azure cyber range. I found some of the flags via this method. However, this is an aid and not a full solution, as I had to come up with some KQL myself, and I often had to modify the KQL given by the Ai. Moreover, I still was not able to find some of the flags with ease. I have not included a full write-up of the threat hunts, as this was a proof-of-concept exercise. This showed me that this method is around 40% effective at finding flags. This brings into question its ethical use, as some threat hunts are award-based for the fastest person to complete them.
