Scenarios
Atomic KQL is vocabulary. A scenario is the grammar that chains primitives into one defensible incident. Each step is labelled with honest detection maturity — what is theorized, what is static-reviewed, what has been lab-tested or field-observed.
ClickFix -> Potemkin Loader -> Hands-on-Keyboard
static-reviewedA user on a compromised website pastes a single copy-and-paste 'fix' command into the Run dialog. Through a LOLBin proxy chain (pcalua -> mshta -> msiexec) the Potemkin loader is silently installed, which then reflectively loads a credential-stealing module (RMMProject) entirely in memory. A human operator takes over, pulls in the blockchain-resolved EtherRAT backdoor, tunnels out through a renamed cloudflared, moves laterally to the domain controller and dismantles Defender step by step. The whole intrusion starts on one endpoint that had no monitoring agent - the single point where none of the signals below could ever have fired.
eCrime / access-to-ransomware (EtherRAT hands-on-keyboard endgame documented)~5h from ClickFix paste to EtherRAT deployment; domain controller reached in the same session11 stepsHuntressDefender XDR · Microsoft SentinelTrigona Ransomware in 3 Hours
static-reviewedA domain Administrator credential logged into an internet-exposed RDP host (no brute force), and 2h49m later Trigona was encrypting the whole network over SMB. Every step rode valid admin creds and built-in tooling, so each signal alone reads as legitimate administration. The incident is only defensible by chaining the steps on one identity within a 3h window. This is the cleanest possible proof that fidelity lives in correlation, not in any single query.
Trigona Ransomware~2h49m initial access to encryption6 stepsThe DFIR Report #19172Defender XDR · Microsoft Sentinel