• Stars
    star
    970
  • Rank 47,174 (Top 1.0 %)
  • Language
  • License
    MIT License
  • Created about 3 years ago
  • Updated 9 months ago

Reviews

There are no reviews yet. Be the first to send feedback to the community and the maintainers!

Repository Details

Code included as part of the MustLearnKQL blog series

Must Learn KQL - the blog series, the book, the video channel, the merch store, the workshop, and much more...

Must Learn KQL

This repository contains the code, queries, and eBook included as part of the MustLearnKQL series. The series is a continuing effort to discuss and educate about the power and simplicity of the Kusto Query Language.

The eBook (PDF) is updated whenever changes are made or new parts of the series are released. Get the book: https://github.com/rod-trent/MustLearnKQL/tree/main/Book_Version

Want a paperback version of the book? You can order a copy from Amazon.com: https://amzn.to/39maJSX - (as with the merch below, all profit goes directly to St. Jude)

There's a YouTube channel for the Must Learn KQL series. My colleague, David Hall, is taking the series and producing follow-along videos: Follow that here: https://youtu.be/rcy2uSMLyqo

Love the series so much you want a coffee mug? There's now a merch store where all proceeds go to St. Jude Children's Research Hospital. Check it out! MUST LEARN KQL STORE

The series has it's own shortlink. To return back here, just remember the easy URL: https://aka.ms/MustLearnKQL

Must Learn KQL is always evolving and updating. Curious about what's new and exciting? Monitor the What's New page

Looking for Advanced topics? Check out the Addicted to KQL series: http://aka.ms/Addicted2KQL

Table of Contents

The following are links to the entire series so far:

* Must Learn KQL Part 1: Tools and Resources - Posted November 17, 2021 - Video Edition
* Must Learn KQL Part 2: Just Above Sea Level - Posted November 18, 2021
* Must Learn KQL Part 3: Workflow - Posted November 19, 2021 - Video Edition
* Must Learn KQL Part 4: Search for Fun and Profit - Posted November 22, 2021
* Must Learn KQL Part 5: Turn Search into Workflow - Posted November 29, 2021 - Video Edition
* Must Learn KQL Part 6: Interface Intimacy - Posted December 2, 2021, Updated May 13, 2022 - Video Edition
* Must Learn KQL Part 7: Schema Talk - Posted December 7, 2021 - Video Edition
* Must Learn KQL Part 8: The Where Operator - Posted December 8, 2021 - Video Edition
* Must Learn KQL Part 9: The Limit/Take Operators - Posted December 13, 2021 - Video Edition
* Must Learn KQL Part 10: The Count Operator - Posted December 14, 2021 - Video Edition
* Must Learn KQL Part 11: The Summarize Operator - Posted January 5, 2022 - Video Edition
* Must Learn KQL Part 12: The Render Operator (with Bin and Time) - Posted January 10, 2022 - Video Edition
* Must Learn KQL Part 13: The Extend Operator - Posted January 18, 2022 - Video Edition
* Must Learn KQL Part 14: The Project Operator - Posted January 20, 2022 - Video Edition
* Must Learn KQL Part 15: The Distinct Operator - Posted January 24, 2022 - Video Edition
* Must Learn KQL Part 16: The Order/Sort and Top Operators - Posted January 26, 2022 - Video Edition
* Must Learn KQL Part 17: The Let Statement - Posted February 1, 2022 - Video Edition
* Must Learn KQL Part 18: The Union Operator - Posted February 7, 2022 - Video Edition
* Must Learn KQL Part 19: The Join Operator - Posted February 14, 2022 - Video Edition
* Must Learn KQL Part 20: Building your first Microsoft Sentinel Analytics Rule - Posted February 17, 2022 - Video Edition


Did you complete the entire series?!! Well, congratulations! When you're ready, take the assessment and receive a bona fide certificate!

The assessment is 25 questions taken directly from the Must Learn KQL series. So, you can take advantage of the open book test, or challenge yourself by attempting to pass without help. Based on the honor system, you can miss 5 questions (80%). Once completed, send an email request to [email protected] and request your certificate.

Take the assessment: Must Learn KQL Assessment (https://aka.ms/PassMustLearnKQL)



Must Learn KQL

More Repositories

1

SentinelKQL

Azure Sentinel KQL
410
star
2

Sentinel-SOC-101

Content and collateral for the Microsoft Sentinel SOC 101 series
PowerShell
154
star
3

OpenAISecurity

Scripts and Content for working with Open AI
Python
149
star
4

Copilot-for-Security

My personal work with Copilot for Security
HTML
143
star
5

AddictedtoKQL

This is an advanced KQL blog series and book
108
star
6

SentinelWorkbooks

Workbooks for Azure Sentinel
52
star
7

SentinelPlaybooks

52
star
8

KQL-for-Everything

KQL example queries for working in Azure
33
star
9

SentinelPS

PowerShell
29
star
10

Azure-Sentinel-Cost-Troubleshooting-Kit

Guidance and collateral for troubleshooting and managing Azure Sentinel data costs.
25
star
11

KQLMysteries

The collateral repository for The KQL Mysteries series
18
star
12

OnPremSecMonitoring4Sentinel

17
star
13

IncidentTasksRecipes

Microsoft Sentinel Incident Tasks Recipes
10
star
14

AzureSentinelMisc

Miscellaneous Azure Sentinel files that don't fall into other categories.
10
star
15

QuantumSecurity

Must Learn Quantum Security
7
star
16

MSIgnite-2023-Security-PreDay

6
star
17

Prompt_Refiner

A web-based tool to create better prompts
HTML
5
star
18

DefenderKQL

KQL queries for Advanced Defender Hunting
4
star
19

SOC_Score

Building the SOC Score for Azure Sentinel
4
star
20

MustLearn

Main page to the Must Learn series
4
star
21

SecurityAdvocacy

3
star
22

WW2045

Welcome to the repository for WW2045: Alien Revenge by Rod Trent
2
star
23

SentinelWatchlists

Watchlists for Microsoft Sentinel
2
star
24

ASCKQL

KQL queries for Azure Security Center/Defender
2
star
25

SentinelRecipes

This repository provides guidance (or recipes) for handling investigations and hunting specific to exposed scenarios.
2
star
26

RodsAITourRepo

Demo Repo for the Microsoft AI Tour
Python
2
star
27

QuantumTides

Repository for the fiction book Quantum Tides by Rod Trent
1
star
28

TwinWithin

Repository for the Ethan Veritas: The Twin Within book
1
star
29

Resource-Graph-KQL

KQL queries for use in Azure Resource Graph Explorer
1
star
30

ThreatIntelligence

Threat Intelligence IOCs
1
star
31

CloudPC-Sentinel

1
star
32

KQLforFitness

Data files and KQL for Fitness apps
1
star