The Must Learn KQL Community Discussion Board

Among all the myriad of cool things that the Must Learn KQL series has birthed, there's now also a Community Discussion board available. The Discussion board is designed to enable Q&A, feedback, ongoing discussions, code posts, polls, and on and on. Must Learn KQL Discussion Board Jump out to the following link to get engaged … Continue reading The Must Learn KQL Community Discussion Board

The Microsoft Security Insights Podcast is Coming to Microsoft Reactor

For fans of the weekly Microsoft Security Insights podcast, Frank, Edward, Brodie, and I have some awesome news to share. The popularity of the podcast continues to grow. Not only is the listener audience in an exploding growth spurt, but there are many security experts coming out of the woodwork asking to come on the … Continue reading The Microsoft Security Insights Podcast is Coming to Microsoft Reactor

Addicted to KQL Part 0: The Wit and Wisdom of Standard Columns in Azure Monitor Logs

The Addicted to KQL series is an ongoing, advanced series for KQL. For beginning topics don't start here. Instead, see the original Must Learn KQL series. The series TOC along with the currently completed chapters, sample queries, series images, and even the series eBook will always be located at the following shortlink: https://aka.ms/Addicted2KQL ======================= I have a … Continue reading Addicted to KQL Part 0: The Wit and Wisdom of Standard Columns in Azure Monitor Logs

Take the Assessment, Get Your Must Learn KQL Certificate

The Must Learn KQL series has reached its completion, but that doesn't mean it's over. In March, I'll kick off the next step in KQL learning in an advanced series called Addicted to KQL. For those just catching on, the Must Learn KQL series has educated close to 5,000 people since it started in November … Continue reading Take the Assessment, Get Your Must Learn KQL Certificate

The Unified Microsoft Sentinel and Microsoft 365 Defender Repository

As product and services always to continue to align its great to see movement in areas that provide pure value. The Microsoft Sentinel GitHub repository has now made room to house Microsoft 365 Defender Hunting queries. KQL is the tie that binds these two security services, and because of that, Hunting queries for Microsoft 365 … Continue reading The Unified Microsoft Sentinel and Microsoft 365 Defender Repository

Update on the Must Learn KQL Series

Since November, I've delivered many pages worth of KQL learning through the Must Learn KQL series. The series has reached heights I never expected and the impact for our customers and for our security products has been incredible. Thanks to everyone for your participation and engagement! I've mentioned this in passing in social network situations, … Continue reading Update on the Must Learn KQL Series

And now…the Must Learn KQL Video series!

Imagine my surprise how popular and far-reaching the Must Learn KQL education series has gotten. I started a blog series about something I knew was important and just hoped -HOPED- someone else would also understand the importance. It's truly taken on a life of itself. I've been invited to speak about it several times already … Continue reading And now…the Must Learn KQL Video series!

New Year’s Resolution: Must Learn KQL in 2022

For those that missed the notification, I'm still off of work until the first week of January. But I'm finding that I truly am a victim of tech FOMO. It's really hard for me to completely shut down and walk away. But this isn't a new phenomenon. I've experienced this my whole professional, adult life. … Continue reading New Year’s Resolution: Must Learn KQL in 2022