#kql
KQL: The Silent Force Multiplier in Modern Cybersecurity – How One Course Turned a CTF into a 2‑Hour Conquest + Video

Introduction: In the high-stakes arena of cybersecurity, proficiency in specialized query languages like Kusto Query Language (KQL) is rapidly becoming the differentiator between…
KQL: The Silent Force Multiplier in Modern Cybersecurity – How One Course Turned a CTF into a 2‑Hour Conquest + Video
Introduction: In the high-stakes arena of cybersecurity, proficiency in specialized query languages like Kusto Query Language (KQL) is rapidly becoming the differentiator between reactive defenders and proactive hunters. The recent feat of a security professional solving the complex YellowHat Capture The Flag (CTF) challenge in a mere two hours, attributed to advanced KQL training, underscores a critical shift: mastering data interrogation is paramount for threat detection, engineering, and response within modern SIEM and XDR platforms like Microsoft Sentinel.
undercodetesting.com
January 14, 2026 at 1:51 AM
Another Learning Opportunity! Passing the Must Learn KQL Assessment https://charbelnemnom.com/passing-the-must-learn-kql-assessment/##Microsoft##Azure##Blog > Please RP if you like it!
January 13, 2026 at 1:30 PM
Catch CoffeeLoader Red-Handed: The One KQL Query That Exposes Its Lame iPhone Disguise + Video

Introduction: In the ever-evolving threat landscape, malware authors constantly tweak their tradecraft to evade detection. A prime example is CoffeeLoader, a malicious downloader, which employs a…
Catch CoffeeLoader Red-Handed: The One KQL Query That Exposes Its Lame iPhone Disguise + Video
Introduction: In the ever-evolving threat landscape, malware authors constantly tweak their tradecraft to evade detection. A prime example is CoffeeLoader, a malicious downloader, which employs a hardcoded User Agent string impersonating an iPhone to blend into benign network traffic. This article delves into a precise Kusto Query Language (KQL) hunting rule designed to catch this deception by correlating the suspicious User Agent with non-iOS system data, showcasing practical threat hunting in Microsoft Sentinel.
undercodetesting.com
January 11, 2026 at 3:26 PM
100 Days of KQL 2026: Filename pattern for RAT dropped in BSOD Clickfix Campaign
100 Days of KQL 2026: Filename pattern for RAT dropped in BSOD Clickfix Campaign
github.com
January 9, 2026 at 2:09 PM
100 Days of KQL 2026: Unusual use of msbuild.exe to execute code inside .proj file to bypass AV detection
100 Days of KQL 2026: Unusual use of msbuild.exe to execute code inside .proj file to bypass AV detection
github.com
January 9, 2026 at 6:09 AM
Automating OneLake shortcuts for Eventhouse? While the UI is one-click, automation needs two REST calls: shortcut creation + KQL external table. Here's the complete step-by-step guide 👇

anssitehti.eu/how-to-autom...

#MicrosoftFabric #OneLake #RealTimeaAalytics
How to Automate OneLake Shortcuts for Eventhouse (Step-by-Step) - Anssi Pannula
Automate OneLake shortcuts for Eventhouse with a two-step REST API approach. Complete guide with code examples and authentication details.
anssitehti.eu
January 7, 2026 at 3:07 PM
The Click That Crashes Your World: Hunting AsyncRAT’s BSOD Campaign with KQL + Video

Introduction: A sophisticated malware campaign is disguising the notorious AsyncRAT remote access trojan within a seemingly benign "ClickFix" utility, which deliberately triggers a Blue Screen of Death (BSOD) to…
The Click That Crashes Your World: Hunting AsyncRAT’s BSOD Campaign with KQL + Video
Introduction: A sophisticated malware campaign is disguising the notorious AsyncRAT remote access trojan within a seemingly benign "ClickFix" utility, which deliberately triggers a Blue Screen of Death (BSOD) to cover its malicious installation tracks. This dual-action attack—system disruption followed by silent, persistent backdoor access—exemplifies modern evasion techniques, making detection a critical challenge for Security Operations Centers (SOCs). This article delves into the threat hunting methodology using Kusto Query Language (KQL) to uncover this activity within Azure Sentinel, transforming raw telemetry into actionable security intelligence.
undercodetesting.com
January 7, 2026 at 9:13 AM
KQL Mastery 2026: The Ultimate Guide to Hunting Threats with the Community’s Sharpest Queries + Video

Introduction: Kusto Query Language (KQL) has cemented itself as the indispensable lingua franca for security professionals operating in Microsoft ecosystems like Microsoft 365 Defender, Sentinel,…
KQL Mastery 2026: The Ultimate Guide to Hunting Threats with the Community’s Sharpest Queries + Video
Introduction: Kusto Query Language (KQL) has cemented itself as the indispensable lingua franca for security professionals operating in Microsoft ecosystems like Microsoft 365 Defender, Sentinel, and Azure. As the threat landscape evolves, so does the collective knowledge of the KQL community. This article dives into the 2026 update of essential KQL resources, transforming raw repositories into actionable defensive tactics. Learning Objectives:
undercodetesting.com
January 6, 2026 at 2:42 AM
😡🎙️ La colère est vive contre l'arbitrage à Lille ! Thomas Meunier est furieux alors que Bruno Genesio a évoqué des raisons personnelles pour préférer éviter la conférence de presse
➡️ https://l.onzemondial.com/Kql
January 3, 2026 at 10:38 PM
Microsoft Intune: Analyze Intune Logs with Kusto Query Language (KQL)!
@microsoft.com @mvpaward.bsky.social @msintune.bsky.social #Microsoft #kql #intune #mvpbuzz #coolstuff
👇👇👇👇
github.com/tomwechsler/...
December 23, 2025 at 3:31 PM
As letras escolhidas foram... KQL!
December 19, 2025 at 5:00 AM
As letras escolhidas foram... KQL!
December 17, 2025 at 4:07 AM
Master Your Microsoft Sentinel Spend: The KQL Hacks That Expose Invisible Cloud Costs + Video

Introduction: In the world of cloud-native security, Microsoft Sentinel provides unparalleled threat visibility, but its pay-per-gigabyte ingestion model can lead to unpredictable and soaring costs.…
Master Your Microsoft Sentinel Spend: The KQL Hacks That Expose Invisible Cloud Costs + Video
Introduction: In the world of cloud-native security, Microsoft Sentinel provides unparalleled threat visibility, but its pay-per-gigabyte ingestion model can lead to unpredictable and soaring costs. Security teams are often blindsided by monthly bills, struggling to answer the fundamental question: "What is generating this cost, and is it worth it?" Ian Hanley's inaugural "KQL Toolbox" post delivers the essential scripts and methodology to transform cost data into actionable intelligence, empowering teams to govern their SIEM spend without sacrificing security coverage.
undercodetesting.com
December 16, 2025 at 2:51 AM
when you use copilot to write a kql query don’t forget to remove that last line that’s just two single quote marks. you don’t need that. it’s vestigial
December 15, 2025 at 9:02 PM
From Reactive Alerts to Proactive Hunts: How KQL is Revolutionizing SOC Defense + Video

Introduction: The modern Security Operations Center (SOC) is shifting from a reactive alert-response model to a proactive threat-hunting paradigm. This evolution is powered by tools like Microsoft Defender for…
From Reactive Alerts to Proactive Hunts: How KQL is Revolutionizing SOC Defense + Video
Introduction: The modern Security Operations Center (SOC) is shifting from a reactive alert-response model to a proactive threat-hunting paradigm. This evolution is powered by tools like Microsoft Defender for Endpoint and the Kusto Query Language (KQL), which allow analysts to sift through vast telemetry data to find hidden adversaries. By leveraging frameworks like MITRE ATT&CK and writing precise KQL queries, security teams can now assume a breach and actively search for malicious tactics, techniques, and procedures (TTPs) before they escalate into full-blown incidents.
undercodetesting.com
December 14, 2025 at 10:26 AM
KustoHawk is a PowerShell triage tool for Defender XDR/Sentinel that runs Graph API runHuntingQuery KQL across environments, aggregates device and identity hits, and exports HTML/CSV for investigations. #tool #KQL #DefenderXDR https://bit.ly/48C7mmV
December 13, 2025 at 7:17 PM
🎙️ Avec Yoan Schinck sur le threat hunting en KQL!

Au menu:
• Workshop threat hunting dans Microsoft Sentinel
• Détection d'abus de comptes de service

🎧 Web: bit.ly/4oBulU1
🎧 Spotify: bit.ly/4iFhO0a
🎧 YouTube: bit.ly/48z6649

#Cybersécurité #ThreatHunting #KQL #SOC
December 11, 2025 at 2:52 PM
Watching the session from @ericberg.de at #CloudBrew ! Nice talk about #Azure #Monitor with #Copilot and #KQL!
December 11, 2025 at 9:45 AM
KQL MCP Server - A Model Context Protocol (MCP) server that searches all of GitHub for KQL (Kusto Query Language) queries using natural language.

www.npmjs.com/packag...
December 10, 2025 at 3:48 PM
@liorbela.bsky.social
🎥 How to Use Device Query for Multiple Devices using Intune Portal
👉All Query Statements are Separated by a ;
👉The Kusto Query Language (KQL) query Editor Supports IntelliSense and has a Parser Tuned for this Scenario
www.youtube.com/watch?v=dmKh...
December 9, 2025 at 5:26 AM
Day 6 of our Education Advent! ⚡
Kusto Query Language powers fast, scalable real-time analytics.

📘 KQL basics: learn.microsoft.com/azure/data-e...

📝 Community intro by #KQL experts: kusto.blog
December 6, 2025 at 8:49 AM