کتاب Blu Raven Academy | Hands-On KQL for Security Analysts

Elevate your security analysis skills with the Kusto Query Language (KQL) training course, offering hands-on experience in a hyper-realistic lab environment! Whether you’re a security analyst or incident responder utilizing Microsoft Sentinel, Defender for Endpoint, or Microsoft 365 Defender XDR, or simply aspiring to master the KQL for security analysis, this course is for you!

Syllabus

  1. Introduction to Databases and Logging

  2. KQL Fundamentals and Exploring Data

  3. Searching and Filtering Data

  4. Creating and Manipulating Fields

  5. Combining Data Sets

  6. Joining Datasets

  7. Using External Threat Intel Feeds

  8. Time Traveling within the Logs

  9. Aggregating Data

  10. Visualizing Data

  11. Time Series Analysis

  12. Rapid Triage and Investigation Using KQL

  13. Capstone: Incident Response and Threat Hunting

  14. Course Wrap-Up

Blu Raven Academy | Hands-On KQL for Security Analysts