Threat Hunting with Kusto The Query Language to Uncovering the Unknown

Threat Hunting with Kusto The Query Language to Uncovering the Unknown

Source: YouTube · SANS Cloud Security · published Oct 25, 2024 · 30:09

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

This video introduces Kusto Query Language (KQL) for threat hunting in Microsoft Sentinel, covering basic syntax, advanced analytics like time series and graph semantics, and scaling strategies across multi-tenant environments.

Key Takeaways:
• KQL is the foundational query language for the Microsoft ecosystem, used in Defender and Sentinel to discover patterns and anomalies 1:00.
• Basic operations include filtering with where, aggregating with summarize, and joining tables to correlate data from different sources 2:30.
• Advanced features like time-series allow for statistical baselining to detect anomalies, while graph semantics enable visualization of complex relationships like lateral movement 12:00.
• Scaling threat hunting is possible via the Defender Multi-Tenant Portal, cross-workspace queries in Sentinel, or external APIs for automation 18:00.
• The session highlights using external data sources, such as Azure Blob Storage, to enrich queries with threat intelligence without exposing sensitive data 15:00.

Mastering KQL empowers security teams to proactively hunt threats and scale operations effectively across complex Microsoft environments.

Sources:

  • 0:00 Introduction to speakers and KQL scope
  • 1:00 Clarification of KQL vs. Kibana and core capabilities
  • 2:30 Basic KQL operators: filter, join, and aggregate
  • 12:00 Advanced analytics: time series and graph semantics
  • 15:00 Integrating external data and threat intel

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

all right so I'm Stephan Sherling um work for one win uh we um do a lot of Microsoft 365 and Sentinel and work with custo all day long more or less so um today we're going to talk a bit about custo threat hunting how we can scale this across custo and some training resources and I have with me Matias yes Matas for work with one win as a threat Hunter and um been doing cust for for some time now uh which is super exciting and um I've also been doing other cor languages uh in other seam platforms and so on um so what we have done here is is to try to U um to get as much content as possible to squeeze into 30 minutes uh so I think we jump forward a little bit yes let's go right cust or kql um so kqu not to uh mix it up with kibana quer language now we're talking custa quer language and we're …