KQLCafe (@kqlcafe) 's Twitter Profile
KQLCafe

@kqlcafe

A Community to make the world a better place with KQL | Learn, share and practice the KQL language | #kql #threathunting #security

ID: 1451885404198735873

linkhttp://www.kqlcafe.com calendar_today23-10-2021 12:19:23

176 Tweet

1,1K Followers

2 Following

Alex Verboon (@alexverboon) 's Twitter Profile Photo

Interested to learn more about Azure Fabric? Join us at the #KQLCafe tomorrow Tuesday February 25, 18:00 CET with guest speaker Uri Barash More information and registration here: kqlcafe.com/#upcoming-shows #KQL #AzureFabric #Kusto

Ugur Koc (@ugurkocde) 's Twitter Profile Photo

🔍 Unlocking Deeper Insights with Multi-Device Queries in Intune You’re working on incidents and need to identify all devices with outdated BIOS. Or maybe you’re planning a Windows 11 rollout and must find devices without TPM 2.0. Running queries one device at a time? That’s

🔍 Unlocking Deeper Insights with Multi-Device Queries in Intune

You’re working on incidents and need to identify all devices with outdated BIOS. Or maybe you’re planning a Windows 11 rollout and must find devices without TPM 2.0. Running queries one device at a time? That’s
Matt Zorich (@reprise_99) 's Twitter Profile Photo

In preview, we now link identifiers such as sessionId and uniqueTokenIdentifier across telemetry in Entra and M365 to help your threat hunters and incident responders track activity bound to a single authentication, check it - learn.microsoft.com/en-us/entra/id…

Nicola Suter (@nicolonsky) 's Twitter Profile Photo

Microsoft is introducing a new data schema for TI data within #Sentinel. From 31. July 2025 data ingestion will transition exclusively to the new ThreatIntelIndicators and ThreatIntelObjects tables. #KQL to identify refs to old tables for analytic rules: github.com/nicolonsky/ITD…

Microsoft is introducing a new data schema for TI data within #Sentinel. From 31. July 2025 data ingestion will transition exclusively to the new ThreatIntelIndicators and ThreatIntelObjects tables. #KQL to identify refs to old tables for analytic rules: github.com/nicolonsky/ITD…
Aura (@securityaura) 's Twitter Profile Photo

Since we're almost nearing the end of my take on the #100DaysOfKQL challenge, I would like to know if you used one of the queries, as it was, or improved and if so, did you end up finding something? Anything: suspicious, malicious, unexpected, etc. Would love to know about it.

Thomas Naunheim (@thomas_live) 's Twitter Profile Photo

I've published a #KQL function ("WorkloadIdentityInfoXDR") for #MicrosoftDefender to enhance details of #MicrosoftEntra #WorkloadID from various sources, incl. the new table "OAuthAppInfo" but also IdentityInfo table and #ExposureManagement. (1/2) 🔗 github.com/Cloud-Architek…

I've published a #KQL function ("WorkloadIdentityInfoXDR") for #MicrosoftDefender to enhance details of #MicrosoftEntra #WorkloadID from various sources, incl. the new table "OAuthAppInfo" but also IdentityInfo table and #ExposureManagement. (1/2)
🔗 github.com/Cloud-Architek…
Aura (@securityaura) 's Twitter Profile Photo

#100DaysOfKQL Day 100 - CScript.exe, WScript.exe or MSHTA.exe Executed from Web Browser Process IT'S FINALLY OVER! I had another query in store for today, but I feel like this challenge wouldn't be complete without that one. (cont) github.com/SecurityAura/D…

Bert-Jan 🛡️ (@bertjancyber) 's Twitter Profile Photo

Microsoft announced the public preview of the OAuthAppInfo table in the Advanced Hunting schema. I created multiple #KQL queries to help you kick-start the usage of this table.🚀 The queries help you to identify high-permissive, unused and external apps. github.com/Bert-JanP/Hunt…

Bert-Jan 🛡️ (@bertjancyber) 's Twitter Profile Photo

Are you joining The KQLCafe next week? I will be talking about #KQL, Logic Apps, APIs and a combination of the three during the session. Interested? Register here: meetup.com/kql-cafe/event… 📅 When: April 29 18:00 - 19:30 (CET) 🖥️ Where: Online 💰 Cost: Free of charge

Bert-Jan 🛡️ (@bertjancyber) 's Twitter Profile Photo

The ClickFix Triage KQL query is now available. The blog will be out next Tuesday. github.com/Bert-JanP/Hunt… Enjoy the weekend!

Bert-Jan 🛡️ (@bertjancyber) 's Twitter Profile Photo

Some time ago, I developed some #KQL queries to get insights on the data you have available. The results list information about tables, sub-tables and entities. Choosing a proactive approach to your data is highly recommended to stay on top of threats. github.com/Bert-JanP/Hunt…

Gianni (@castello_johnny) 's Twitter Profile Photo

Bert-Jan Pals joins the latest #KQLCafe to share how he uses Microsoft security APIs and Azure Logic Apps for incident automation! Hosted by Alex Verboon . Plus, save the date for #KustoCon 2025 (Nov 6 in Zurich). youtu.be/sQaBtJ9UU5k

Sarah Lean 🏴󠁧󠁢󠁳󠁣󠁴󠁿 (@techielass) 's Twitter Profile Photo

New to KQL? In this quick beginner’s guide, I’ll explain what Kusto Query Language is, where it’s used in Azure, and how to write simple queries using operators and functions. Perfect for IT pros, security analysts, and data enthusiasts. bit.ly/4d69vId

New to KQL? In this quick beginner’s guide, I’ll explain what Kusto Query Language is, where it’s used in Azure, and how to write simple queries using operators and functions. Perfect for IT pros, security analysts, and data enthusiasts. 

bit.ly/4d69vId
Aura (@securityaura) 's Twitter Profile Photo

Finally took the time to write a quick blog post on my #100DaysOfKQL challenge. medium.com/@securityaura/… The tl;dr is that I'm never doing anything like this again, at least, not before I have a LOT more free time than I have now. But very happy to have gone through with it!

ᴍɪᴄʜᴀʟɪs ᴍɪᴄʜᴀʟᴏs (@cyb3rmik3) 's Twitter Profile Photo

Next Tuesday, May 27th Christos Galanopoulos and I will join my dear fellows Alex Verboon and Gianni at this month's 𝐊𝐐𝐋 𝐂𝐚𝐟𝐞. Christos Galanopoulos and I worked over the past couple of months on 𝐬𝐊𝐚𝐥𝐞𝐐𝐋, a tool that allows query automation on your log

KQLCafe (@kqlcafe) 's Twitter Profile Photo

🎉 KustoCon 2025 is official! Watch the announcement video and register now for the main event or join us onsite in Zurich for also the hands-on detection engineering workshop! Info & sign-up: kustocon.com/sessions/ #KustoCon #KQL #KustoFans

Gianni (@castello_johnny) 's Twitter Profile Photo

📢 New #KQLCafe just dropped on YouTube 🔹 sKaleQL Michals Michalos and Christos Galanopoulos 🔹 Defender hunts Teams messages 🔹 Multi-Tenant Defender is GA 🔹 Detecting malicious PowerShell 🎥 youtu.be/Yna97PlIX18 📝 kqlcafe.com/shownotes/2025… #KQL #DefenderXDR