KQL guides
Kusto Query Language — Microsoft's query language for telemetry data across Defender XDR, Sentinel, and Azure Monitor. See the glossary entry →
11 guides touch on kql.
- Defender XDR advanced hunting workshop
How to use Defender XDR advanced hunting effectively — tables, common queries, and threat-hunting patterns.
- Defender XDR and attack-surface management
How Microsoft Defender XDR unifies Defender for Office, Endpoint, Identity, and Cloud Apps into a single SOC workflow.
- Investigating a suspicious sign-in with Entra sign-in logs
How to work a suspicious sign-in in the Entra sign-in logs: which log, which columns matter, traveller vs attacker, and when to escalate to compromise.
- KQL primer for Defender XDR
A practical introduction to Kusto Query Language for Microsoft Defender XDR and Sentinel hunting.
- Microsoft 365 Copilot use cases by role
Specific Copilot use cases for sales, marketing, HR, finance, engineering, and executive roles.
- Microsoft Defender for Identity sensor deployment
How to plan and roll out Defender for Identity sensors — DCs, AD FS, Entra Connect, and tuning.
- Microsoft Security Copilot
Microsoft's AI assistant for security analysts — what it does, where it's embedded, and how it's licensed.
- Microsoft Sentinel analytic rules
How analytic rules work in Sentinel — types, tuning, and writing custom detections.
- Microsoft Sentinel cost optimisation
How to control Microsoft Sentinel costs — ingestion tuning, commitment tiers, retention, and data tiering.
- Microsoft Sentinel for Microsoft 365
How Microsoft Sentinel ingests Microsoft 365 signals and extends Defender XDR into a full SIEM.
- Microsoft Sentinel onboarding
How to onboard Microsoft Sentinel — workspace setup, data connectors, and starting analytic rules.