
About this episode
Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!
Links
- Threat Intelligence Blog
- Phishing-Resistant Passwordless Authentication
- Kusto Query Language
- Microsoft Sentinel
- Microsoft Security Copilot
- KQL Guide on GitHub
Recorded December 19, 2024
Get every episode summarized
Each time RunAs Radio publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.
Email me new episodesFree for 3 shows. No card needed.
Hosts & guests
No transcript yet
This episode has not been transcribed. Request it and it moves to the front of the queue.
More episodes
More from RunAs Radio

State of WSUS with Adam Marshall
RunAs Radio

Reimagining Intranets with Susan Hanley
RunAs Radio

Security Features of PowerShell 7 with Mike O'Neill
RunAs Radio

Automatic Attack Disruption with Liz Tesch
RunAs Radio