In this video, I walk through a full KQL log analysis course using Microsoft Sentinel and Microsoft Defender. It’s a practical, end-to-end breakdown of how KQL is actually used to investigate logs, detect threats, and support real security operations.
———
⚡️ Cyber Range: Enterprise Tools + Internships + Employment Verification ⚡️
https://skool.com/cyber-range
📊 Sample Log Export (Google Sheets) 📊
https://docs.google.com/spreadsheets/...
🎯 Threat Hunt Sample Report 🎯
https://docs.google.com/document/d/1d...
🎯 KQL Threat Hunting Curriculum 🎯
https://docs.google.com/document/d/1S...
———
00:00 Intro
00:29 Why Learn KQL
01:58 Course Overview
03:50 Accessing the Environment
06:03 What Are Logs
10:17 How Logs Are Stored
13:03 Tables Explained
15:11 Querying Logs and KQL Practice
19:42 Filtering with KQL
38:03 Counting and Summarizing Logs
49:23 Threat Hunt Brief
49:24 Threat Hunt Intro
52:07 Flag 1 Initial Access - Remote Source
56:27 Flag 2 Initial Access - Compromised Account
57:13 Flag 3 Discovery - Network Recon
01:04:12 Flag 4 Defense Evasion - Malware Staging
01:09:00 Flag 5 Defense Evasion - Extension Exclusions
01:13:03 Flag 6 Defense Evasion - Temp Folder
01:16:22 Flag 7 Defense Evasion - Download Abuse
01:19:31 Flag 8 Persistence - Scheduled Task Name
01:20:46 Flag 9 Persistence - Task Target
01:21:28 Flag 10 C2 Server Address
01:30:21 Flag 11 C2 Communication Port
01:31:19 Flag 12 Credential Access - Theft Tool
01:34:50 Flag 13 Credential Access - Memory Module
01:35:47 Flag 14 Collection - Data Archive
01:37:34 Flag 15 Exfiltration Channel
01:41:06 Flag 16 Anti-Forensics - Log Tampering
01:43:17 Flag 17 Impact - Persistence Account
01:49:31 Flag 18 Execution - Malicious Script
01:51:35 Flag 19 Lateral Movement - Secondary Target
01:53:56 Flag 20 Lateral Movement - RAT
01:54:27 Report Explanation