KQL for Security Analysts

Learn KQL from your first query to mastery

The query language of Microsoft Sentinel and Defender Advanced Hunting, taught a rung at a time against a month of records from a company under attack. Every query runs in the page, every answer is checked, and nothing assumes you have written KQL before.

Included with Premium, from $19.99/month, or $179/year and save 25%. Preview the first module free, no account needed.
Your subscription also includes the Practice Hub: graded scenarios, forensic cases, query drills and the response playbooks.
View Pricing Take End of Course Exam → 40 CPE Credits

What you'll be able to do

✓Read, filter and shape any table in Microsoft Sentinel and Defender Advanced Hunting
✓Count correctly: distinct counts, distributions, rates and the averages that mislead
✓Combine tables with union, every kind of join and lookup, and keep joins honest by counting rows
✓Turn free text, JSON and arrays into columns, and write reusable logic with let and functions
✓Analyze time series and follow relationships as graphs
✓Keep queries fast and answers right, including borrowed and AI-written KQL
SEC201 | Premium tier | 10 teaching modules, an orientation and a Project | 36–40 hours at your own pace | 40 CPE credits

Course Syllabus

Every module and every lesson. The first three modules are open; the rest open on a click.

Download the full syllabus (PDF)

Orientation

Module 0Course OrientationCourse Preview

KQL for Security Analysts: the query language of Microsoft Sentinel and Defender, taught against one month of an engineering company's records with several real attacks in them. What KQL is, how security data is stored, the tables analysts query, the two places queries run, a first query, the practice lab, how the course climbs from basics to mastery, and a six-scenario check of whether it fits you.

Show 8 lessonsHide lessons
  1. 0.10.1 What KQL Is and Where It RunsPreview
  2. 0.20.2 How Security Data Is StoredPreview
  3. 0.30.3 The Tables a Security Analyst QueriesPreview
  4. 0.40.4 Sentinel Logs and Defender Advanced Hunting ComparedPreview
  5. 0.50.5 Your First QueryPreview
  6. 0.60.6 The Practice Lab and the Sample MonthPreview
  7. 0.70.7 How to Learn KQL: the Mastery LadderPreview
  8. 0.80.8 What This Course BuildsPreview

Foundation

Module 1Query Structure and Data Types

Module 1 of KQL for Security Analysts: how a KQL query is built from statements and a pipe of tables, how to explore a table and choose its columns, the ten scalar types, conversion, null and empty values, and a six-pass method for reading a query someone else wrote.

Show 9 lessonsHide lessons
  1. 1.11.1 Turning a Question into KQL
  2. 1.21.2 Statements and Tabular Expressions
  3. 1.31.3 The Pipe and Operator Order
  4. 1.41.4 Learning a Table You Have Never Seen
  5. 1.51.5 What a Value Really Is: Types and Conversion
  6. 1.61.6 Incomplete Data: Nulls, Empties and Gaps in Coverage
  7. 1.71.7 Checking a KQL Result Against Its Table
  8. 1.81.8 Reading a Query You Did Not Write
  9. 1.9Module Summary and Knowledge Check
Module 2Searching and Filtering

Module 2 of KQL for Security Analysts: finding where a value lives with search and find, narrowing a table with where, matching text the way the engine indexes it, working in time windows and around an event, and filtering addresses, nested fields and negations without losing rows.

Show 9 lessonsHide lessons
  1. 2.12.1 Searching for a Value When You Do Not Know the Column
  2. 2.22.2 Narrowing a Table to the Events That Matter
  3. 2.32.3 Matching Text the Way the Engine Indexes It
  4. 2.42.4 Working Inside a Time Window
  5. 2.52.5 Pivoting on a Timestamp: Windows Around an Event
  6. 2.62.6 Filtering Addresses and Ranges
  7. 2.72.7 Filtering Inside Nested Fields
  8. 2.82.8 Negative Filters: !in, !has, not() and What They Silently Keep
  9. 2.9Module Summary and Knowledge Check
Module 3Shaping Results

Module 3 of KQL for Security Analysts: deriving new values with extend, classifying rows with iff and case, cleaning text, working with time formats, choosing and naming columns, ordering and limiting, removing duplicates, and shaping a result for the person who will act on it.

Show 9 lessonsHide lessons
  1. 3.13.1 Deriving New Values: extend, Expressions and Rounding
  2. 3.23.2 Classifying Rows: iff, case and Labels
  3. 3.33.3 Cleaning and Normalizing Text
  4. 3.43.4 Working with Time Values and Formats
  5. 3.53.5 Choosing and Naming Columns: project and Its Variants
  6. 3.63.6 Ordering and Limiting Results
  7. 3.73.7 Removing Duplicates and Repeated Events
  8. 3.83.8 Shaping a Result for Its Reader
  9. 3.9Module Summary and Knowledge Check

Intermediate

Module 6String and Structured Data

Module 6 of KQL for Security Analysts: pulling fields out of free text with parse, key-value logs, regular expressions and extract, indicators and encoded commands in text, JSON and the dynamic type, property bags, and turning arrays into rows with mv-expand and mv-apply.

Show 9 lessonsHide lessons
  1. 6.16.1 Pulling Fields out of Free Text: parse
  2. 6.26.2 Text That Varies: parse-where and Key-Value Logs
  3. 6.36.3 Matching Patterns: Regular Expressions and extract
  4. 6.46.4 Indicators Buried in Text: extract_all and Decoding
  5. 6.56.5 Nested Data: JSON and the dynamic Type
  6. 6.66.6 Property Bags and Changing Schemas
  7. 6.76.7 One Row per Element: mv-expand
  8. 6.86.8 Working Inside an Array: mv-apply
  9. 6.9Module Summary and Knowledge Check

Advanced

Module 9Graph Operators

Module 9 of KQL for Security Analysts: relationships as nodes and edges, make-graph, graph-match patterns, variable-length paths with map, all, any and inner_nodes, process trees, identity paths, machine-to-machine connections, and when a join is the better tool.

Show 9 lessonsHide lessons
  1. 9.19.1 Relationships as a Graph
  2. 9.29.2 Building a Graph: make-graph
  3. 9.39.3 Finding Patterns: graph-match
  4. 9.49.4 Paths of Any Length
  5. 9.59.5 Process Trees as Graphs
  6. 9.69.6 Who Can Reach What: Identity Paths
  7. 9.79.7 Connections Between Machines
  8. 9.89.8 Graph or Join: Choosing
  9. 9.9Module Summary and Knowledge Check

Mastery

Module 10Query Optimization and Validation

Module 10 of KQL for Security Analysts: how a query runs, filtering early, the cost of string operators, joins and summaries at scale, documented limits, adapting public queries, checking answers for silent zeros and data gaps, and checking AI-written KQL.

Show 9 lessonsHide lessons
  1. 10.110.1 How a Query Runs
  2. 10.210.2 Filter First: Time, Table and Columns
  3. 10.310.3 String Operators and Their Cost
  4. 10.410.4 Joins and Summaries at Scale
  5. 10.510.5 Limits in Sentinel and Advanced Hunting
  6. 10.610.6 Reading and Adapting Public Queries
  7. 10.710.7 Checking the Answer
  8. 10.810.8 Checking AI-Written KQL
  9. 10.9Module Summary and Knowledge Check

Phase 0: Course Resources

ResourcesCheatsheets

One sheet per module of KQL for Security Analysts, each entry a question, a query that answers it against the sample month, what to read and what the answer does not prove.

Show 11 lessonsHide lessons
  1. 1Tables and the Lab
  2. 2Query Structure and Types
  3. 3Searching and Filtering
  4. 4Shaping Results
  5. 5Aggregation
  6. 6Multi-Table Queries
  7. 7String and Structured Data
  8. 8Variables, Functions and External Data
  9. 9Time Series and Window Functions
  10. 10Graph Operators
  11. 11Query Optimization and Validation
ResourcesCookbooks

Procedures for the three problems every KQL user meets: a query that returns nothing, a query that is too slow, and a log source nobody has parsed.

Show 3 lessonsHide lessons
  1. 1A Query Returns Nothing
  2. 2A Query Is Too Slow
  3. 3Parsing an Unfamiliar Log Source
ResourcesLab Setup

The course's practice lab, which needs no setup, and how to get a workspace of your own to run the course's queries and the Project against.

Show 2 lessonsHide lessons
  1. 1The Practice Lab
  2. 2Your Own Workspace
ResourcesWalkthroughs

Six investigations worked end to end with the output at every step, five of them turning on a query that ran cleanly and answered wrongly.

Show 6 lessonsHide lessons
  1. 1Building a Query From a Question
  2. 2When the Join Lies
  3. 3The Baseline That Learned the Attack
  4. 4The Query That Timed Out
  5. 5The Parse That Half Worked
  6. 6Reconstructing the Process Tree
ResourcesQuery Patterns

Five query patterns that recur across security questions: first time seen, rare in population, volume anomaly per entity, paired events in sequence, and regularity.

Show 5 lessonsHide lessons
  1. 1First Time Seen
  2. 2Rare in Population
  3. 3Volume Anomaly per Entity
  4. 4Paired Events in Sequence
  5. 5Beaconing and Regularity
ResourcesPlayground

Resources for practicing KQL and using it at work: the detection library, a free-run query console, guided investigations, response playbooks, and an open-source DFIR toolkit.

ResourcesOperational Reference

Every operator, function, check and limit from KQL for Security Analysts in one place, organized by the task in front of you and linked back to the section that explains it.

Show 1 lessonHide lessons
  1. 1Operational Reference
ResourcesReferences & Further Reading

The documentation behind KQL for Security Analysts, arranged by the question it answers: the language, where queries run and their limits, getting data, and community query material.

Project

ResourcesProject: Your Own Query Library

The KQL for Security Analysts project: a brief for a library of twenty queries you build on your own data, each answering a stated question, each checked, with its table's pitfalls and its cost noted, and one taken to the quality of a scheduled rule. No submission, no grading.

Show 1 lessonHide lessons
  1. 1The Brief

Course Completion

CompletionCourse Exam

KQL for Security Analysts end-of-course exam: twenty tasks, two per teaching module, each answered by writing KQL against the course's sample month and checked on the server.

Show 1 lessonHide lessons
  1. 1Course Completion. KQL for Security Analysts

Course overview

KQL is how security analysts ask questions of Microsoft Sentinel and Defender: who signed in from where, which process started which, what an account did after it was compromised. This course teaches the language itself, from the shape of a first query to graphs, time series and the checks that make an answer trustworthy.

It is taught against one month of records from Northgate Engineering, an 810-person company whose month holds ordinary work and several real attacks: a password spray, stolen sessions, malicious applications granted mailbox access, data taken from file shares and a ransomware infection. The course finds them with the techniques of each module, so every operator is learned on a question worth asking.

How this course works

Every query runs in the page. A practice lab built into each lesson holds the sample month in 21 tables with their real names and columns. Change a query, run it, and see what changed.

Predict, then run. Many queries ask for your prediction before they show their result, so every query is a small test of your understanding.

Three exercises in every lesson. Complete a query, fix a broken one, and write one from a blank editor, each graded on the result it returns. Each module ends with a knowledge check and a challenge set of questions the lessons did not answer.

Check every answer. The course treats an empty result, a surprising count and a borrowed or AI-written query as things to verify before anyone relies on them, and teaches the checks that do it.

What you will learn

✓ Read, filter and shape any table, and know which tables hold which answers in Sentinel and Advanced Hunting
✓ Count correctly: distinct counts, distributions, rates and the averages that mislead
✓ Combine tables with union, every kind of join and lookup, and count rows to keep joins honest
✓ Turn free text, JSON and arrays into columns with parse, regular expressions, mv-expand and mv-apply
✓ Write reusable logic with let, functions, saved parsers, watchlists and external data
✓ Analyze time with make-series, anomaly functions, window functions and running totals
✓ Follow relationships as graphs, from addresses to accounts and from a document to the processes it started
✓ Keep queries fast and answers right: filter first, respect documented limits, and check borrowed and AI-written KQL

Who this course is for

Anyone who needs to query security data in Microsoft Sentinel or Defender: SOC analysts, incident responders, detection engineers and threat hunters, and people moving into those roles. No experience with KQL or any other query language is assumed; every operator is explained where it is first used.

Readers who already write KQL will find the later modules go well past the basics, and the Course Fit Check in the free orientation shows where you sit.

What you will build

✓ A query library of your own: twenty checked queries on your own data, each with its question, period, check and cost, built in the Project
✓ One query taken to the quality of a scheduled rule, with a measured threshold and a tested known case
✓ The habits that make answers defensible: counting before trusting, stating what was checked, and saying what an answer does not prove

What this course does not cover

Detection engineering as a program, threat hunting methodology and SIEM administration each have their own course on the platform. This course teaches the language they all depend on.

Things you need to know

What are the prerequisites?

None. The course teaches KQL from first principles, and the free orientation module explains the language, how security data is stored and the tables an analyst queries before the first lesson.

What do I need to run the queries?

A device with a modern browser. Every query in the course runs in the practice lab built into the page. For the Project you query your own data, in Advanced Hunting or a Sentinel workspace you are allowed to use; the lab setup pages explain the routes.

How is the course assessed?

By a query-based exam: twenty tasks, two per teaching module, each answered by writing KQL against the sample month and checked on the server. Passing at 70 earns the KQL for Security Analysts certificate with CPE credit.

Usage rights and disclaimer

Course materials: Licensed for individual professional development. You may use the queries you write in your own environment. You may not redistribute course content or share account credentials.

Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.

COURSE ASSESSMENT

End of Course Exam

Complete the course, then write the queries: twenty tasks answered against the sample month, no time limit. Pass mark: 70. Earn your certificate with CPE credits.

20tasks
10modules
100points
Take End of Course Exam

Answers are checked on the server. Certificate issued on pass.