KQL for Security Analysts
Learn KQL from your first query to mastery
The query language of Microsoft Sentinel and Defender Advanced Hunting, taught a rung at a time against a month of records from a company under attack. Every query runs in the page, every answer is checked, and nothing assumes you have written KQL before.
What you'll be able to do
Course Syllabus
Every module and every lesson. The first three modules are open; the rest open on a click.
Download the full syllabus (PDF)
Orientation
KQL for Security Analysts: the query language of Microsoft Sentinel and Defender, taught against one month of an engineering company's records with several real attacks in them. What KQL is, how security data is stored, the tables analysts query, the two places queries run, a first query, the practice lab, how the course climbs from basics to mastery, and a six-scenario check of whether it fits you.
Show 8 lessonsHide lessons
- 0.10.1 What KQL Is and Where It RunsPreview
- 0.20.2 How Security Data Is StoredPreview
- 0.30.3 The Tables a Security Analyst QueriesPreview
- 0.40.4 Sentinel Logs and Defender Advanced Hunting ComparedPreview
- 0.50.5 Your First QueryPreview
- 0.60.6 The Practice Lab and the Sample MonthPreview
- 0.70.7 How to Learn KQL: the Mastery LadderPreview
- 0.80.8 What This Course BuildsPreview
Foundation
Module 1 of KQL for Security Analysts: how a KQL query is built from statements and a pipe of tables, how to explore a table and choose its columns, the ten scalar types, conversion, null and empty values, and a six-pass method for reading a query someone else wrote.
Show 9 lessonsHide lessons
- 1.11.1 Turning a Question into KQL
- 1.21.2 Statements and Tabular Expressions
- 1.31.3 The Pipe and Operator Order
- 1.41.4 Learning a Table You Have Never Seen
- 1.51.5 What a Value Really Is: Types and Conversion
- 1.61.6 Incomplete Data: Nulls, Empties and Gaps in Coverage
- 1.71.7 Checking a KQL Result Against Its Table
- 1.81.8 Reading a Query You Did Not Write
- 1.9Module Summary and Knowledge Check
Module 2 of KQL for Security Analysts: finding where a value lives with search and find, narrowing a table with where, matching text the way the engine indexes it, working in time windows and around an event, and filtering addresses, nested fields and negations without losing rows.
Show 9 lessonsHide lessons
- 2.12.1 Searching for a Value When You Do Not Know the Column
- 2.22.2 Narrowing a Table to the Events That Matter
- 2.32.3 Matching Text the Way the Engine Indexes It
- 2.42.4 Working Inside a Time Window
- 2.52.5 Pivoting on a Timestamp: Windows Around an Event
- 2.62.6 Filtering Addresses and Ranges
- 2.72.7 Filtering Inside Nested Fields
- 2.82.8 Negative Filters: !in, !has, not() and What They Silently Keep
- 2.9Module Summary and Knowledge Check
Module 3 of KQL for Security Analysts: deriving new values with extend, classifying rows with iff and case, cleaning text, working with time formats, choosing and naming columns, ordering and limiting, removing duplicates, and shaping a result for the person who will act on it.
Show 9 lessonsHide lessons
- 3.13.1 Deriving New Values: extend, Expressions and Rounding
- 3.23.2 Classifying Rows: iff, case and Labels
- 3.33.3 Cleaning and Normalizing Text
- 3.43.4 Working with Time Values and Formats
- 3.53.5 Choosing and Naming Columns: project and Its Variants
- 3.63.6 Ordering and Limiting Results
- 3.73.7 Removing Duplicates and Repeated Events
- 3.83.8 Shaping a Result for Its Reader
- 3.9Module Summary and Knowledge Check
Intermediate
Module 4 of KQL for Security Analysts: how summarize builds a result, counting and distinct counting, describing distributions with medians and percentiles, conditional aggregates, lists and sets, binning activity over time, rates and denominators, and drawing aggregates as charts with render.
Show 9 lessonsHide lessons
- 4.14.1 From Rows to Groups: How summarize Builds a Result
- 4.24.2 Counting Correctly: count, dcount and When an Estimate Matters
- 4.34.3 Describing a Distribution: Typical, Unusual and Spread
- 4.44.4 Several Questions in One Pass: Conditional Aggregates
- 4.54.5 Collecting Evidence Inside a Group: Lists, Sets and Bags
- 4.64.6 Activity Over Time: Bins, Rates per Period and the Busiest Window
- 4.74.7 Rates Done Right: Denominators and Averages of Averages
- 4.84.8 Showing an Aggregate: render and When a Chart Beats a Table
- 4.9Module Summary and Knowledge Check
Module 5 of KQL for Security Analysts: stacking tables with union, matching rows with join, the default innerunique join, outer, anti and semi joins, lookup and reference tables, joining events across time, and checking that a join returned the right answer.
Show 9 lessonsHide lessons
- 5.15.1 Putting Sources Side by Side: union
- 5.25.2 Matching Rows Across Tables: How join Works
- 5.35.3 The Default Join Drops Rows: innerunique against inner
- 5.45.4 Keeping Rows That Have No Match: Outer Joins
- 5.55.5 What One Table Has That Another Lacks: Anti and Semi Joins
- 5.65.6 Adding Context to Rows: lookup and Reference Tables
- 5.75.7 Joining Across Time: Events Near Each Other
- 5.85.8 Joins That Return the Wrong Answer
- 5.9Module Summary and Knowledge Check
Module 6 of KQL for Security Analysts: pulling fields out of free text with parse, key-value logs, regular expressions and extract, indicators and encoded commands in text, JSON and the dynamic type, property bags, and turning arrays into rows with mv-expand and mv-apply.
Show 9 lessonsHide lessons
- 6.16.1 Pulling Fields out of Free Text: parse
- 6.26.2 Text That Varies: parse-where and Key-Value Logs
- 6.36.3 Matching Patterns: Regular Expressions and extract
- 6.46.4 Indicators Buried in Text: extract_all and Decoding
- 6.56.5 Nested Data: JSON and the dynamic Type
- 6.66.6 Property Bags and Changing Schemas
- 6.76.7 One Row per Element: mv-expand
- 6.86.8 Working Inside an Array: mv-apply
- 6.9Module Summary and Knowledge Check
Advanced
Module 7 of KQL for Security Analysts: naming values and intermediate results with let, materialize, writing functions, parsers as functions, watchlists, externaldata, matching indicators in every format, and IP address functions and ranges.
Show 9 lessonsHide lessons
- 7.17.1 Naming Values and Thresholds: let for Scalars
- 7.27.2 Naming Intermediate Results: let for Tables
- 7.37.3 Writing Your Own Functions
- 7.47.4 Parsers as Functions: Saved and Shared
- 7.57.5 Lists Kept Outside the Query: Watchlists
- 7.67.6 Data from Outside the Workspace: externaldata
- 7.77.7 Indicators in Every Format
- 7.87.8 Address Functions and Ranges
- 7.9Module Summary and Knowledge Check
Module 8 of KQL for Security Analysts: make-series and the zeros it keeps, series arithmetic and statistics, reading series function output, comparing periods, series per entity, row order with serialize, prev and next for sessions, and running totals.
Show 9 lessonsHide lessons
- 8.18.1 Counts Over Time That Include the Zeros: make-series
- 8.28.2 Working on Whole Series: Arithmetic, Gaps and Statistics
- 8.38.3 Reading What a Series Function Returns
- 8.48.4 This Week Against Last: Comparing Periods
- 8.58.5 One Series per Entity
- 8.68.6 Order in a Table: serialize and Row Numbers
- 8.78.7 The Row Before and After: prev, next and Sessions
- 8.88.8 Running Totals and Cumulative Counts
- 8.9Module Summary and Knowledge Check
Module 9 of KQL for Security Analysts: relationships as nodes and edges, make-graph, graph-match patterns, variable-length paths with map, all, any and inner_nodes, process trees, identity paths, machine-to-machine connections, and when a join is the better tool.
Show 9 lessonsHide lessons
- 9.19.1 Relationships as a Graph
- 9.29.2 Building a Graph: make-graph
- 9.39.3 Finding Patterns: graph-match
- 9.49.4 Paths of Any Length
- 9.59.5 Process Trees as Graphs
- 9.69.6 Who Can Reach What: Identity Paths
- 9.79.7 Connections Between Machines
- 9.89.8 Graph or Join: Choosing
- 9.9Module Summary and Knowledge Check
Mastery
Module 10 of KQL for Security Analysts: how a query runs, filtering early, the cost of string operators, joins and summaries at scale, documented limits, adapting public queries, checking answers for silent zeros and data gaps, and checking AI-written KQL.
Show 9 lessonsHide lessons
- 10.110.1 How a Query Runs
- 10.210.2 Filter First: Time, Table and Columns
- 10.310.3 String Operators and Their Cost
- 10.410.4 Joins and Summaries at Scale
- 10.510.5 Limits in Sentinel and Advanced Hunting
- 10.610.6 Reading and Adapting Public Queries
- 10.710.7 Checking the Answer
- 10.810.8 Checking AI-Written KQL
- 10.9Module Summary and Knowledge Check
Phase 0: Course Resources
One sheet per module of KQL for Security Analysts, each entry a question, a query that answers it against the sample month, what to read and what the answer does not prove.
Show 11 lessonsHide lessons
Procedures for the three problems every KQL user meets: a query that returns nothing, a query that is too slow, and a log source nobody has parsed.
Show 3 lessonsHide lessons
The course's practice lab, which needs no setup, and how to get a workspace of your own to run the course's queries and the Project against.
Show 2 lessonsHide lessons
Six investigations worked end to end with the output at every step, five of them turning on a query that ran cleanly and answered wrongly.
Five query patterns that recur across security questions: first time seen, rare in population, volume anomaly per entity, paired events in sequence, and regularity.
Show 5 lessonsHide lessons
Resources for practicing KQL and using it at work: the detection library, a free-run query console, guided investigations, response playbooks, and an open-source DFIR toolkit.
Every operator, function, check and limit from KQL for Security Analysts in one place, organized by the task in front of you and linked back to the section that explains it.
Show 1 lessonHide lessons
The documentation behind KQL for Security Analysts, arranged by the question it answers: the language, where queries run and their limits, getting data, and community query material.
Project
The KQL for Security Analysts project: a brief for a library of twenty queries you build on your own data, each answering a stated question, each checked, with its table's pitfalls and its cost noted, and one taken to the quality of a scheduled rule. No submission, no grading.
Show 1 lessonHide lessons
Course Completion
KQL for Security Analysts end-of-course exam: twenty tasks, two per teaching module, each answered by writing KQL against the course's sample month and checked on the server.
Show 1 lessonHide lessons
Course overview
KQL is how security analysts ask questions of Microsoft Sentinel and Defender: who signed in from where, which process started which, what an account did after it was compromised. This course teaches the language itself, from the shape of a first query to graphs, time series and the checks that make an answer trustworthy.
It is taught against one month of records from Northgate Engineering, an 810-person company whose month holds ordinary work and several real attacks: a password spray, stolen sessions, malicious applications granted mailbox access, data taken from file shares and a ransomware infection. The course finds them with the techniques of each module, so every operator is learned on a question worth asking.
How this course works
Every query runs in the page. A practice lab built into each lesson holds the sample month in 21 tables with their real names and columns. Change a query, run it, and see what changed.
Predict, then run. Many queries ask for your prediction before they show their result, so every query is a small test of your understanding.
Three exercises in every lesson. Complete a query, fix a broken one, and write one from a blank editor, each graded on the result it returns. Each module ends with a knowledge check and a challenge set of questions the lessons did not answer.
Check every answer. The course treats an empty result, a surprising count and a borrowed or AI-written query as things to verify before anyone relies on them, and teaches the checks that do it.
What you will learn
Who this course is for
Anyone who needs to query security data in Microsoft Sentinel or Defender: SOC analysts, incident responders, detection engineers and threat hunters, and people moving into those roles. No experience with KQL or any other query language is assumed; every operator is explained where it is first used.
Readers who already write KQL will find the later modules go well past the basics, and the Course Fit Check in the free orientation shows where you sit.
What you will build
What this course does not cover
Detection engineering as a program, threat hunting methodology and SIEM administration each have their own course on the platform. This course teaches the language they all depend on.
Things you need to know
What are the prerequisites?
None. The course teaches KQL from first principles, and the free orientation module explains the language, how security data is stored and the tables an analyst queries before the first lesson.
What do I need to run the queries?
A device with a modern browser. Every query in the course runs in the practice lab built into the page. For the Project you query your own data, in Advanced Hunting or a Sentinel workspace you are allowed to use; the lab setup pages explain the routes.
How is the course assessed?
By a query-based exam: twenty tasks, two per teaching module, each answered by writing KQL against the sample month and checked on the server. Passing at 70 earns the KQL for Security Analysts certificate with CPE credit.
Usage rights and disclaimer
Course materials: Licensed for individual professional development. You may use the queries you write in your own environment. You may not redistribute course content or share account credentials.
Fictional environment: All scenarios use Northgate Engineering. Any resemblance to real organizations is coincidental.
End of Course Exam
Complete the course, then write the queries: twenty tasks answered against the sample month, no time limit. Pass mark: 70. Earn your certificate with CPE credits.
Answers are checked on the server. Certificate issued on pass.