Querying for Breaches with Mark Morowcyznski episode artwork

EPISODE · Jan 29, 2025 · 34 MIN

Querying for Breaches with Mark Morowcyznski

from RunAs Radio · host Mark Morowczynski, Richard Campbell

Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!LinksThreat Intelligence BlogPhishing-Resistant Passwordless AuthenticationKusto Query LanguageMicrosoft SentinelMicrosoft Security CopilotKQL Guide on GitHubRecorded December 19, 2024

NOW PLAYING

Querying for Breaches with Mark Morowcyznski

0:00 34:07

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

Frequently Asked Questions

How long is this episode of RunAs Radio?

This episode is 34 minutes long.

When was this RunAs Radio episode published?

This episode was published on January 29, 2025.

What is this episode about?

Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all...

Can I download this RunAs Radio episode?

Yes, you can download this episode by clicking the download button on the episode player, or subscribe to the podcast in your preferred podcast app for automatic downloads.
URL copied to clipboard!