Agent Foskett KQL Academy.
Learn Kusto Query Language as a practical Microsoft security investigation skill.
Across 170 published lessons, the Academy progresses from KQL foundations into Microsoft Defender XDR telemetry, email and phishing investigations, attack scenarios, incident response, identity threat hunting, endpoint investigation, cloud and SaaS compromise, proactive hunting and detection engineering.
The goal is not simply to write queries. It is to ask better security questions, follow the evidence and turn telemetry into defensible investigation conclusions.
KQL Academy overview
From your first query to complete investigation timelines, proactive hunts and production-ready detection engineering.
KQL Academy roadmap
Learn what KQL is, write your first query, explore security tables, filter, project, sort, summarise, bin, distinct and top.
Move from single queries into EmailEvents, UrlClickEvents, joins, investigation timelines, let statements and reusable parameters.
Build stronger searches with in, has_any, contains_cs, startswith, regex, parse_json, extract, mv-expand, mv-apply, extend, case and iff.
Explore endpoint, identity, alert, incident, behaviour, device and cloud telemetry inside Microsoft Defender XDR.
Investigate NetworkMessageId, authentication details, senders, delivery outcomes, threats, recipients and message identifiers.
Trace phishing from email delivery through Safe Links clicks, URL chains, endpoint processes and network activity.
Apply KQL to lateral movement, PowerShell, ransomware, LOLBins, credential theft, persistence, IOC hunts and BEC.
Use advanced joins, reusable hunting logic, performance tuning, arg_max, make_set, mv-expand, mv-apply and regex.
Hunt impossible travel, credential theft, OAuth abuse, risky sign-ins, PowerShell, LOLBins, insider threats and ransomware.
Bring KQL into phishing, BEC, compromised-account, malware, ransomware, exfiltration and OAuth response workflows.
Master joins, dynamic data, performance, reusable functions, time series analysis and enterprise hunting workbooks.
Investigate successful sign-ins, MFA fatigue, new MFA methods, Conditional Access, privilege, sessions and complete identity timelines.
Follow suspicious process chains through PowerShell, files, network connections, persistence, credential access and lateral movement.
Investigate cloud compromise, then move into proactive hunting, baselines, detection tuning, backtesting and reusable hunts.
Original KQL programme — Lessons 1–130
Start with what KQL is, your first query, security tables, filtering, useful columns, sorting, summarize, bin(), distinct and top.
Move from single queries into EmailEvents, UrlClickEvents, joins, investigation timelines, let statements and reusable parameters.
Learn multi-indicator searches, string matching, regex, dynamic JSON, mv-expand, mv-apply, extend, case(), iff() and data normalisation.
Explore endpoint, identity, alert, incident, behaviour, device and cloud telemetry inside Microsoft Defender XDR.
Investigate NetworkMessageId, AuthenticationDetails, sender fields, delivery outcomes, ThreatTypes, BCL, recipients and message identifiers.
Trace phishing activity from email delivery through Safe Links clicks, URL chains, endpoint process activity and network telemetry.
Apply KQL to lateral movement, PowerShell attacks, ransomware behaviour, LOLBins, credential theft, persistence, IOC hunts and BEC.
Build stronger hunts with advanced joins, reusable logic, dynamic data, performance tuning, arg_max(), make_set(), mv-expand, mv-apply and regex.
Use KQL to hunt impossible travel, credential theft, OAuth abuse, risky sign-ins, PowerShell, LOLBins, persistence, insider threats and ransomware.
Bring KQL into response workflows for phishing, BEC, compromised accounts, malware, ransomware, insider threat, exfiltration and OAuth compromise.
Master joins, dynamic data, mv-expand, query performance, reusable functions, parse_json(), regex, time series analysis and enterprise hunts.
Bring the original programme together into a structured enterprise hunting workbook for Microsoft Defender XDR investigations.
Phase Two — Real-World Threat Hunting
Begin Identity Threat Hunting by investigating a successful Microsoft Entra sign-in that does not fit the user's normal pattern. Use SigninLogs, baselines, IP, location, device and authentication context to decide what the evidence actually supports.
Use KQL to identify repeated authentication pressure, suspicious sign-in sequences, authentication detail patterns and the important failure-to-success sequence that may indicate account compromise.
Hunt identity changes that may establish persistence by investigating newly registered authentication methods, the surrounding sign-in activity and whether the change fits the user's normal behaviour.
Use KQL to investigate Conditional Access outcomes in context and determine what the result does — and does not — prove about a suspicious sign-in.
Use KQL to investigate privileged role activation, correlate the event with surrounding sign-in activity and determine whether the elevation fits legitimate administrative behaviour.
Use KQL to pivot from a single source IP across multiple identities, identify coordinated authentication activity and determine whether the pattern points to password spraying, credential testing or another shared source.
Use KQL to investigate what happened after a successful sign-in and determine whether the session behaviour, applications, resources and surrounding identity activity still fit the legitimate user.
Use KQL to follow one identity across multiple Microsoft security data sources, correlate related events and build a single investigation story from sign-in, cloud, endpoint and identity telemetry.
Use KQL to reconstruct an identity compromise chronologically, correlate authentication and post-authentication evidence, and turn separate security events into a defensible investigation timeline.
Complete an end-to-end identity threat hunting investigation with KQL, following evidence from suspicious authentication through source-IP pivots, privilege, persistence and post-authentication cloud activity to a defensible conclusion.
Use KQL to investigate a suspicious browser-to-PowerShell process chain, inspect command-line activity and correlate process, user, device and network evidence to determine whether the behaviour represents the beginning of an endpoint compromise.
Use KQL to identify encoded PowerShell execution, preserve the original command-line evidence, decode the captured content safely for analysis and correlate the resulting behaviour with surrounding process and network telemetry.
Use KQL to reconstruct suspicious process trees, follow parent-child execution relationships and determine whether the process chain fits normal user behaviour or represents a deeper endpoint attack sequence.
Use KQL to correlate file creation with process execution, identify the process that created the file, preserve its hash and determine whether the same file appears elsewhere across the environment.
Use KQL to correlate suspicious process execution with outbound network activity, preserve the remote IP, port and URL evidence, and determine whether the same destination appears elsewhere across the environment.
Use KQL to investigate scheduled-task persistence, correlate task creation with the suspicious process chain and determine whether the task was created to maintain access on the endpoint.
Use KQL to investigate registry-based persistence, identify newly created Run and RunOnce values, correlate the registry change with the suspicious process chain and determine whether the same persistence pattern appears elsewhere across the environment.
Use KQL to investigate suspicious LSASS-related activity, correlate Defender alert evidence with endpoint process telemetry and determine whether the behaviour supports a credential-access hypothesis without overstating what the evidence proves.
Use KQL to follow an account across endpoints, investigate the destination device, analyse logon type and source context, and determine whether authentication minutes after suspected credential access supports a lateral-movement hypothesis.
Use KQL to correlate process, file, network, persistence, credential-access and authentication evidence across Microsoft Defender XDR, reconstruct the complete attack chain and turn the findings into a defensible endpoint compromise timeline.
Use KQL to investigate unusually large SharePoint and OneDrive downloads, establish the user's normal behaviour, examine the source and timing of the activity, and determine whether the evidence supports escalation as possible pre-departure data collection.
Use KQL to correlate SharePoint activity with Microsoft Entra sign-in evidence, compare IP addresses, locations, applications and device context, and determine whether geographically separated access supports a possible session or account compromise.
Use KQL to investigate a sudden high-volume SharePoint and OneDrive download burst, measure download velocity, compare the activity with the user's historical baseline, and determine whether the behaviour fits legitimate synchronisation, automation or suspicious data collection.
Use KQL to investigate Microsoft Entra OAuth application consent, identify the initiating user, application and permission evidence, correlate the grant with surrounding sign-in activity, and determine whether the consent may represent cloud persistence.
Use KQL to investigate non-interactive application access after OAuth consent, correlate service principal sign-ins with Microsoft 365 activity, identify the resources the application reached, and determine whether the granted permissions were exercised without a new interactive user sign-in.
Use KQL to investigate Exchange Online inbox-rule creation after suspicious authentication, inspect forwarding, redirect, deletion and concealment actions, compare the rule with mailbox history, and determine whether the change supports persistence or attacker control of the mailbox.
Use KQL to investigate Exchange Online forwarding activity, identify external recipients, correlate actual message delivery with the suspicious inbox rule, compare the behaviour with the mailbox baseline, and determine whether organisational mail was redirected outside the tenant.
Use KQL to investigate SharePoint and OneDrive external sharing, identify the shared file and recipient, compare the activity with the user's historical sharing behaviour, and determine whether sensitive organisational data was exposed outside the tenant.
Use KQL to follow one identity across Microsoft Entra, Exchange Online and SharePoint, correlate sign-in, mailbox and file activity, and build a single cross-workload timeline that turns separate cloud events into one investigation story.
Use KQL to reconstruct a complete cloud compromise across Microsoft Entra, Exchange Online, SharePoint and OneDrive, correlate identity, mailbox and data evidence, separate confirmed observations from investigative hypotheses, and produce a defensible final incident timeline.
Use KQL to begin a proactive threat hunt with suspicious behaviour rather than a known indicator, establish normal PowerShell activity, identify unusual process relationships, and combine behavioural signals into high-value investigation candidates.
Use KQL to scope a behavioural hunting result across multiple endpoints, compare devices, users, command lines and process ancestry, and determine whether repeated activity represents legitimate enterprise tooling or evidence of a wider attack.
Use KQL to turn a successful threat-hunting query into repeatable detection logic, add supporting behavioural signals, measure expected alert volume, tune validated legitimate activity and preserve the context analysts need for effective triage.
Use KQL to investigate a noisy behavioural detection, identify the users, devices, processes and commands generating repeated false positives, preserve suspicious outliers, and tune validated benign activity without removing the behaviour the detection was designed to find.
Use KQL to establish historical behavioural baselines, measure normal activity across users and devices, compare current behaviour with expected ranges, and choose defensible detection thresholds based on evidence rather than arbitrary numbers.
Use KQL to compare historical and recent behavioural baselines, identify users and devices whose normal activity has changed, investigate the evidence behind the drift, and determine whether the new pattern represents legitimate environmental change or suspicious activity that should be escalated.
Use KQL to combine individually weak behavioural signals, correlate process, command-line and network evidence around the same device, process and time window, and turn the combined activity into a higher-confidence, explainable detection candidate.
Use KQL to backtest detection logic against historical telemetry, measure result volume and prevalence, identify recurring false-positive patterns, validate known suspicious activity, and tune the detection before promoting it into production.
Use KQL to measure operational detection volume, identify repeated and duplicate activity, group related events into investigation-ready candidates, prioritise stronger behavioural combinations, and tune a working detection so analysts can realistically investigate it.
Turn successful KQL threat-hunting logic into a documented, parameterised and repeatable hunt by exposing tunable values, preserving investigation context, standardising output, and making the reasoning understandable for other analysts.
Explore other Agent Foskett academies
Final thought
Agent Foskett KQL Academy
Agent Foskett KQL Academy is a 170-lesson Microsoft security learning path for Kusto Query Language, Microsoft Defender XDR, Microsoft Sentinel, identity threat hunting, endpoint investigation, cloud and SaaS investigation, incident response and detection engineering.
Learn KQL for Microsoft Defender XDR
Learn practical KQL for EmailEvents, UrlClickEvents, DeviceProcessEvents, DeviceNetworkEvents, IdentityLogonEvents, AlertInfo, AlertEvidence, CloudAppEvents and enterprise hunting workflows.
KQL threat hunting and detection engineering
The 170-lesson learning path progresses from beginner KQL through real-world investigation workflows, identity, endpoint and cloud threat hunting, behavioural baselines, backtesting and reusable security detections.
