Jiří Činčura ↹ · @cincura_net
105 followers · 201 posts · Server mas.to

#kusto #kql #sql

Last updated 2 years ago

MISP · @misp
961 followers · 102 posts · Server misp-community.org

KQL-MISP

"This folder is a KQL MISP implementation. The goal of this folder is to share queries which implement MISP feeds which can be used for detection, threat hunting or enrichment of incidents. No additional infrastructure or sources are needed besides an environment in which you can run KQL. This implementation can be used in Sentinel, Defender For Endpoint and other Log Analytics sources that fit your needs."

🔗 github.com/Bert-JanP/Hunting-Q

#cti #kql #threatintel

Last updated 2 years ago

IAintShootinMis · @iaintshootinmis
512 followers · 371 posts · Server digitaldarkage.cc

Ok, it looks like we finally narrowed it down. The actual query was a such

let m = dynamic(["malapp1","malapp2"]);
OfficeActivity
| where Operation == "FileMalwareDetected"
and SourceFileName in (m)

This would fail every time as "m is not a known table, variable, or function"

BUT

if I switched it to

|where SourceFileName in (m) and Operation == "FileMalwareDetected"

then the query works fine. We spent hours troubleshooting this. At least it wasn't a semicolon.

#mssentinel #kql

Last updated 2 years ago

IAintShootinMis · @iaintshootinmis
512 followers · 369 posts · Server digitaldarkage.cc

I need some help from anyone using or or

In Sentinel, I'm creating the below query, but being told the variable I'm assigning isn't the name of a known function table or variable. I don't need insight on a different way to write the statement, just to understand why it won't work.

`let names = dynamic(["Admin1","Admin2"]);
AuditLogs
|where Principal in (names)`

The same query works in LogAnalytics without issue. I'm losing my mind.

#mssentinel #kql #kustoquerylanguage

Last updated 2 years ago

Dimitar Grozdanov · @grozdanovd
18 followers · 14 posts · Server masto.ai
Thomas Lee ✅ :patreon: · @DoctorDNS
814 followers · 1083 posts · Server masto.ai

The latest A Daily Dose of PowerShell! paper.li/doctordns/1580827252? Thanks to @OverSecurity@twitter.com @tdlogger@twitter.com @kfalconspb@twitter.com

#infosec #kql

Last updated 3 years ago

Geby · @geby
53 followers · 334 posts · Server ruhr.social

RT @maarten_goet@twitter.com

I am truly amazed by . Here's an example of & 👇🏻

🐦🔗: twitter.com/maarten_goet/statu

#chatgpt #microsoftsentinel #kql

Last updated 3 years ago

Kat Marchán 🐈 · @zkat
5315 followers · 9634 posts · Server toot.cat

omg it works! My engine works beautifully!

So to summarize:

a > b 👉🏻 any child "b" of node "a"
a >> b 👉🏻 any descendant "b" of node "a"
a + b 👉🏻 any "b" that immediately follows an "a" node under the same parent
a ++ b 👉🏻 any "b" anywhere after "a" under the same parent.

I've also got multiple parallel selectors working (with the `,` operator, just like CSS), and some magic around the toplevel `scope()` selector that lets you do things like `scope() > a` to make sure you're selecting only direct children of the *current* document/node you're querying from.

Whew. It's been a couple of days but this was really fun! 💯 would parse again.

Oh and it has all the nice error reporting you would expect from a tool that uses 😉

#kdl #kql #miette #rust #rustlang

Last updated 3 years ago

Kat Marchán 🐈 · @zkat
5260 followers · 9524 posts · Server toot.cat

A implementation built right into kdl-rs is Coming Soon™️ to a crates.io near you!

I spent some time actually _using_ kdl-rs this weekend on a project, and realized the whole experience would be *massively* improved if I actually had access to KQL (and extractors), so I switched gears from a $newproject and went back to this.

It's basically CSS selectors, but for !

#kql #kdl #rust #rustlang

Last updated 3 years ago

Chris Bradshaw · @chrisbradshaw
28 followers · 25 posts · Server mas.to

If you do anything in (or or elsewhere) with Query Language () and you like solving puzzles I can thoroughly recommend the Kusto Detective Agency. detective.kusto.io/
I solved the 5th case this morning, some great challenges here.

#kql #kusto #m365 #azure

Last updated 3 years ago

DIN-News · @din_news
17 followers · 7683 posts · Server social.beachcom.org

Im traut sich die Frühlingssonne wieder raus . So lässt sich Mittagspause aushalten! @montanimmo @stadt_dinslaken .twitter.com/7MqpnnJIw6 - twitter.com/Text_im_Pott/statu

#bergpark #lohberg #dinslaken #kreativquartierlohberg #kql #quartiersentwicklung #zeche #industriekulturpic

Last updated 7 years ago