Listen "Querying for Breaches with Mark Morowcyznski"
Episode Synopsis
Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!LinksThreat Intelligence BlogPhishing-Resistant Passwordless AuthenticationKusto Query LanguageMicrosoft SentinelMicrosoft Security CopilotKQL Guide on GitHubRecorded December 19, 2024
More episodes of the podcast RunAs Radio
HaveIBeenPwned with Troy Hunt
01/10/2025
Managing Vendor Incidents with Mandi Walls
24/09/2025
Certificate Automation with Todd Gardner
17/09/2025
Training for AI with Stephanie Donahue
10/09/2025
Episode 1000!
03/09/2025
Common Azure Mistakes with Scott Sauber
27/08/2025
Data Governance for AI with Martina Grom
20/08/2025
The Power of the Graph with Tony Redmond
13/08/2025
From ClickOps to DevOps with Steven Bucher
30/07/2025