Skip to content
This repository was archived by the owner on Nov 16, 2023. It is now read-only.

Commit b3439dd

Browse files
authored
Update README.md
1 parent 27cdfa8 commit b3439dd

File tree

1 file changed

+7
-8
lines changed

1 file changed

+7
-8
lines changed
Lines changed: 7 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -1,24 +1,23 @@
1-
---
2-
page_type: sample
3-
languages:
4-
- kusto
5-
products:
6-
- MTP
7-
description: "Tracking the Adversary with Microsoft Threat Protection Advanced Hunting"
8-
---
91
#Tracking The Adversary
102
**[Webcast Link](https://techcommunity.microsoft.com/t5/microsoft-threat-protection/webinar-series-unleash-the-hunter-in-you/ba-p/1509232)**
113
This webcast is designed to take you from newbie to ninja on advanced hunting in four episodes. This repo contains the query files used in each of the webcasts so that you can hunt in your own MTP instance.
124

135
---
6+
147
#Episode 1: KQL Fundamentals
158
In the first episode, we will cover the basics of advanced hunting capabilities in Microsoft Threat Protection (MTP). Learn about available advanced hunting data and basic KQL syntax and operators. The best part? No slides!
9+
1610
---
11+
1712
#Episode 2: Joins
1813
In episode 2, we will continue learning about data in advanced hunting and how to join tables together. Learn about inner, outer, unique, and semi joins, as well as the nuances of the default Kusto innerunique join. Make Edgar F. Codd proud!
14+
1915
---
16+
2017
#Episode 3: Summarizing, pivoting, and visualizing Data
2118
Now that we’re able to filter, manipulate, and join data, it’s time to start summarizing, quantifying, pivoting, and visualizing. In this episode, we will cover the summarize operator and some of the various calculations you can perform while diving into additional tables within MTP. We will turn our datasets into charts that can help improve analysis.
19+
2220
---
21+
2322
#Episode 4: Let’s hunt! Applying KQL to incident tracking
2423
Time to track some attacker activity! In this episode, we will use our improved understanding of KQL and advanced hunting in Microsoft Threat Protection to track an attack. Learn some of the tips and tricks used in the field to track attacker activity, including the ABCs of cybersecurity and how to apply them to incident response.

0 commit comments

Comments
 (0)