RunAs Radio

Querying for Breaches with Mark Morowcyznski


Listen Later

Do you Kusto? Richard talks to Mark Morowczynski about his new book, The Definitive Guide to KQL, and the power of Kusto to look across your Azure tenant and understand operational and security issues. Mark talks about being able to query across all log sets, telemetry, the M365 graph, and more - to help understand issues. The book provides example queries you could run today, including knowing the first and last time a user logged on and what devices they used. There are examples of calculating baseline behavior for an account so that you can see when unusual activity starts. There are a ton of excellent queries for operational excellence and cybersecurity - get started today! And for RunAs listeners, you can use code KUSTO to get 30% off the book!

Links

  • Threat Intelligence Blog
  • Phishing-Resistant Passwordless Authentication
  • Kusto Query Language
  • Microsoft Sentinel
  • Microsoft Security Copilot
  • KQL Guide on GitHub

Recorded December 19, 2024

...more
View all episodesView all episodes
Download on the App Store

RunAs RadioBy Richard Campbell

  • 4.6
  • 4.6
  • 4.6
  • 4.6
  • 4.6

4.6

80 ratings


More shows like RunAs Radio

View all
This Week in Tech (Audio) by TWiT

This Week in Tech (Audio)

3,010 Listeners

Security Now (Audio) by TWiT

Security Now (Audio)

1,982 Listeners

Hanselminutes with Scott Hanselman by Scott Hanselman

Hanselminutes with Scott Hanselman

377 Listeners

Software Engineering Radio - the podcast for professional software developers by se-radio@computer.org

Software Engineering Radio - the podcast for professional software developers

272 Listeners

.NET Rocks! by Carl Franklin and Richard Campbell

.NET Rocks!

37 Listeners

.NET Rocks! by Carl Franklin and Richard Campbell

.NET Rocks!

243 Listeners

MacBreak Weekly (Audio) by TWiT

MacBreak Weekly (Audio)

2,012 Listeners

Windows Weekly (Audio) by TWiT

Windows Weekly (Audio)

868 Listeners

Risky Business by Patrick Gray

Risky Business

364 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

639 Listeners

Intelligent Machines (Audio) by TWiT

Intelligent Machines (Audio)

733 Listeners

The Changelog: Software Development, Open Source by Changelog Media

The Changelog: Software Development, Open Source

284 Listeners

Tech News Weekly (Audio) by TWiT

Tech News Weekly (Audio)

1,073 Listeners

The Cloudcast by Massive Studios

The Cloudcast

154 Listeners

The Stack Overflow Podcast by The Stack Overflow Podcast

The Stack Overflow Podcast

63 Listeners

2.5 Admins by The Late Night Linux Family

2.5 Admins

91 Listeners