In this course, you’ll master identity threat hunting with Microsoft’s security stack. Learn how to build complex Kusto Query Language (KQL) queries to detect threats and anomalies across your environment, set up real-time alerts, and automate investigations to crush response times. We’ll show you how Sentinel and Defender XDR team up for full visibility into identity-based attacks, privilege abuse, and shady sign-ins. By the end, you’ll be running automated hunts and slashing response times like a pro.

Identity Threat Hunting: A Modern KQL Approach

Learn how to leverage Kusto Query Language (KQL) in Microsoft Sentinel and Microsoft Defender to build a proactive identity security strategy. Detect anomalies in sign-in patterns, uncover privilege abuse, and investigate suspicious activity using advanced KQL queries.

Retake this course?
Retaking this course from the beginning will reset all of your tracked progress.
Retake