kql-writing
OfficialMaster KQL queries for Sentinel detections.
AuthorLiberty91LTD
Version1.0.0
Installs0
System Documentation
What problem does it solve?
KQL writing guidance helps security analysts craft effective queries for Microsoft Sentinel, reducing trial-and-error and enabling faster detection development across multiple data sources.
Core Features & Use Cases
- Guidance on KQL syntax, operators, and common patterns used in security analytics.
- Concrete examples for Windows Event logs, Azure AD Sign-ins, Defender for Endpoint, and Defender logs to build detections and dashboards.
- Use Case: write a query to identify suspicious sign-in patterns or lateral movement indicators and export results for investigation.
Quick Start
Run a sample KQL query against your data to validate syntax and refine detection logic.
Dependency Matrix
Required Modules
None requiredComponents
Standard package💻 Claude Code Installation
Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.
Please help me install this Skill: Name: kql-writing Download link: https://github.com/Liberty91LTD/cti-skills/archive/main.zip#kql-writing Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
Agent Skills Search Helper
Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.