kql-writing

Official

Master KQL queries for Sentinel detections.

AuthorLiberty91LTD
Version1.0.0
Installs0

System Documentation

What problem does it solve?

KQL writing guidance helps security analysts craft effective queries for Microsoft Sentinel, reducing trial-and-error and enabling faster detection development across multiple data sources.

Core Features & Use Cases

  • Guidance on KQL syntax, operators, and common patterns used in security analytics.
  • Concrete examples for Windows Event logs, Azure AD Sign-ins, Defender for Endpoint, and Defender logs to build detections and dashboards.
  • Use Case: write a query to identify suspicious sign-in patterns or lateral movement indicators and export results for investigation.

Quick Start

Run a sample KQL query against your data to validate syntax and refine detection logic.

Dependency Matrix

Required Modules

None required

Components

Standard package

💻 Claude Code Installation

Recommended: Let Claude install automatically. Simply copy and paste the text below to Claude Code.

Please help me install this Skill:
Name: kql-writing
Download link: https://github.com/Liberty91LTD/cti-skills/archive/main.zip#kql-writing

Please download this .zip file, extract it, and install it in the .claude/skills/ directory.
View Source Repository

Agent Skills Search Helper

Install a tiny helper to your Agent, search and equip skill from 471,000+ vetted skills library on demand.