Further reading
You may refer to the following links to expand your knowledge on the topics explored in this chapter:
- Must Learn KQL by Rod Trent: https://github.com/rod-trent/MustLearnKQL
- Shuffle hints: https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/shufflequery
- Join hints: https://learn.microsoft.com/en-us/azure/data-explorer/kusto/query/joinoperator?pivots=azuredataexplorer#join-hints
- Optimizing KQL queries: https://www.youtube.com/watch?v=ceYvRuPp5D8
- Advanced hunting query best practices: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-best-practices?view=o365-worldwide
- https://cloudbrothers.info/en/alert-sensitive-ad-groups-mdi/
- https://cloudbrothers.info/en/automated-response-c2-traffic-devices/