Technical requirements
As I mentioned previously, we're going to get into the query language that's used across the M365 stack, which is the Kusto query language (KQL). We're going to break down a few things to help get you up to speed on it, then dive into leveraging it for advanced hunting in the M365 Defender portal, as well as inMicrosoft Sentinel. With that said, let's look at the list of technical requirements for this chapter:
- A basic understanding of KQL
- The ability to work with custom queries
- The ability to work with custom detections
- Microsoft Livestream, notebooks, and bookmarks