Further reading
There is a lot more to learn about general Microsoft Sentinel usage than we can cram into this book. Check out the following links for useful resources:
- Rod Trent of Microsoft has championed KQL more than anyone. You can find his Must Learn KQL repository on GitHub, including purchase options for a hard copy book of the same name, to help you master KQL: github.com/rod-trent/MustLearnKQL.
- Another must-visit GitHub repository is Matt Zorich’s, which is home to a massive list of his custom queries and the #365daysofKQL series: github.com/reprise99/Sentinel-Queries.
- Want to join a community and learn, share, or practice the Sentinel query language? The KQL Café, run by Gianni Castaldi and Alex Verboon, hosts regular meetups to cover all things Kusto: kqlcafe.github.io/website.
- For the most comprehensive book on Microsoft Sentinel you’ll find, check out Microsoft Sentinel in Action – Second Edition, from Packt Publishing: packtpub...