Skip to content

Latest commit

 

History

84 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

KQL_KC7

Hands-on KQL (Kusto Query Language) practice queries and walkthrough notes from KC7 Cyber investigation scenarios. 🔍

This repository focuses on practical querying—working through real-world investigation scenarios, writing KQL queries, and using the results to drive investigations forward. 📊


📊 Repository Stats

Metric Count
📁 Scenarios 11
📄 Sections Completed 31
🔍 KQL Queries 150+
📚 Documentation Markdown
🚀 Status 🟢 Active Development

🚧 Project Status

This repository is a work in progress and is updated regularly with new KC7 scenario sections, notes, and KQL queries.


📁 Repository Structure

1️⃣ AzureCrest - The full version

  • Section 1 - KQL 101.md
  • Section 2 - Quarantine Quandary.md
  • Section 3 - The Phisher's Net.md
  • Section 4 - Derpy Database.md
  • Section 5 - Bonus - Mo' Money Mo' Problems.md

2️⃣ Castle & Sand - A Beachy Case of Ransomware

  • Section 1 - KQL 101 🧰.md
  • Section 2 - Shark Attack! 🦈.md
  • Section 3 - Hunting the Shark 🔍.md
  • Section 4 - Sand in my 👁️ 👁️.md
  • Section 5 - A Clean Sweep 🧹.md
  • Section 6 - Security Jeopardy REDUX 🕺.md

3️⃣ Cowboy Couture - A Steampunk Space Adventure

  • Section 1 - What's a Query 🤔.md
  • Section 2 - All about the dataz 👩‍💻.md
  • Section 3 - Cyber Cattle Thief 🐄.md
  • Section 4 - Cowhands-on-Keyboard 🤠.md

4️⃣ Critical Compromise In Chicago - ICS

  • Section 1 - SCADA NADA.md
  • Section 2 - Phish and Chips.md

5️⃣ Dai Wok Foods - A Challenging Culinary Mystery

  • Section 1 - KQL 101 🍚.md
  • Section 2 - Tummy Trouble, make it Double 🤢.md

6️⃣ Empire Health

  • Section 1 - Empire Health Introduction.md
  • Section 2 - More Intel.md

7️⃣ French Socksess Story

  • Section 1 - Sock Savior.md

8️⃣ Krusty Krab - A Intro to Pivoting and Analysis

  • Section 1 - KQL 101 🥚.md
  • Section 2 - Just Keep Swimming 🐟.md
  • Section 3 - Hash Slinging Slasher 🪦.md
  • Section 4 - Swimming with Jellyfishes 🏊‍♀️.md
  • Section 5 - Y'all Too Good.md

9️⃣ Scholomance - Secrets and Lateral Movement

  • Section 0 - KQL 101! 🧙.md
  • Section 1 - They call me CRIMSON 🐁.md
  • Section 2 - 🌲 Forest Blizzard ❄️.md

🔟 Sunlands - A Tough Space Investigation

  • SUPERMASSIVE BLACKHOLE 🪐.md
  • YEETED INTO SPACE 😱👾.md

1️⃣1️⃣ World Domination Nation

  • Section 3 - GETTING SMARTER 🧠.md

🎯 Purpose

This repository is intended to:

  • Practice Kusto Query Language (KQL) through realistic security investigations.
  • Learn investigation methodologies used by SOC analysts.
  • Improve KQL query writing through hands-on exercises.
  • Maintain organized documentation for future reference.
  • Track progress across KC7 Cyber scenarios.

🛠️ How to Use

  1. Open a scenario folder.
  2. Start from the first available section.
  3. Read the investigation context.
  4. Execute the provided KQL queries in KC7/Kusto.
  5. Modify the queries and observe the results.
  6. Continue to the next section.

📝 Notes

  • All documentation is written in Markdown.
  • Scenario names and section titles are preserved exactly as provided by KC7.
  • Queries include explanations, investigation steps, and observations where applicable.
  • This repository is continuously expanded as more KC7 investigations are completed.

⭐ If you found this repository useful

Consider giving it a ⭐ to support the project and help others discover practical KQL learning resources.


Happy Hunting! 🔎

About

Scenario-driven hands-on KQL practice and investigation query notes actively updated. Current Rank 180 out of 150K people globally

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors