Hands-on KQL (Kusto Query Language) practice queries and walkthrough notes from KC7 Cyber investigation scenarios. 🔍
This repository focuses on practical querying—working through real-world investigation scenarios, writing KQL queries, and using the results to drive investigations forward. 📊
| Metric | Count |
|---|---|
| 📁 Scenarios | 11 |
| 📄 Sections Completed | 31 |
| 🔍 KQL Queries | 150+ |
| 📚 Documentation | Markdown |
| 🚀 Status | 🟢 Active Development |
This repository is a work in progress and is updated regularly with new KC7 scenario sections, notes, and KQL queries.
Section 1 - KQL 101.mdSection 2 - Quarantine Quandary.mdSection 3 - The Phisher's Net.mdSection 4 - Derpy Database.mdSection 5 - Bonus - Mo' Money Mo' Problems.md
Section 1 - KQL 101 🧰.mdSection 2 - Shark Attack! 🦈.mdSection 3 - Hunting the Shark 🔍.mdSection 4 - Sand in my 👁️ 👁️.mdSection 5 - A Clean Sweep 🧹.mdSection 6 - Security Jeopardy REDUX 🕺.md
Section 1 - What's a Query 🤔.mdSection 2 - All about the dataz 👩💻.mdSection 3 - Cyber Cattle Thief 🐄.mdSection 4 - Cowhands-on-Keyboard 🤠.md
Section 1 - SCADA NADA.mdSection 2 - Phish and Chips.md
Section 1 - KQL 101 🍚.mdSection 2 - Tummy Trouble, make it Double 🤢.md
Section 1 - Empire Health Introduction.mdSection 2 - More Intel.md
Section 1 - Sock Savior.md
Section 1 - KQL 101 🥚.mdSection 2 - Just Keep Swimming 🐟.mdSection 3 - Hash Slinging Slasher 🪦.mdSection 4 - Swimming with Jellyfishes 🏊♀️.mdSection 5 - Y'all Too Good.md
Section 0 - KQL 101! 🧙.mdSection 1 - They call me CRIMSON 🐁.mdSection 2 - 🌲 Forest Blizzard ❄️.md
SUPERMASSIVE BLACKHOLE 🪐.mdYEETED INTO SPACE 😱👾.md
Section 3 - GETTING SMARTER 🧠.md
This repository is intended to:
- Practice Kusto Query Language (KQL) through realistic security investigations.
- Learn investigation methodologies used by SOC analysts.
- Improve KQL query writing through hands-on exercises.
- Maintain organized documentation for future reference.
- Track progress across KC7 Cyber scenarios.
- Open a scenario folder.
- Start from the first available section.
- Read the investigation context.
- Execute the provided KQL queries in KC7/Kusto.
- Modify the queries and observe the results.
- Continue to the next section.
- All documentation is written in Markdown.
- Scenario names and section titles are preserved exactly as provided by KC7.
- Queries include explanations, investigation steps, and observations where applicable.
- This repository is continuously expanded as more KC7 investigations are completed.
Consider giving it a ⭐ to support the project and help others discover practical KQL learning resources.
Happy Hunting! 🔎