Azure Kusto Irql

by microsoft354361d83247MITListed Oct 8, 2026Updated Oct 8, 2026

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.

FeaturedInstructions onlySecurityData & Analytics

Only the file list is public. File contents are available once the skill is installed in a workspace.

PathSizeType
references/EXAMPLES.md2.2 KBtext/markdown
references/KUSTO_EXPLORER_LAUNCH.md2.6 KBtext/markdown
SKILL.md10.2 KBtext/markdown

Source and attribution

Source:microsoft/skillsin.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irqlat commit354361d

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal