Azure Kusto Irql

by microsoft354361d83247MITListed Oct 8, 2026Updated Oct 8, 2026

Compose IRQL (Incident Response Query Language) queries for Kusto cybersecurity investigations. Translates natural language hunting questions into composable IRQL pipelines using Get_*, Extract_*, and Enrich_* functions. WHEN: IRQL query, security hunt, threat hunting KQL, incident response query, compose hunting pipeline, failed logins, phishing investigation, lateral movement, process execution, file creation events.

FeaturedInstructions onlySecurityData & Analytics
  1. 354361d83247Currentcommit 354361dPublished Oct 8, 2026

Source and attribution

Source:microsoft/skillsin.github/plugins/azure-kusto-graph-skills/skills/azure-kusto-irqlat commit354361d

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal