17. MustLearnKQL -  The Let Statement
2:58
14 MustLearnKQL The Project Operator
1:57
13.MustLearnKQL: The Extend Operator
2:40
10. MustLearnKQL:  The Count Operator
2:27
8. MustLearnKQL: The Where Operator
4:05
7. MustLearnKQL: The Schema
5:00
2 жыл бұрын
6. MustLearnKQL: The Interface
8:37
2 жыл бұрын
3. Must Learn KQL: The Workflow
5:35
1. Must Learn KQL: Introduction
1:06
Пікірлер
@sudeepkoroth1468
@sudeepkoroth1468 6 күн бұрын
Description Url is not working
@CyberAutomate
@CyberAutomate 5 күн бұрын
Sorry about that, I'm still in the process of moving all my legacy code to Github
@daye1997
@daye1997 8 күн бұрын
Thank you! How do you list available module names you can run for this function or you need to know the exact module name?
@CyberAutomate
@CyberAutomate 8 күн бұрын
Get-Module -ListAvailable will show all modules
@sudeepkoroth1468
@sudeepkoroth1468 Ай бұрын
Thanks a lot
@gettingpast4391
@gettingpast4391 2 ай бұрын
Thanks for this! The sound of that keyboard is like nails on a chalk board lol.
@AbhishekShah-u1j
@AbhishekShah-u1j 2 ай бұрын
For some reason, i dont see the filter tab, any idea where it is?
@bijithjoshy
@bijithjoshy 5 ай бұрын
Hi Sir, I am currently using your old script for the inventory and I saw this new version. I want to try this can you please help to know how I can run this script from a list file ? I saw this in the example, but how can I choose this?
@Sabs761010
@Sabs761010 5 ай бұрын
hi, how can I get a list of the computers from AD with the user that has login into them?
@Explorewithargho
@Explorewithargho 9 ай бұрын
Hi, can you help how to change the status of Azure devops test case to passed fail as per vs code execution.
@edwardaragon915
@edwardaragon915 10 ай бұрын
Very useful. Thank you for sharing.
@randallflat2010
@randallflat2010 11 ай бұрын
How would this be done across a domain? Replace -computers with domain or?
@fylip22b
@fylip22b Жыл бұрын
Bonjour et merci pour cette note intéressante. Je pratique PowerShell et j'ai toujours cherché à rendre la lecture plus claire. Votre exemple est le bienvenue. À bientôt. Philippe P
@hareeshsinguluri8841
@hareeshsinguluri8841 Жыл бұрын
Can you tel me how to export active directory users list with this all attributes like Display name, userprincipal name, SMTP address,lastlogon date, last logon days count(60 or 90days), lastpasswordset,when created,when changed
@atul2651
@atul2651 Жыл бұрын
Thanks for the video, quick query: Is there anyway to join more than 2 tables ?
@TenMinuteKQL
@TenMinuteKQL Жыл бұрын
Great KQL content, thank you!
@darryvakki9807
@darryvakki9807 Жыл бұрын
excellent Kiss concept
@leoh.8096
@leoh.8096 Жыл бұрын
Thanks for the video which is really helpful. Our group member is over 5000, and when I run this I get "The size limit for this request was exceeded". do you have a work around for this? Thank you,
@kabipradeep1
@kabipradeep1 Жыл бұрын
Oh. Thank you. This is really helped me. Thanks for the initiative. Keep it up
@kabipradeep1
@kabipradeep1 Жыл бұрын
Thanks buddy. It really helped me to understand this operator.
@dollysiharath4205
@dollysiharath4205 Жыл бұрын
the video is blurry and hard to see.
@endelnaiva
@endelnaiva Жыл бұрын
Crie um arquivo em LOTE, que faça o seguinte : - pesquise, procure por algum programa e ou serviço do windows Se "aberto" ( Faça isso ou isso ou isso ) se fechado ou nao existente ( Aguarde X minutos ou X segundos, e refaça operação outra vez PERGUNTA : - COMO ESCREVER UM ARQUIVO QUE FAÇA ISSO CORRETAMENTE - SE VOCÊ SABE ESCREVER UM ARQUIVO ASSIM ? - ALGUÉM QUE ESTÁ LENDO ISSO , SABE ESCREVER TAL ARQUIVO ?
@PaulMisner
@PaulMisner Жыл бұрын
The CDA.MS links no longer work.
@swXanterra
@swXanterra 2 жыл бұрын
Nice video, I appreciate your help.
@jaiyden9888
@jaiyden9888 2 жыл бұрын
Noice
@sagarprajapati5857
@sagarprajapati5857 2 жыл бұрын
this code works for me..Thanks for this helpful video.
@scatheli
@scatheli 2 жыл бұрын
Hi CyberAutomate.... Just few words to thank you. It helps.... Just one more question.... instead of verbose live comment (for non responding computer) how can you add into the cvs export : $computer unreachable line...? Many thanks for your precious support
@jaiyden9888
@jaiyden9888 2 жыл бұрын
Thanks for this :)
@Antonio-yc2kx
@Antonio-yc2kx 2 жыл бұрын
𝐩𝐫𝐨𝐦𝐨𝐬𝐦 🤘
@default19in
@default19in 2 жыл бұрын
Millions of tx for taking efforts and shearing with us. One think we missed is pc serial numbers.
@BERMUDA-vh1yb
@BERMUDA-vh1yb 2 жыл бұрын
IS THIS SCRIPT APPLICABLE TO LINUX MACHINES AS WELL?
@manjualadakatti6531
@manjualadakatti6531 2 жыл бұрын
Great content and Video 💥✨ I have a query, so you are pushing a configuration from Client laptop to Exchange server VM, what is the authentication method you have used?? Is there any registration key? How will LCM of client will come to know to push the config. to a VM?? Thanks
@blajorst
@blajorst 2 жыл бұрын
good video. I have created a gMSA, using your guide, but i am having issues starting a service once i assign the new created account. I am getting 'Error 1297: A privilege that the service requires to function properly does not exist in the service account configuration'
@mission_possible
@mission_possible 2 жыл бұрын
Thanks! Make more videos on KQL
@umeshhande5759
@umeshhande5759 2 жыл бұрын
Than you for you videos. Can you please help, I don't see 3 dots where you click File path and Extend Column..
@TheOspf
@TheOspf 2 жыл бұрын
same here, unbale to find three dots in logs table, not sure if that applies to any specific table
@jatingupta8364
@jatingupta8364 2 жыл бұрын
How we can make to seperate ps1 for example download on multiple machines on first day and then ran script to install it om second day please assist
@maninder1984
@maninder1984 2 жыл бұрын
You are a savior bud! Thank you
@matclarkcybersec
@matclarkcybersec 2 жыл бұрын
Gday mate - great series, the Playlist for KQL has a weird as jarring Gridfinity modular workshop video? Not sure if that's a youtube thing - but might pay to remove it from the list :) thanks and good work.
@CyberAutomate
@CyberAutomate 2 жыл бұрын
Oops... Thanks for bringing it to my attention. :)
@savosaslic4764
@savosaslic4764 2 жыл бұрын
Hi Mate, having issues with cyber security school work so thought I’d ask you if you know? “ Any techniques to identify information about a remote machine” and what softwares to use? Thanks very much
@rodrigochegueescalante226
@rodrigochegueescalante226 2 жыл бұрын
NEW SUBSCRIBERS LIKE AND SHARE. THANKS FOR SHARING.
@stephenthang7607
@stephenthang7607 2 жыл бұрын
Powershell want me to type help in terminal and can't start the project correctly
@legionsalt
@legionsalt 2 жыл бұрын
help
@RichardGailey
@RichardGailey 2 жыл бұрын
I noticed that when I do this, the ComputerIP_Hidden information it returns is the ISP IP and can sometimes show the location (in my case my device) is miles away from where it is in reality. But when I do a Location lookup in Intune, it is pin-point accurate. Do you know what the table name is that Intune uses that give accurate information about my devices location and why the Azure information regarding IP address is always out by some way at times? I noticed this when looking at my Sign-ins in Azure. The IP address, while correct for my machine, is geographically way out, but the Intune Locate Device lookup is always very accurate?
@CyberAutomate
@CyberAutomate 2 жыл бұрын
The blog post has the Intune table names in it. www.azurecloudai.blog/2020/07/02/connecting-intune-to-azure-sentinel
@RichardGailey
@RichardGailey 2 жыл бұрын
@@CyberAutomate Awesome. Going to take a read now. Just finished the series you have made so far here on YT. This really is a great resource and fantastic for people like me that learn better via video format and can follow along on our own Azure labs. Thanks again and look forward to the next one
@DeepakKumar-my9kg
@DeepakKumar-my9kg 2 жыл бұрын
Looking forward to the next lessons - Many thanks for doing this!
@khurramwzd
@khurramwzd 2 жыл бұрын
Thanks dear. will be easy for newbies to follow.
@ovidiuioni5690
@ovidiuioni5690 2 жыл бұрын
hope the next videos will be added soon
@RichardGailey
@RichardGailey 2 жыл бұрын
This was really helpful, so thank you. Can you also explain what type of Data Connectors the user will need to be logging on for certain queries to work? The reason I ask is that for certain queries that I have found that will be useful, they will fail to run (will run, but will just show an error or have a Red mark against the KQL query) but Azure LA won't tell you why in human readable terms as to what type of Data Logs need to be connected to get the query to work? That's probably been my main frustration with writing and editing previously created queries I have found, like in the Defender Github.
@CyberAutomate
@CyberAutomate 2 жыл бұрын
The easiest method I can think of is expanding all the data sources in the Sentinel Log console. That will show you what tables have data in them. If you're trying to execute a table that doesn't exist it will error. For instance, if I find a useful query on Github that references the AADRiskyUsers table and that table is not in my list I'll get an error. If I wanted to know which data connector is associated with the AADRiskyUsers table I can open the Data Connectors blade, click on a data connector and the tables that connector uses will be in the pane on the right at the bottom. As an example, if you click on the Amazon Web Services connector you will see that connector uses the AWSCloudTrail table. I hope all that makes sense. There are probably other methods but that's how I do it.
@RichardGailey
@RichardGailey 2 жыл бұрын
@@CyberAutomate Yep, that makes perfect sense. Thank you for the reply
@CyberAutomate
@CyberAutomate 2 жыл бұрын
I hope you will join me for some KQL goodness. The first video in the series is kzbin.info/www/bejne/fZKci3R4jdmMja8. Access all of Rod Trent's blog series aka.ms/MustLearnKQL
@meriemlaassal5469
@meriemlaassal5469 3 жыл бұрын
How we can add description for each group? And how we can recovre the common name cn for each group plz ?
@fnanfne
@fnanfne 2 жыл бұрын
Create a new column in the .csv file and call it Description. Then add the following switch into the script at the end of line 4... -Description $item.Description
@johnmosqueda1029
@johnmosqueda1029 3 жыл бұрын
Is there a way to filter the group members even more? I have a large group of users within a universal group. I’m able to export the results and copy the results to excel and filter that way. I was wondering if there was a another method?
@redadz9105
@redadz9105 3 жыл бұрын
Thank you, but I think with splatting you can ommit the semi-column when you put the Key-Value pair in a new line (using Enter Key)
@ANIl1454
@ANIl1454 3 жыл бұрын
Thanks for the same, any idea how do i get partition information such as MBR or GPT for 120+ servers remotely ? output in a file. Below script i used but not helping, as it doesnt get data from more than 1 machine. $LogDate = get-date -f yyyyMMddhhmm $File = Get-Content -Path D:\disk\servers.txt $DiskReport = ForEach ($Servernames in ($ServerList)) {} Invoke-Command -computername $Servernames -scriptblock { Get-Disk } | Select-Object Number, PartitionStyle