1

Osquery is a great open standard for collecting data from endpoints, using SQL syntax.

Kusto is a new Microsoft language for collecting data from Windows endpoints, using syntax which is almost--but not entirely--unlike SQL.

Microsoft is publishing threat hunting guidance in Kusto.

Is there any easy way to translate threat hunting queries that are published in Kusto into an Osquery compatible form?

UndercoverDog
  • 612
  • 2
  • 17
user502
  • 3,261
  • 1
  • 22
  • 18

0 Answers0