<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Talk on Nicola Suter</title><link>https://nicolasuter.ch/tags/talk/</link><description>Recent content in Talk on Nicola Suter</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><copyright>© 2026 Nicola Suter</copyright><lastBuildDate>Mon, 01 Jul 2024 20:07:46 +0000</lastBuildDate><atom:link href="https://nicolasuter.ch/tags/talk/rss.xml" rel="self" type="application/rss+xml"/><item><title>Mai 2024 KQL Café Recap</title><link>https://nicolasuter.ch/mai-2024-kql-cafe-recap/</link><pubDate>Mon, 01 Jul 2024 20:07:46 +0000</pubDate><guid>https://nicolasuter.ch/mai-2024-kql-cafe-recap/</guid><description>&lt;p&gt;In May I had the pleasure to be invited to the &lt;a href="https://kqlcafe.github.io/website/" target="_blank" rel="noreferrer"&gt;KQL Café&lt;/a&gt; which is hosted by &lt;a href="https://twitter.com/castello_johnny" target="_blank" rel="noreferrer"&gt;Gianni Castaldi&lt;/a&gt; &amp;amp; &lt;a href="https://twitter.com/alexverboon" target="_blank" rel="noreferrer"&gt;Alex Verboon&lt;/a&gt;. Within this format they empower people to work with KQL and share various tips and tricks. So this is not a usual blogpost but rather a summary and resource hub for the things I presented within the KQL Café.&lt;/p&gt;

&lt;h1 class="relative group"&gt;Summary
 &lt;div id="summary" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#summary" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h1&gt;
&lt;p&gt;To make the content of my talk more accessible, you can find a summary of the individual topics, including the leveraged KQL queries and further resources as part of this post. The KQL queries were mostly consuming the Entra ID Sign-In and Audit Logs. You can forward them to your Microsoft Sentinel or Log Analytics workspace.&lt;/p&gt;

&lt;h2 class="relative group"&gt;Recording
 &lt;div id="recording" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#recording" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;You can find the full recording of the KQL Café on YoutTube.&lt;/p&gt;
&lt;iframe width="560" height="315" src="https://www.youtube-nocookie.com/embed/lKB1sfZuDio?si=HgXMFWTI21ypES3g" title="YouTube video player" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" referrerpolicy="strict-origin-when-cross-origin" allowfullscreen&gt;&lt;/iframe&gt;

&lt;h2 class="relative group"&gt;What the heck is ITDR?!
 &lt;div id="what-the-heck-isitdr" class="anchor"&gt;&lt;/div&gt;
 
 &lt;span
 class="absolute top-0 w-6 transition-opacity opacity-0 -start-6 not-prose group-hover:opacity-100 select-none"&gt;
 &lt;a class="text-primary-300 dark:text-neutral-700 !no-underline" href="#what-the-heck-isitdr" aria-label="Anchor"&gt;#&lt;/a&gt;
 &lt;/span&gt;
 
&lt;/h2&gt;
&lt;p&gt;Identity Threat Detection and Response (ITDR) is currently one of my favourite topics. It’s basically a combination of the disciplines Identity and Access Management (IAM) and the cyber security disciplines detection and response. Similar to other cybersecurity topics there’s a rule of thumb: The more you invest on the preventive side to increase your identity security posture — the less effort you (hopefully) have on the detection and response side 🤞🤞. Within my talk for the KQL Café I addressed various of those ITDR topics that help you on the preventive side.&lt;/p&gt;</description></item></channel></rss>