Skills test for hiring
KQL and Microsoft Sentinel test for hiring
A hands-on KQL test that shows who can actually hunt. Candidates write real queries against sign-in, device and audit tables in a Sentinel-style workspace, with nothing labelled, and have to find the attacker in the data.
9 hands-on challenges · 20 to 40 minutes each · Built around your job spec
What candidates actually do
The work itself. Not questions about it.
Candidates work in environments that look like the job, on realistic data with legitimate activity left in. The answer only exists in the data in front of them, so there is nothing to look up and nothing to guess between.
- Sentinel-style KQL workspace
- SigninLogs
- Device and process events
- Audit logs
KQL Lab: Password Spray and Privilege Escalation
An attacker sprayed passwords against the tenant, then escalated privileges with an account they took over. Using the sign-in and alert tables, find the source IP address of the spray, then the account that was compromised.
Counts distinct accounts with failed sign-ins per source address in a time window, rather than failures per account, then follows the successful sign-in through to the privilege change. A weak answer stalls at the schema or reports the noisiest IP.
Skills covered
9 real challenges. Pick the ones that fit the role.
Every assessment is assembled from the library to match your job spec, then calibrated to the level you are hiring. These are the KQL and Sentinel challenges it draws on.
Identity and sign-in investigation
- KQL Lab: Suspicious Sign-In Investigation
- KQL Lab: Password Spray & Privilege Escalation
- KQL Lab: MFA Bypass & Token Replay Detection
Endpoint and logon hunting
- KQL Lab: Windows Logon Forensics
- KQL Lab: Endpoint Threat Detection
Email and data threats
- KQL Lab: Phishing Campaign Detection
- KQL Lab: Insider Threat - Data Exfiltration
End-to-end investigation
- KQL Lab: Full Kill Chain Investigation
Detection rule review
- Detection Review Board - Sentinel Analytics Rule
Levels: 6 Medium · 2 Hard · 1 Expert. Assessments usually combine a few challenges to fit the time you set.
What you get back
Evidence for every candidate. Scored the same way.
Every candidate is scored against the same answers, so you compare the work, not impressions. Read a candidate in two minutes, then interview the ones who can do the job.
- A score per skill See where each candidate is strong and where they are thin, not just a single number.
- Their actual answers Read what they found and how they explained it, so you can probe it in the interview.
- Integrity signals Time away, outside pasting, fullscreen exits and second screens, next to every score.
Roles it fits
Use it for the hire. Then for the interview.
- SOC analyst skills test KQL alongside phishing, event logs and triage, for SOC roles.
- Detection engineer interview questions 25 questions with strong answers, including a KQL task.
- How to assess a detection engineer Testing rule writing and tuning, not just querying.
- SOC analyst interview questions Questions to follow up the test in the interview.
Common questions
About the KQL and Sentinel test.
What does the KQL test measure?
Whether a candidate can use KQL to investigate real activity: finding suspicious sign-ins, password sprays, token replay, endpoint threats and data exfiltration across sign-in, device and audit tables. The answer has to be found in the data, not recalled.
Is this a real Microsoft Sentinel instance?
It is a Sentinel-style KQL workspace with realistic tables such as SigninLogs, device events and audit logs, built for assessment. Candidates write real KQL against it; they do not need access to your environment.
Who should take a KQL test?
SOC analysts, threat hunters and detection engineers working in Microsoft security tools. For broader SOC roles, combine it with email and event log challenges in the SOC analyst test.
How long does it take?
Most labs take 20 to 30 minutes; the end-to-end kill chain investigation takes about 40. You choose which labs to include to fit the time you want.
Try it on your role
See the KQL and Sentinel test built for your job spec.
Send us the job spec for a role you are hiring. Within 48 hours we send you a hands-on assessment built around it, in your brand, to try for yourself. Free, and with no commitment.