> Markdown version of [/videos/1543-from-tables-to-graphs-in-minutes-supercharging-kusto-graph-analytics-with-ai-powered-development?t=1476](https://www.wearedevelopers.com/videos/1543-from-tables-to-graphs-in-minutes-supercharging-kusto-graph-analytics-with-ai-powered-development?t=1476). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # From Tables to Graphs in Minutes: Supercharging Kusto Graph Analytics with AI-Powered Development Attackers think in graphs, so why are defenders still searching through lists? Learn to build native Kusto graph models from tabular data in minutes using generative AI. - **Speakers:** [Prof Smoke](https://www.wearedevelopers.com/@prof-smoke) - **Event:** World Congress 2025 - **Published:** August 20, 2025 - **Duration:** 27:31 - **URL:** https://www.wearedevelopers.com/videos/1543-from-tables-to-graphs-in-minutes-supercharging-kusto-graph-analytics-with-ai-powered-development ## Summary Defenders historically think in lists while attackers think in graphs, leaving an analytical gap in discovering lateral movement across enterprise datasets. While relational time-series engines like Azure Data Explorer (Kusto) excel at ingesting petabytes of event telemetry, surfacing topological patterns has traditionally required moving data to separate tools like Neo4j. Embedding graph capabilities natively into Kusto Query Language (KQL) shifts this paradigm, allowing developers to execute Cypher-like graph matches right where the data lands to minimize data duplication and infrastructure overhead. The primary friction point in graph analytics is modeling explicit node and edge relationships from raw, unstructured tabular data. By utilizing generative AI via GitHub Copilot alongside specialized Model Context Protocol (MCP) servers in Microsoft Fabric, developers can autonomously inspect table schemas and generate optimized JSON-based graph models in minutes instead of hours. Supplying LLMs with query best practices through these custom MCP servers prevents the generation of overly complex scripts, allowing the AI agent to rapidly contextualize cybersecurity logs into functional incident graphs. This streamlined workflow enables powerful hybrid analyses, seamlessly piping output from traditional time-series anomaly detection into transient, query-time, in-memory graph models. Furthermore, contextualizing data into graphs unlocks semantic and geospatial vector proximity matching at scale. Because browser-based DOM limits frequently collapse under extensive relational topologies, natively coupling Kusto with GPU-accelerated visualization libraries like Graphistry allows security teams to render millions of active nodes, fully leveraging the massive compute capabilities underlying their telemetry lakes. **Keywords:** azure data explorer, kusto query language, kql graph analytics, tabular to graph conversion, generative ai data contextualization, cybersecurity lateral movement, model context protocol, relational time-series databases, in-memory query-time graphs, cypher graph matching, time-series anomaly detection, gpu-accelerated graph visualization, fabric realtime intelligence, graphistry integration, semantic vector matching ## Chapters 1. **Gamifying database feature learning with capture the flag** (00:05) — How capture the flag events creatively introduce and teach modern database capabilities. 1. **Overview of the Kusto big data analytics platform** (02:27) — The core capabilities of Kusto for handling large streams of high-velocity telemetry data. 1. **Embedding graph capabilities deeply into a relational engine** (03:25) — Consolidating security data by bringing native graph processing functions directly to the primary relational store. 1. **Evolving graph capabilities to first party engine objects** (05:19) — The architectural evolution from in-memory tabular graph retrofits to fully integrated native graph constructs. 1. **Defining graph structures using parameterized json objects** (06:43) — Structuring flexible node and edge definitions to correctly assemble network layers from raw relational datasets. 1. **Processing global telemetry data queries at massive scale** (07:52) — An overview of global data ingestion environments executing over seven million processor cores. 1. **Combining time series anomaly detection with network analysis** (09:59) — Implementing complex query pipelines that unite time series decomposition, geospatial distance, and semantic similarity evaluations. 1. **Materializing and persisting complex referential graph models** (13:04) — Abstracting complex multi-step procedural mapping logics into clean, queryable network model representations. 1. **Overcoming the difficulty of modeling cybersecurity attack graphs** (14:33) — The iterative manual bottlenecks required to untangle relational tables into valid security investigation structures. 1. **Automating structural graph generation using large language models** (16:09) — Using specialized tool integrations and coding assistants to rapidly evaluate relational schemas and infer graph relationships. 1. **Generating lateral movement security graphs from raw datasets** (18:35) — Prompting autonomous assistants to discover logical security connections and produce interactive hardware network visualizations. 1. **Leveraging Python visualization libraries for hardware accelerated rendering** (24:36) — Accelerating interactive graph density by offloading visual layout algorithms to dedicated hardware processors. 1. **Provisioning developer telemetry clusters for interactive training scenarios** (26:24) — Methods to deploy no-cost database environments to immediately practice analytics functions across simulated scenarios. ## Related Moments - [Introduction to generative AI and knowledge graphs](https://www.wearedevelopers.com/videos/1154-large-language-models-knowledge-graphs) (from "Large Language Models ❤️ Knowledge Graphs") - [Leveraging connected teamwork graphs to generate massive AI returns](https://www.wearedevelopers.com/videos/100068-the-ai-fluent-team-a-playbook-for-driving-enterprise-ai-transformation) (from "The AI-Fluent Team: A Playbook for Driving Enterprise AI Transformation") - [Summary of decoupling analytical compute and storage](https://www.wearedevelopers.com/videos/100075-parquet-delta-iceberg-ducklake-an-introduction-for-developers) (from "Parquet, Delta, Iceberg & Ducklake - An introduction for developers") - [Demonstrating a knowledge graph powered chatbot interface](https://www.wearedevelopers.com/videos/754-knowledge-graph-based-chatbot) (from "Knowledge graph based chatbot") - [Overcoming developer intimidation when integrating foundational graph structures](https://www.wearedevelopers.com/videos/1311-graphs-and-rags-everywhere-but-what-are-they-andreas-kollegger-neo4j) (from "Graphs and RAGs Everywhere... But What Are They? - Andreas Kollegger - Neo4j") - [Transforming unstructured email data into customized user knowledge graphs](https://www.wearedevelopers.com/videos/100128-the-golden-age-of-email-owning-the-inbox-in-the-age-of-ai) (from "The Golden Age of Email: Owning the Inbox in the Age of AI") ## Related Articles - [Graph and AI Trends 2026: Why Is AI Running but Not Yet Delivering?](https://www.wearedevelopers.com/magazine/680-graph-and-ai-trends-2026-why-is-ai-running-but-not-yet-delivering) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Making Data Warehouses Fast: A Developer’s Story](https://www.wearedevelopers.com/magazine/107-making-data-warehouses-fast-a-developer-s-story) - [Dev Digest 132 - Binging WADFlix?](https://www.wearedevelopers.com/magazine/473-dev-digest-132-binging-wadflix) ## Related Jobs - [Data Scientist](https://www.wearedevelopers.com/jobs/ext/1351648-data-scientist) at **Almedia** - [Principal Software Engineer, Enterprise AI Platform](https://www.wearedevelopers.com/jobs/ext/1467292-principal-software-engineer-enterprise-ai-platform) at **GitHub** - [Staff Software Engineer, Copilot Experiences](https://www.wearedevelopers.com/jobs/ext/164361-staff-software-engineer-copilot-experiences) at **GitHub** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [AI Software Engineer (Germany)](https://www.wearedevelopers.com/jobs/48317-ai-software-engineer-germany) at **Sunhat** - [Lead Software Engineer - Data Engineering](https://www.wearedevelopers.com/jobs/ext/2000968-lead-software-engineer-data-engineering) at **Dynatrace**