26 results found Sort:

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Created 2022-05-30
404 commits to main branch, last one 7 hours ago
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Created 2019-05-30
321 commits to master branch, last one 23 days ago
83
735
bsd-3-clause
57
Hunting queries and detections
Created 2020-08-04
99 commits to main branch, last one 3 months ago
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Created 2020-11-02
30 commits to main branch, last one a day ago
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Created 2022-07-19
347 commits to main branch, last one 16 days ago
MDATP
This repository has been archived (exclude archived)
Created 2019-06-15
208 commits to master branch, last one 5 months ago
79
445
unknown
22
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
Created 2022-12-12
808 commits to main branch, last one 29 days ago
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Created 2023-11-01
53 commits to main branch, last one 11 days ago
KQL Queries. Microsoft Defender, Microsoft Sentinel
Created 2024-08-02
444 commits to main branch, last one 2 days ago
Repository with Sample KQL Query examples for Threat Hunting
Created 2020-10-23
17 commits to main branch, last one 2 years ago
My personal work with Copilot for Security
Created 2023-10-28
856 commits to main branch, last one 9 days ago
5
145
mit
16
Kirby's Query Language API combines the flexibility of Kirby's data structures, the power of GraphQL and the simplicity of REST.
Created 2020-01-15
111 commits to main branch, last one 3 months ago
KQL Queries. Microsoft Defender, Microsoft Sentinel
Created 2023-05-02
101 commits to main branch, last one 11 days ago
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant
Created 2021-08-13
140 commits to main branch, last one 4 months ago
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
Created 2022-07-19
1,724 commits to main branch, last one a day ago
example queries for learning the kusto language
Created 2019-05-20
24 commits to main branch, last one 3 years ago
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
Created 2023-10-17
85 commits to main branch, last one 4 months ago
Collection of awesome KQL queries for use in Portal and via PowerShell - by @JesseLoudon
Created 2020-06-04
25 commits to master branch, last one 5 months ago
Hunting Queries for Defender ATP
Created 2023-09-12
276 commits to main branch, last one about a month ago
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
Created 2022-03-25
134 commits to master branch, last one a day ago
Contains Entra Related PowerShell Scripts and Entra Related KQL for Logs in Log Analytics
Created 2017-10-16
1,927 commits to master branch, last one 2 days ago
Sentinel Analytics Rule converter PowerShell module
Created 2023-02-18
192 commits to main branch, last one 2 days ago
5
51
gpl-3.0
3
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Created 2020-10-29
148 commits to main branch, last one about a year ago
C# KQL query engine with flexible I/O layers and visualization
Created 2023-11-13
579 commits to main branch, last one about a month ago
8
46
unknown
4
Ian Hanley's deceptively simple KQL queries.
Created 2023-04-29
130 commits to Main branch, last one 2 months ago
This repository has no description...
Created 2023-01-02
44 commits to master branch, last one about a year ago