26 results found Sort:

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Created 2022-05-30
372 commits to main branch, last one a day ago
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Created 2019-05-30
313 commits to master branch, last one about a year ago
78
725
bsd-3-clause
56
Hunting queries and detections
Created 2020-08-04
99 commits to main branch, last one about a month ago
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Created 2020-11-02
23 commits to main branch, last one 9 days ago
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Created 2022-07-19
343 commits to main branch, last one 3 days ago
MDATP
This repository has been archived (exclude archived)
Created 2019-06-15
208 commits to master branch, last one 3 months ago
78
442
unknown
22
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
Created 2022-12-12
807 commits to main branch, last one 3 months ago
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Created 2023-11-01
51 commits to main branch, last one about a month ago
KQL Queries. Microsoft Defender, Microsoft Sentinel
Created 2024-08-02
406 commits to main branch, last one a day ago
Repository with Sample KQL Query examples for Threat Hunting
Created 2020-10-23
17 commits to main branch, last one 2 years ago
My personal work with Copilot for Security
Created 2023-10-28
829 commits to main branch, last one 2 days ago
5
144
mit
16
Kirby's Query Language API combines the flexibility of Kirby's data structures, the power of GraphQL and the simplicity of REST.
Created 2020-01-15
111 commits to main branch, last one about a month ago
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant
Created 2021-08-13
140 commits to main branch, last one 3 months ago
KQL Queries. Microsoft Defender, Microsoft Sentinel
Created 2023-05-02
99 commits to main branch, last one 28 days ago
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
Created 2022-07-19
1,702 commits to main branch, last one a day ago
example queries for learning the kusto language
Created 2019-05-20
24 commits to main branch, last one 3 years ago
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
Created 2023-10-17
85 commits to main branch, last one 3 months ago
Collection of awesome KQL queries for use in Portal and via PowerShell - by @JesseLoudon
Created 2020-06-04
25 commits to master branch, last one 4 months ago
Hunting Queries for Defender ATP
Created 2023-09-12
274 commits to main branch, last one 2 days ago
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
Created 2022-03-25
117 commits to master branch, last one 14 hours ago
Contains Entra Related PowerShell Scripts and Entra Related KQL for Logs in Log Analytics
Created 2017-10-16
1,903 commits to master branch, last one 27 days ago
Sentinel Analytics Rule converter PowerShell module
Created 2023-02-18
179 commits to main branch, last one 3 months ago
5
50
gpl-3.0
3
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Created 2020-10-29
148 commits to main branch, last one about a year ago
8
44
unknown
3
Ian Hanley's deceptively simple KQL queries.
Created 2023-04-29
130 commits to Main branch, last one about a month ago
C# KQL query engine with flexible I/O layers and visualization
Created 2023-11-13
579 commits to main branch, last one 4 days ago
This repository has no description...
Created 2023-01-02
44 commits to master branch, last one about a year ago