7 results found Sort:

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Created 2020-11-02
30 commits to main branch, last one about a month ago
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Created 2022-07-19
357 commits to main branch, last one 3 days ago
Microsoft Sentinel SOC Operations
Created 2020-02-27
368 commits to master branch, last one 6 months ago
The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
Created 2021-10-13
746 commits to main branch, last one 12 days ago
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
Created 2022-07-19
1,745 commits to main branch, last one a day ago
A collection of various SIEM rules relating to malware family groups.
Created 2022-12-05
52 commits to master branch, last one 7 months ago
9
46
unknown
4
Ian Hanley's deceptively simple KQL queries.
Created 2023-04-29
134 commits to Main branch, last one a day ago