Repository navigation

#

defender-for-endpoint

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python
1560
16 小时前

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Jupyter Notebook
773
19 小时前

PowerShell-based Automation of Defender for Endpoint

Python
176
3 个月前

Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations

PowerShell
96
2 个月前

ASR Configurator, Essentials and Atomic Testing

Python
95
6 个月前

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior

54
3 天前

Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC

Python
48
3 天前

This repository will describe the details surrounding the SIEM (wazuh) mini project, which will cover all aspects of topology design, deployment, rules, integration, and fine tune.

26
3 年前

Python for Security is the home of all open source Python projects that can integrate with Microsoft Technologies.

Python
14
4 年前

Microsoft Defender for Endpoint PowerShell module

PowerShell
12
2 年前

Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)

PowerShell
12
1 个月前

A set of importable Intune policies that simplify onboarding/offboarding MacOS devices to/from Defender for Business/Endpoint.

7
2 个月前

Repo includes KQL queries that you can run in your Azure Log Analyics environment.

6
3 年前

A PowerShell module to interact with Microsoft's Defender for Endpoint API.

C#
5
3 年前

K9-Defender is highly Simple with a Sophisticated Watchdog System and a Powerful Process Scanning both for Windows 10 and 11

4
1 年前

MaxMind Geo and ASN Data for Kusto

Shell
3
1 个月前