Repository navigation

#

defender-for-endpoint

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python
1520
2 天前

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Jupyter Notebook
747
5 个月前

PowerShell-based Automation of Defender for Endpoint

Python
172
2 个月前

Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations

PowerShell
93
4 天前

ASR Configurator, Essentials and Atomic Testing

Python
86
4 个月前

Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC

Python
47
1 天前

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior

41
1 个月前

This repository will describe the details surrounding the SIEM (wazuh) mini project, which will cover all aspects of topology design, deployment, rules, integration, and fine tune.

26
2 年前

Python for Security is the home of all open source Python projects that can integrate with Microsoft Technologies.

Python
14
4 年前

Microsoft Defender for Endpoint PowerShell module

PowerShell
12
2 年前

Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)

PowerShell
12
1 个月前

Repo includes KQL queries that you can run in your Azure Log Analyics environment.

7
3 年前

A PowerShell module to interact with Microsoft's Defender for Endpoint API.

C#
6
2 年前

K9-Defender is highly Simple with a Sophisticated Watchdog System and a Powerful Process Scanning both for Windows 10 and 11

4
1 年前

MaxMind Geo and ASN Data for Kusto

Shell
3
1 个月前

Defender for Endpoint Advanced Hunting Queries

2
4 年前