Repository navigation

#

kql

KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.

Python
1560
20 小时前
netevert/sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

HCL
1073
10 个月前

Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).

Jupyter Notebook
767
1 天前

KQL Queries. Microsoft Defender, Microsoft Sentinel

JavaScript
755
3 小时前

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

733
1 个月前

Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.

483
10 个月前

A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.

414
2 个月前

Repository with Sample KQL Query examples for Threat Hunting

216
3 年前

My personal work with Copilot for Security

HTML
193
3 个月前

KQL Queries. Microsoft Defender, Microsoft Sentinel

181
18 天前

KQL queries for Advanced Hunting

175
6 年前

Kirby's Query Language API combines the flexibility of Kirby's data structures, the power of GraphQL and the simplicity of REST.

PHP
150
3 个月前

In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).

XSLT
129
4 天前

Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.

Bicep
127
6 天前

C# KQL query engine with flexible I/O layers and visualization

C#
105
2 天前

example queries for learning the kusto language

104
4 年前

Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations

PowerShell
96
2 个月前