A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Dec 5, 2024
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Collection of Azure Monitor or Sentinel Kusto Queries
KQL Local Manager, allows you to manage and organize KQL Queries in a central Database.
Add a description, image, and links to the kusto-query topic page so that developers can more easily learn about it.
To associate your repository with the kusto-query topic, visit your repo's landing page and select "manage topics."