kql
Here are 144 public repositories matching this topic...
Language:All
Sort:Most stars
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
- Updated
Mar 3, 2025 - Python
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
- Updated
Nov 28, 2024
Hunting queries and detections
- Updated
Jan 17, 2025
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
- Updated
Mar 14, 2025 - Jupyter Notebook
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
- Updated
Feb 12, 2025
KQL Queries. Microsoft Defender, Microsoft Sentinel
- Updated
Mar 16, 2025 - HTML
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
- Updated
Nov 22, 2024
MDATP
- Updated
Jul 20, 2024 - PowerShell
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
- Updated
Dec 29, 2024
Repository with Sample KQL Query examples for Threat Hunting
- Updated
Sep 1, 2022
My personal work with Copilot for Security
- Updated
Mar 17, 2025 - HTML
Kirby's Query Language API combines the flexibility of Kirby's data structures, the power of GraphQL and the simplicity of REST.
- Updated
Feb 12, 2025 - PHP
KQL Queries. Microsoft Defender, Microsoft Sentinel
- Updated
Feb 26, 2025
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.
- Updated
Aug 5, 2024
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
- Updated
Mar 16, 2025
example queries for learning the kusto language
- Updated
Jun 23, 2021
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
- Updated
Aug 2, 2024 - PowerShell
Hunting Queries for Defender ATP
- Updated
Mar 13, 2025
Improve this page
Add a description, image, and links to thekql topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with thekql topic, visit your repo's landing page and select "manage topics."