Skip to content

Latest commit

 

History

History
38 lines (38 loc) · 9.28 KB

Community Repositories.md

File metadata and controls

38 lines (38 loc) · 9.28 KB

KQL Community Repositories

Link Description Stars
Azure Sentinel Repository - Azure Cloud-native SIEM for intelligent security analytics for your entire enterprise Stars
Sentinel-Queries - reprise99 Collection of KQL queries Stars
Falcon Friday - FalconForceTeam Hunting queries and detections Stars
Threat-Hunting-and-Detection - Cyb3r-Monk Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language). Stars
Hunting-Queries-Detection-Rules - Bert-JanP KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. Stars
AzSentinelQueries - f-bader Repository with Sentinel Analytics Rules and Hunting Queries Stars
KQL-threat-hunting-queries - cyb3rmik3 A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender). Stars
KQL - Wortell KQL queries for Advanced Hunting Stars
SentinelKQL - rod-trent Azure Sentinel KQL Stars
Sentinel_KQL - ep3p In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool). Stars
AdvancedHuntingQueries - lawndoc Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant Stars
MDATP AdvancedHunting - JesseEsquivel Microsoft Defender Advanced Threat Protection Stars
KQL - mjmelone Michael Melone's Kusto Query library Stars
AzureSentinel - Cloud-Architekt Sharing my KQL queries for Azure Sentinel Stars
Hunting-Queries-Detection-Rules - alexverboon KQL Queries. Microsoft 365 Defender, Microsoft Sentinel Stars
KQL Security Queries - Shivammalaviya KQL Security Queries Stars
Invictus-training - KQL-QueryPack - invictus-ir Invictus: Cloud Incident Response Query Pack Stars
DefenderATPQueries - 0xAnalyst Hunting Queries for Defender ATP Stars
LearningKijo/KQL Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint. Stars
awesomekql - awesomekql Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs Stars
Hunting-Queries-Detection-Rules - KustoKing KQL Detections for Microsoft Sentinel and Microsoft 365 Defender Stars
KQL- mr-r3b00t This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet Stars
MustLearnKQL - rod-trent Code included as part of the MustLearnKQL blog series Stars
kql-for-dfir - reprise99 A guide to using Azure Data Explorer and KQL for DFIR Stars
Invictus-training - Invictus Cloud Incident Response Query Pack Stars
MDATP - JesseEsquivel Microsoft Defender Advanced Threat Protection Stars
DefenderATPQueries - 0xAnalyst Hunting Queries for Defender ATP Stars
KQL - LearningKijo Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint. Stars
KQL - KostasKoutrou KQL Queries for Advanced Hunting / Log Analytics Stars
Sentinel-queries - samilamppu Sentinel-queries Stars
Hunting-Queries-Detection-Rules - SlimKQL KQL Queries. Microsoft Defender, Microsoft Sentinel Stars
KustQueryLanguage_kql - m4nbat Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting Stars
DE-TH-Aura - SecurityAura Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration). Stars
Threat-Hunting-KQL-Queries Threat-Hunting-KQL-Queries Stars
Kustonomicon The Kustonomicon is your reference companion for navigating the depths of Kusto Query Language (KQL). Stars