A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Nov 4, 2024
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant
example queries for learning the kusto language
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
Enables Kibana to query Azure Data Explorer (ADX / Kusto)
Azure Data Explorer (Kusto) SDK for Go
JS SDK for the Kusto service
C# KQL query engine with flexible I/O layers and visualization
Quick start. Index multiple documents in a repository using HuggingFace embeddings. Save them in Chroma and / or FAISS for recall. Choose OpenAI or Azure OpenAI APIs to get answers to your questions - Q&A with OpenAI and Azure OpenAI.
Terraform script to deploy almost all Azure Data Services
Query Kusto like a pro from the comfort of your Jupyter notebook
A self-contained execution engine for the Kusto Query Language (KQL) written in C#
Add a description, image, and links to the kusto topic page so that developers can more easily learn about it.
To associate your repository with the kusto topic, visit your repo's landing page and select "manage topics."