Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Jul 15, 2026 - PowerShell
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
Threat Hunting queries of multiple platforms
This solution accelerator provides the architecture and working solution for real-time intelligence for operations. Key features include real-time dashboard, anomaly detection, and fabric data agent.
This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.
Overnight AI monitoring for D365 Finance & Operations — 7 agents, Azure App Insights, Claude Code , Copilot Cowork
Cloud-based SOC environment using Microsoft Sentinel, Azure Arc, KQL, and Windows Security Events for threat detection and incident monitoring.
KQL Collection
Threat hunt for unauthorized TOR browser installation and use on a workstation using Microsoft Defender for Endpoint and KQL. Traces file, process, and network evidence with a full timeline, mapped to MITRE ATT&CK.
Comprehensive KQL query reference for Microsoft Defender XDR and Azure Sentinel, optimized for Context7 integration
Documenting my threat hunting projects and experience as a Cybersecurity Analyst during my internship at LOGs N' PACIFIC. For educational purposes only.
Cloud-based honeynet and SIEM lab built in Microsoft Azure using Microsoft Sentinel, Log Analytics Workspace, and attack telemetry visualization.
Hands-on Azure SOC simulation project focused on Microsoft Sentinel, threat detection engineering, log ingestion pipelines, KQL-based analytics, custom telemetry onboarding, and real-world SOC monitoring workflows using Windows & Linux virtual machines.
A curated collection of SOC investigation case files demonstrating end-to-end incident analysis, KQL-driven detection, and attack timeline reconstruction using Microsoft Sentinel.
Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.
Zero Trust IAM pipeline on Microsoft Entra ID: Graph API automation, PowerShell governance scripts, Logic Apps workflows, audit log streaming & Microsoft Sentinel threat detection.
A beginner-friendly project that demonstrates how to set up a Windows Server 2019 VM in Hyper-V, connect it to Azure using Azure Arc, and collect event logs into Microsoft Sentinel for security monitoring and analysis using KQL.
KQL Queries for Microsoft Sentinel and Microsoft Defender XDR
Add a description, image, and links to the kql-queries topic page so that developers can more easily learn about it.
To associate your repository with the kql-queries topic, visit your repo's landing page and select "manage topics."