32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
-
Updated
Aug 1, 2026
32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
Microsoft Sentinel, SIEM, SOAR, KQL, SOC Operations: Explore cloud-native security monitoring, threat detection, incident investigation, and automated response workflows.
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.
Microsoft Sentinel purple team detection engineering using Atomic Red Team, Sysmon, KQL, and MITRE ATT&CK.
A completely free, AI-powered assistant that translates natural language SOC analyst questions into precise Splunk SPL, Elastic KQL, Microsoft Sentinel KQL, and Wazuh SIEM queries. Built for threat hunters.
End-to-end SOC incident response lab using Microsoft Sentinel, KQL, TheHive, and Docker to detect, triage, investigate, document, and respond to suspicious authentication activity
This repository contains demos and guides on how to setup Sentinel for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.
Microsoft Sentinel cloud SIEM lab - deployed Azure VM, ingested Windows Security Events via AMA, wrote KQL queries to detect brute force attacks and failed logins in real time. Replicates L1 SOC analyst workflows.
Scenario-driven hands-on KQL practice and investigation query notes actively updated. Current Rank 180 out of 150K people globally
Add a description, image, and links to the microsoft-sentinel-kql topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-sentinel-kql topic, visit your repo's landing page and select "manage topics."