A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Aug 28, 2025
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
AI-powered email threat analysis daemon — IMAP IDLE monitoring, SPF/DKIM/DMARC/DNSBL/URLhaus/VirusTotal enrichment, multi-provider AI (OpenAI/Anthropic/Ollama), Flask web UI, and full audit log.
Endpoint Detection & Response platform with kernel-level telemetry, behavioral analysis, and automated threat response
🏗️ Hands-on workshop to secure a serverless AWS application across seven defense-in-depth layers using AI-powered automation. Covers Cognito adaptive auth, WAF edge protection, VPC isolation, Lambda hardening with Kiro, Secrets Manager, DynamoDB encryption, and a Bedrock AI agent for GuardDuty incident response via EventBridge.
Add a description, image, and links to the threat-detecting topic page so that developers can more easily learn about it.
To associate your repository with the threat-detecting topic, visit your repo's landing page and select "manage topics."