Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Aug 19, 2026 - PowerShell
8000
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
Threat Hunting queries of multiple platforms
Kusto and Log Analytics MCP server help you execute a KQL (Kusto Query Language) query within an AI prompt, analyze, and visualize the data.
This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.
Detection rules and threat hunting queries in Defender XDR and Azure Sentinel
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
Maps Microsoft Defender XDR Schemas to a local Kustainer Data Explorer instance
AI-enhanced Azure SOC homelab for phishing detection & response, threat intelligence, and much more using Microsoft Sentinel, Defender XDR, and ANY.RUN.
This lab is inspired by concepts and guidance from Josh Madakor’s Cyber Range course.
A collection of Mitre ATT&CK aligned KQL detection, hunting, and audit queries for Defender XDR.
Built a honeypot database server with an open firewall and exposed it to the public internet for 4 days. 2 threat actors brute-forced it in 4 hours, exfiltrated data, and left a ransom note demanding 0.0135 BTC. Wrote 2 custom analytics rules in Sentinel (KQL) to detect initial access across 34 alerts and 2 incidents.
KQL Queries for Microsoft Sentinel and Microsoft Defender XDR
Find potential local privilege escalation on windows with KQL
A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.
To hunt for potential malicious extensions
In this repository, you will find KQL queries that can be executed in Defender EDR.
Level II cybersecurity investigation portfolio built through KC7 Cyber. Extends KQL-based security analysis into networking, ransomware-as-a-service, supply-chain security, and industrial control system (ICS) investigations, with documented case analysis and investigative queries.
This repository contains my labs for developing threat hunting skills by simulating real-world attack scenarios on Windows systems, focusing on system configuration tampering, unauthorised access detection, and network activity analysis.
Add a description, image, and links to the kql-threathunting topic page so that developers can more easily learn about it.
To associate your repository with the kql-threathunting topic, visit your repo's landing page and select "manage topics."