8000
Skip to content
#

kql-threathunting

Here are 31 public repositories matching this topic...

A Microsoft Sentinel SOC homelab in Azure, where I built and validated a basic cloud SOC workflow: data onboarding, detection, investigation, and visualization. It demonstrates practical blue-team skills in SIEM operations, KQL-based threat hunting, watchlist enrichment, and workbook reporting.

  • Updated Jun 2, 2026

Level II cybersecurity investigation portfolio built through KC7 Cyber. Extends KQL-based security analysis into networking, ransomware-as-a-service, supply-chain security, and industrial control system (ICS) investigations, with documented case analysis and investigative queries.

  • Updated Aug 19, 2026
  • HTML

Improve this page

Add a description, image, and links to the kql-threathunting topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the kql-threathunting topic, visit your repo's landing page and select "manage topics."

Learn more

0