Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

26 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

KQL Queries

A collection of useful KQL (Kusto Query Language) queries for security monitoring and threat detection.

Contents

  • Threat Detection – Queries for detecting suspicious activity.
  • Threat Hunting – Proactive queries mapped to MITRE ATT&CK.
  • Network – Queries for network analysis and monitoring.
  • Windows – Queries for Windows event log analysis.
  • Identity – Queries for user behavior and IAM monitoring.
  • Endpoint – Queries for endpoint monitoring.
  • Cloud – Azure-specific queries.

Usage

These queries are primarily used with:

  • Microsoft Sentinel
  • Microsoft Defender
  • Elasticsearch
  • Wazuh

License

MIT

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors