A collection of useful KQL (Kusto Query Language) queries for security monitoring and threat detection.
- Threat Detection – Queries for detecting suspicious activity.
- Threat Hunting – Proactive queries mapped to MITRE ATT&CK.
- Network – Queries for network analysis and monitoring.
- Windows – Queries for Windows event log analysis.
- Identity – Queries for user behavior and IAM monitoring.
- Endpoint – Queries for endpoint monitoring.
- Cloud – Azure-specific queries.
These queries are primarily used with:
- Microsoft Sentinel
- Microsoft Defender
- Elasticsearch
- Wazuh
MIT