There are 10 repositories under kql topic.
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Hunting queries and detections
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
KQL Queries. Microsoft Defender, Microsoft Sentinel
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.
MDATP
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Repository with Sample KQL Query examples for Threat Hunting
My personal work with Copilot for Security
KQL Queries. Microsoft Defender, Microsoft Sentinel
Kirby's Query Language API combines the flexibility of Kirby's data structures, the power of GraphQL and the simplicity of REST.
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
Repository with Sentinel Analytics Rules, Hunting Queries and helpful external data sources.
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.
C# KQL query engine with flexible I/O layers and visualization
example queries for learning the kusto language
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
Collection of awesome KQL queries for use in Portal and via PowerShell - by @JesseLoudon
Hunting Queries for Defender ATP
Repository for SOC analysts, queries to investigate, advanced hunting, sites for analysis, malware samples, courses to improve skills, IOC and monitoring.
Sentinel Analytics Rule converter PowerShell module
Ian Hanley's deceptively simple KQL queries.
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs
Welcome to the Cloud Security Toolkit repository, your all-in-one destination for cutting-edge cloud security resources! Whether you're diving into offensive strategies, mastering threat hunting, or bolstering your blue-team defenses, this repo has you covered.
A self-contained execution engine for the Kusto Query Language (KQL) written in C#
Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
Microsoft Fabric Real-time Analytics flight streaming
sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Log Analytics Workspaces.
A collection of sample dashboards, custom labels, mustaches, SQL scripts and PowerShell scripts to help you get the most out of SquaredUp. #community-powered