🔍 Discover KQL queries designed for Microsoft Sentinel and Defender XDR to enhance your security monitoring and incident response capabilities.
-
Updated
Nov 8, 2025
🔍 Discover KQL queries designed for Microsoft Sentinel and Defender XDR to enhance your security monitoring and incident response capabilities.
KQL-Queries 🐙 provides ready KQL scripts for Microsoft Defender XDR threat hunting, helping security teams detect, investigate, and respond to threats.
KQL Queries. Microsoft Defender, Microsoft Sentinel
Completed a Malware Analysis and Reverse Engineering project where I analyzed a malware sample in an isolated environment, monitored its behavior, extracted file metadata, and created custom YARA rules and IoCs. Automated reporting with Python streamlined the analysis and improved efficiency.
KQL Queries for Microsoft Sentinel and Microsoft Defender XDR
Configure and deploy AWS GuardDuty.
AWS GuardDuty service configuration and deployment
A simple, low-interaction MongoDB honeypot server in Python for easy network traffic monitoring
A simple, low-interaction PostgreSQL honeypot server in Python for easy network traffic monitoring
A simple, low-interaction SSH honeypot server in Python for easy network traffic monitoring
A simple, low-interaction LDAP honeypot server in Python for easy network traffic monitoring
A simple, low-interaction TELNET honeypot server in Python for easy network traffic monitoring
A simple, low-interaction FTP honeypot server in Python for easy network traffic monitoring
A simple, low-interaction SIP honeypot server in Python for easy network traffic monitoring
A simple, low-interaction DNS honeypot server in Python for easy network traffic monitoring
A simple, low-interaction NTP honeypot server in Python for easy network traffic monitoring
A simple, low-interaction HTTPS honeypot server in Python for easy network traffic monitoring
A simple, low-interaction HTTP honeypot server in Python for easy network traffic monitoring
This is an artificial intelligence (ML and DL) project for network security which works by detecting threats and uses attack classification and then implements self-healing mechanisms
Advanced PDF Analysis & Disarm Tool is a robust Python-based utility designed to scan, analyze, and neutralize potentially malicious elements in PDF files.
Add a description, image, and links to the threatdetection topic page so that developers can more easily learn about it.
To associate your repository with the threatdetection topic, visit your repo's landing page and select "manage topics."