Stars
Sample queries and data as part of the Microsoft Press book, The Definitive Guide to KQL
This repo aims to help you decipher the UAL from a Digital Forensics & Incident Response (DFIR) perspective. The UAL is the Microsoft 365 Unified Audit Log.
A collection of essential and foundational cybersecurity knowledge, thoughtfully organized for easy comprehension.
Repository of attack and defensive information for Business Email Compromise investigations
A tool for checking if MFA is enabled on multiple Microsoft Services
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Small and highly portable detection tests based on MITRE's ATT&CK.
A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel
Collection of awesome KQL queries for use in Portal and via PowerShell - by @JesseLoudon