Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
-
Updated
Jul 1, 2025 - PowerShell
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
Defender for Identity Technical Items
Collection of KQL queries for sentinel and defender for organization wide monitoring
Add a description, image, and links to the advanced-hunting topic page so that developers can more easily learn about it.
To associate your repository with the advanced-hunting topic, visit your repo's landing page and select "manage topics."