KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
-
Updated
Nov 7, 2024
KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
Defender for Identity Technical Items
✨ A linting tool for working with Microsoft Sentinel & Defender Advanced Hunting KQL
Collection of KQL queries for sentinel and defender for organization wide monitoring
Add a description, image, and links to the advanced-hunting topic page so that developers can more easily learn about it.
To associate your repository with the advanced-hunting topic, visit your repo's landing page and select "manage topics."