Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Oct 5, 2026 - PowerShell
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
Threat Hunting queries of multiple platforms
This solution accelerator provides the architecture and working solution for real-time intelligence for operations. Key features include real-time dashboard, anomaly detection, and fabric data agent.
This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.
Self-hosted OpenTelemetry viewer in a single binary — traces, metrics & logs with a beautiful web UI. OTLP in, DuckDB inside.
Overnight AI monitoring for D365 Finance & Operations — 7 agents, Azure App Insights, Claude Code , Copilot Cowork
Cloud-based SOC environment using Microsoft Sentinel, Azure Arc, KQL, and Windows Security Events for threat detection and incident monitoring.
KQL Collection
Hybrid Active Directory SOC lab using Azure Arc, Microsoft Sentinel, Sysmon, KQL, custom detections, threat hunting, incident response and SOAR automation.
Awesome Kusto Query Language (KQL)
Comprehensive KQL query reference for Microsoft Defender XDR and Azure Sentinel, optimized for Context7 integration
Threat hunt for unauthorized TOR browser installation and use on a workstation using Microsoft Defender for Endpoint and KQL. Traces file, process, and network evidence with a full timeline, mapped to MITRE ATT&CK.
Cloud-based honeynet and SIEM lab built in Microsoft Azure using Microsoft Sentinel, Log Analytics Workspace, and attack telemetry visualization.
Hands-on Azure SOC simulation project focused on Microsoft Sentinel, threat detection engineering, log ingestion pipelines, KQL-based analytics, custom telemetry onboarding, and real-world SOC monitoring workflows using Windows & Linux virtual machines.
Hybrid SIEM evaluation — Microsoft Sentinel + KQL, live-compared against an existing Wazuh SOC lab
Synthetic SOC / Blue Team credential access detection lab with MITRE ATT&CK mapping, SIEM detection logic, alert triage notes, false-positive handling, detection tuning, and dashboard reporting.
Zero Trust IAM pipeline on Microsoft Entra ID: Graph API automation, PowerShell governance scripts, Logic Apps workflows, audit log streaming & Microsoft Sentinel threat detection.
To associate your repository with the kql-queries topic, visit your repo's landing page and select "manage topics."