{"repo":"Bert-JanP/Hunting-Queries-Detection-Rules","free":true,"listed":false,"github":"https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules","clone":"git clone https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules.git","description":"KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.","language":"Python","stars":1732,"topics":["azure","defender-for-endpoint","dfir","kql","sentinel","threat-hunting","vulnerability-management","zero-day","blueteam","cybersecurity"],"license":"BSD-3-Clause","category":"security-tools","readme_excerpt":"KQL Sentinel & Defender queries KQL for Defender For Endpoint & Microsoft Sentinel The purpose of this repository is to share KQL queries that can be used by anyone and are understandable. These queries are intended to increase detection coverage through the logs of Microsoft Security products. Not all suspicious activities generate an alert by default, but many of those activities can be made detectable through the logs. These queries include Detection Rules, Hunting Queries and Visualisations. Anyone is free to use the queries. If you have any questions feel free to reach out to me on Twitter @BertJanCyber. Presenting this material as your own is illegal and forbidden. A reference to Twitter @BertJanCyber or Github @Bert-JanP is much appreciated when sharing or using the content. KQL Blogs More detailed KQL information can be found on my blog page: https://kqlquery.com. Some KQL related blogs: - KQL Functions For Security Operations - KQL Functions For Network Operations - Incident Response Part 1: IR on Microsoft Security Incidents (KQL edition) - Incident Response Part 2: What about the other logs? - From Threat Report to (KQL) Hunting Query - Prioritize Vulnerabilities Using The CISA Known Exploited Vulnerabilities Catalog - KQL Security Sources - 2024 Update - Detecting Post-Exploitation Behaviour - Investigating Microsoft Graph Activity Logs - Audit Defender XDR Activities - Use Cases For Sentinel Summary Rules - Unleash The Power Of DeviceTvmInfoGathering For Sentinel","default_branch":null,"files":null,"tree":[],"storefront":"/r/Bert-JanP","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Bert-JanP/Hunting-Queries-Detection-Rules/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}