{"repo":"alexverboon/Hunting-Queries-Detection-Rules","free":true,"listed":false,"github":"https://github.com/alexverboon/Hunting-Queries-Detection-Rules","clone":"git clone https://github.com/alexverboon/Hunting-Queries-Detection-Rules.git","description":"KQL Queries. Microsoft Defender, Microsoft Sentinel","language":null,"stars":207,"topics":["detection","kql","security","sentinel","dfir","hunting","defenderforendpoint","defenderforidentity","azure","azuread"],"license":"BSD-3-Clause","category":"security-tools","readme_excerpt":"KQL Sentinel & Defender queries KQL for Defender XDR, Microsoft Sentinel & other Microsoft Solutions The purpose of this repository is to share KQL queries that can be used by anyone and are understandable. These queries are intended to increase detection coverage through the logs of Microsoft Security products. Not all suspicious activities generate an alert by default, but many of those activities can be made detectable through the logs. These queries include Detection Rules, Hunting Queries and Visualisations. Anyone is free to use the queries. If you have any questions feel free to reach out to me on twitter @AlexVerboon. Presenting this material as your own is illegal and forbidden. A reference to Twitter @AlexVerboon or Github AlexVerboon is much appriciated when sharing or using the content. Credits @BertJanCyber - The content structure of this repository was adopted from Bert-Jan's KQL repository KQL Queries: While I have personally authored the majority of the KQL queries stored here, it is important to note that as I continue to collect queries in my daily work, the repository may also include KQL code contributed by others. I make every effort to acknowledge and credit the original creators whenever I have information about them. In addition to the queries I have written myself, it's worth mentioning that certain queries within the repository may be direct copies of those found in Microsoft's online documentation and blog posts. KQL Categories The queries in this r","default_branch":null,"files":null,"tree":[],"storefront":"/r/alexverboon","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/alexverboon/Hunting-Queries-Detection-Rules/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}