{"repo":"vinsk0h/KQLab","free":true,"listed":false,"github":"https://github.com/vinsk0h/KQLab","clone":"git clone https://github.com/vinsk0h/KQLab.git","description":"The self-hosted KQL query management platform for SOC teams","language":"JavaScript","stars":22,"topics":["blue-team","detection-engineering","kql","microsoft-defender","microsoft-sentinel","mitre-attack","security","siem","soc","threat-hunting"],"license":"MIT","category":"security-tools","readme_excerpt":"The self-hosted KQL query management platform for SOC teams Passphrase authentication · AES-256-GCM encryption · MITRE ATT&CK mapping · Investigation tracking --- Why KQLab? SOC analysts accumulate hundreds of KQL queries across Microsoft Defender and Azure Sentinel. They live in Notepad, Notion, shared drives — undocumented, unsearchable, scattered across teams. KQLab centralizes them in a self-hosted, encrypted platform : team-based sharing, MITRE ATT&CK mapping, investigation tracking, and passphrase authentication — with zero cloud dependency and zero vendor lock-in. Deploy it on your infrastructure. Own your data. --- Features Feature Description --- --- Passphrase authentication Login + scrypt-hashed passphrase — no plain-text passwords ever stored or transmitted Encrypted database AES-256-GCM with scrypt KDF, unique salt per stored value Multi-language queries Write queries in KQL (Defender/Sentinel), DSL (Elastic/ELK), or SPL (Splunk) Team scoping Queries and folders isolated per team MITRE ATT&CK mapping Tag queries by tactic and technique SANS IR Cycle mapping Map queries to PICERL incident response phases Variable resolver Fill {{variables}} before copying a query to the clipboard Environment compatibility Check query compatibility against your Defender/Sentinel tables Investigations Track active incidents — IoCs, timeline, findings, reports Report export Generate PDF, DOCX, and HTML investigation reports Report templates Customizable section-based report templates","default_branch":null,"files":null,"tree":[],"storefront":"/r/vinsk0h","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/vinsk0h/KQLab/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}