KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
-
Updated
Apr 13, 2026 - Python
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Hunting queries and detections
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
MDATP
PowerShell-based Automation of Defender for Endpoint
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.
ASR Configurator, Essentials and Atomic Testing
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC
Microsoft Intune Custom Compliance
This repository will describe the details surrounding the SIEM (wazuh) mini project, which will cover all aspects of topology design, deployment, rules, integration, and fine tune.
PowerShell + WPF GUI for managing DUDE automation (Dynamic User & Device Enumeration)
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
Microsoft Defender for Endpoint PowerShell module
Python for Security is the home of all open source Python projects that can integrate with Microsoft Technologies.
This repository contains detection and threat hunting queries created by NVISO’s CSIRT and SOC teams.
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
A set of importable Intune policies that simplify onboarding/offboarding MacOS devices to/from Defender for Business/Endpoint.
Repo includes KQL queries that you can run in your Azure Log Analyics environment.
Add a description, image, and links to the defender-for-endpoint topic page so that developers can more easily learn about it.
To associate your repository with the defender-for-endpoint topic, visit your repo's landing page and select "manage topics."