A comprehensive collection of Kusto Query Language (KQL) queries designed for security professionals to detect, hunt, and respond to cyber threats and incidents, covering areas like Detections, Digital Forensics, and Hunting by Entity (Device, Email, User), and including operational queries for incident management and analytics tuning.
☆16Dec 28, 2025Updated 6 months ago
Alternatives and similar repositories for Incident-Response-and-Threat-Hunting
Users that are interested in Incident-Response-and-Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sigma Queries turned into KQL for Defender using pysigma☆12Mar 29, 2026Updated 3 months ago
- Volatility 3 Plugins☆21Oct 3, 2022Updated 3 years ago
- Monitor/Archive of Azure IAM (Role Definitions and Provider Operations). Tweets at https://twitter.com/maiam_bot☆10Updated this week
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆13Jan 24, 2026Updated 5 months ago
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- Scanner for Log4j RCE CVE-2021-44228☆11Jul 6, 2022Updated 4 years ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- ☆15Mar 12, 2025Updated last year
- Tool to enumerate unregistered reply URLs for single and multitenant apps in Azure☆15Jan 23, 2025Updated last year
- ☆46Apr 10, 2024Updated 2 years ago
- Configurations to implement Wazuh☆13Nov 28, 2022Updated 3 years ago
- ☆31Oct 28, 2024Updated last year
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- ☆43May 22, 2021Updated 5 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Scripts and Samples for the KQL Pluralsight Course Created in 2022☆23Jan 6, 2023Updated 3 years ago
- Python CLI covering the FileScan.IO API - enabling automatic interaction with www.filescan.io or private instances☆22Jul 15, 2025Updated last year
- A collection of practical SOC investigation playbooks for common security alerts including brute-force attacks, phishing incidents, suspi…☆20Mar 15, 2026Updated 4 months ago
- This is a collection of Security Baselines that I use in my virtual lab environment.☆23Mar 11, 2020Updated 6 years ago
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆82Jul 11, 2026Updated last week
- Gradient boosting model for predicting credit default risk on Kaggle competition☆18Nov 30, 2020Updated 5 years ago
- ☆47Updated this week
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 5 years ago
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated last month
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- ☆11Aug 15, 2024Updated last year
- ☆71Apr 20, 2026Updated 3 months ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆141Updated this week
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 4 months ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- A PoC that uses the DirSync protocol to poll Active Directory for changes☆13Aug 16, 2020Updated 5 years ago
- ☆33Jun 27, 2022Updated 4 years ago
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆17May 13, 2026Updated 2 months ago
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- Generate realistic-looking fake meetings to fill up your Microsoft Outlook/Apple/Google calendar. Available in Python and PowerShell.☆32Jan 17, 2024Updated 2 years ago
- AI featured threat modeling and security review action☆48Nov 17, 2024Updated last year
- Automatisierung von Amass + Nmap + Nikto.☆14Oct 13, 2022Updated 3 years ago
- A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense☆105Dec 13, 2023Updated 2 years ago
- KQL Queries for Advanced Hunting / Log Analytics☆13Jan 29, 2026Updated 5 months ago
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆69Apr 1, 2026Updated 3 months ago
- HoneyDB Python Module☆15Jul 7, 2026Updated last week