A comprehensive collection of Kusto Query Language (KQL) queries designed for security professionals to detect, hunt, and respond to cyber threats and incidents, covering areas like Detections, Digital Forensics, and Hunting by Entity (Device, Email, User), and including operational queries for incident management and analytics tuning.
☆16Dec 28, 2025Updated 7 months ago
Alternatives and similar repositories for Incident-Response-and-Threat-Hunting
Users that are interested in Incident-Response-and-Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sigma Queries turned into KQL for Defender using pysigma☆12Mar 29, 2026Updated 4 months ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- Volatility 3 Plugins☆21Oct 3, 2022Updated 3 years ago
- ☆47Updated this week
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆13Jan 24, 2026Updated 6 months ago
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- ☆15Mar 12, 2025Updated last year
- Tool to enumerate unregistered reply URLs for single and multitenant apps in Azure☆15Jan 23, 2025Updated last year
- ☆46Apr 10, 2024Updated 2 years ago
- Configurations to implement Wazuh☆13Nov 28, 2022Updated 3 years ago
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- Scripts and Samples for the KQL Pluralsight Course Created in 2022☆23Jan 6, 2023Updated 3 years ago
- Python Machine Learning Tutorials - Scikit-Learn☆21Nov 6, 2024Updated last year
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆82Jul 11, 2026Updated 3 weeks ago
- A collection of practical SOC investigation playbooks for common security alerts including brute-force attacks, phishing incidents, suspi…☆20Mar 15, 2026Updated 4 months ago
- macOS Security Resources☆37Aug 15, 2025Updated 11 months ago
- This is a collection of Security Baselines that I use in my virtual lab environment.☆23Mar 11, 2020Updated 6 years ago
- Gradient boosting model for predicting credit default risk on Kaggle competition☆18Nov 30, 2020Updated 5 years ago
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 6 years ago
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated 2 months ago
- ☆71Apr 20, 2026Updated 3 months ago
- convert youtube channel to audio + video podcast☆11May 8, 2020Updated 6 years ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- ☆11Aug 15, 2024Updated last year
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆142Jul 29, 2026Updated last week
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 4 months ago
- ☆33Jun 27, 2022Updated 4 years ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- A broken-by-design Azure environment to practice and train security skills in the cloud domain.☆29Oct 20, 2025Updated 9 months ago
- A PoC that uses the DirSync protocol to poll Active Directory for changes☆13Aug 16, 2020Updated 5 years ago
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆17May 13, 2026Updated 2 months ago
- Generate realistic-looking fake meetings to fill up your Microsoft Outlook/Apple/Google calendar. Available in Python and PowerShell.☆32Jan 17, 2024Updated 2 years ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- AI featured threat modeling and security review action☆48Nov 17, 2024Updated last year
- Automatisierung von Amass + Nmap + Nikto.☆14Oct 13, 2022Updated 3 years ago
- KQL Queries for Advanced Hunting / Log Analytics☆13Jan 29, 2026Updated 6 months ago
- OptKeras: wrapper around Keras and Optuna for hyperparameter optimization☆29Apr 1, 2020Updated 6 years ago
- Per Country IP Lists based on the GeoLite2 Database☆18Apr 18, 2015Updated 11 years ago
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated last year
- Rules I have researched for Microsoft Sentinel in my spare time. If someone wants to offer me a job I am open. Anyone can use this. Pleas…☆17Mar 29, 2026Updated 4 months ago