A comprehensive collection of Kusto Query Language (KQL) queries designed for security professionals to detect, hunt, and respond to cyber threats and incidents, covering areas like Detections, Digital Forensics, and Hunting by Entity (Device, Email, User), and including operational queries for incident management and analytics tuning.
☆18Dec 28, 2025Updated 9 months ago
Alternatives and similar repositories for Incident-Response-and-Threat-Hunting
Users that are interested in Incident-Response-and-Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Sigma Queries turned into KQL for Defender using pysigma☆12Mar 29, 2026Updated 6 months ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- Monitor/Archive of Azure IAM (Role Definitions and Provider Operations). Tweets at https://twitter.com/maiam_bot☆10Updated this week
- ☆55Updated this week
- Volatility 3 Plugins☆21Oct 3, 2022Updated 4 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆13Jan 24, 2026Updated 8 months ago
- Sentinel BEC IR☆14Aug 18, 2022Updated 4 years ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- ☆15Mar 12, 2025Updated last year
- Tool to enumerate unregistered reply URLs for single and multitenant apps in Azure☆17Jan 23, 2025Updated last year
- ☆46Apr 10, 2024Updated 2 years ago
- Configurations to implement Wazuh☆13Nov 28, 2022Updated 3 years ago
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- ☆43May 22, 2021Updated 5 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Scripts and Samples for the KQL Pluralsight Course Created in 2022☆23Jan 6, 2023Updated 3 years ago
- A collection of practical SOC investigation playbooks for common security alerts including brute-force attacks, phishing incidents, suspi…☆20Mar 15, 2026Updated 6 months ago
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆82Sep 2, 2026Updated last month
- Python Machine Learning Tutorials - Scikit-Learn☆22Nov 6, 2024Updated last year
- This is a collection of Security Baselines that I use in my virtual lab environment.☆23Mar 11, 2020Updated 6 years ago
- Gradient boosting model for predicting credit default risk on Kaggle competition☆18Nov 30, 2020Updated 5 years ago
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 6 years ago
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated 4 months ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆124Jan 18, 2026Updated 8 months ago
- AI Agents on DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- ☆70Apr 20, 2026Updated 5 months ago
- convert youtube channel to audio + video podcast☆11May 8, 2020Updated 6 years ago
- ☆11Aug 15, 2024Updated 2 years ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆143Sep 9, 2026Updated last month
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 6 months ago
- ☆33Jun 27, 2022Updated 4 years ago
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆18Sep 4, 2026Updated last month
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- A broken-by-design Azure environment to practice and train security skills in the cloud domain.☆29Oct 20, 2025Updated 11 months ago
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- A PoC that uses the DirSync protocol to poll Active Directory for changes☆13Aug 16, 2020Updated 6 years ago
- Generate realistic-looking fake meetings to fill up your Microsoft Outlook/Apple/Google calendar. Available in Python and PowerShell.☆32Jan 17, 2024Updated 2 years ago
- A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense☆108Dec 13, 2023Updated 2 years ago
- The funny insult device for everyday use.☆16May 10, 2026Updated 4 months ago
- KQL Queries for Advanced Hunting / Log Analytics☆13Jan 29, 2026Updated 8 months ago
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆69Apr 1, 2026Updated 6 months ago
- OptKeras: wrapper around Keras and Optuna for hyperparameter optimization☆29Apr 1, 2020Updated 6 years ago