A comprehensive collection of Kusto Query Language (KQL) queries designed for security professionals to detect, hunt, and respond to cyber threats and incidents, covering areas like Detections, Digital Forensics, and Hunting by Entity (Device, Email, User), and including operational queries for incident management and analytics tuning.
☆18Dec 28, 2025Updated 8 months ago
Alternatives and similar repositories for Incident-Response-and-Threat-Hunting
Users that are interested in Incident-Response-and-Threat-Hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- ☆51Updated this week
- Volatility 3 Plugins☆21Oct 3, 2022Updated 3 years ago
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆13Jan 24, 2026Updated 7 months ago
- Sentinel BEC IR☆14Aug 18, 2022Updated 4 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Scanner for Log4j RCE CVE-2021-44228☆11Jul 6, 2022Updated 4 years ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- ☆15Mar 12, 2025Updated last year
- Tool to enumerate unregistered reply URLs for single and multitenant apps in Azure☆16Jan 23, 2025Updated last year
- ☆46Apr 10, 2024Updated 2 years ago
- ☆31Oct 28, 2024Updated last year
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- ☆43May 22, 2021Updated 5 years ago
- Scripts and Samples for the KQL Pluralsight Course Created in 2022☆23Jan 6, 2023Updated 3 years ago
- Bare Metal GPUs on DigitalOcean Gradient AI • AdPurpose-built for serious AI teams training foundational models, running large-scale inference, and pushing the boundaries of what's possible.
- A collection of practical SOC investigation playbooks for common security alerts including brute-force attacks, phishing incidents, suspi…☆20Mar 15, 2026Updated 6 months ago
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆82Sep 2, 2026Updated 2 weeks ago
- This is a collection of Security Baselines that I use in my virtual lab environment.☆23Mar 11, 2020Updated 6 years ago
- Defcon 28 - Red Team Village - Applied Purple Teaming - Why Can't We Be Friends☆26Aug 9, 2020Updated 6 years ago
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆17Jun 9, 2026Updated 3 months ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆124Jan 18, 2026Updated 8 months ago
- convert youtube channel to audio + video podcast☆11May 8, 2020Updated 6 years ago
- ☆11Aug 15, 2024Updated 2 years ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆143Sep 9, 2026Updated last week
- GPU virtual machines on DigitalOcean Gradient AI • AdGet to production fast with high-performance AMD and NVIDIA GPUs you can spin up in seconds. The definition of operational simplicity.
- ☆33Jun 27, 2022Updated 4 years ago
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆18Sep 4, 2026Updated 2 weeks ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- A broken-by-design Azure environment to practice and train security skills in the cloud domain.☆29Oct 20, 2025Updated 10 months ago
- A PoC that uses the DirSync protocol to poll Active Directory for changes☆13Aug 16, 2020Updated 6 years ago
- A library of reference materials, tools, and other resources to aid threat profiling, threat quantification, and cyber adversary defense☆108Dec 13, 2023Updated 2 years ago
- The funny insult device for everyday use.☆16May 10, 2026Updated 4 months ago
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆69Apr 1, 2026Updated 5 months ago
- HoneyDB Python Module☆16Aug 30, 2026Updated 2 weeks ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- Per Country IP Lists based on the GeoLite2 Database☆18Apr 18, 2015Updated 11 years ago
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated last year
- Rules I have researched for Microsoft Sentinel in my spare time. If someone wants to offer me a job I am open. Anyone can use this. Pleas…☆17Mar 29, 2026Updated 5 months ago
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆176Updated this week
- ☆18Jul 20, 2024Updated 2 years ago
- F-Secure Lightweight Acqusition for Incident Response (FLAIR)☆16Jul 5, 2021Updated 5 years ago
- Get a stable, canonical version of any URL, with DNS and HTTPS checks, redirects, tracker stripping, and canonical link extraction!☆13Updated this week