HybridBrothers / Hunting-Queries-Detection-Rules
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
☆21Updated last week
Alternatives and similar repositories for Hunting-Queries-Detection-Rules:
Users that are interested in Hunting-Queries-Detection-Rules are comparing it to the libraries listed below
- ☆18Updated last year
- Repository with Hunting and Detection Queries for Microsoft Sentinel and Microsoft Defender XDR☆14Updated last month
- This repo aims to help you decipher the UAL from a Digital Forensics & Incident Response (DFIR) perspective. The UAL is the Microsoft 365…☆57Updated 10 months ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆20Updated last year
- ☆51Updated last month
- MDE Quickstart is a battle-tested MDE policy set designed to be restored with Intune Backup & Restore☆66Updated 2 years ago
- ☆82Updated last year
- ☆30Updated last week
- Ian Hanley's deceptively simple KQL queries.☆48Updated last week
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆142Updated last month
- Utilities for Microsoft Sentinel☆17Updated 4 months ago
- Content Repo for Demystifying KQL Tutorial Series☆68Updated 6 months ago
- All about Microsoft 365 Enterprise Mobility + Security (EMS)☆23Updated last year
- Misc. content for Microsoft Sentinel☆18Updated 11 months ago
- A collection of Microsoft Sentinel workbooks and analytics rules.☆105Updated last year
- ☆55Updated 3 weeks ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆36Updated 4 months ago
- ☆16Updated 6 months ago
- This tool is designed to assist you in analyzing issues related to Defender for Endpoint on your local endpoint. It offers a centralized …☆54Updated last month
- Microsoft Sentinel related content☆36Updated 2 months ago
- ☆29Updated 3 weeks ago
- Defender for Endpoint☆17Updated last year
- Implement a powerful Tiering Security Model in Microsoft Entra for your Cloud Administrator identities using Azure Automation.☆44Updated last month
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆18Updated 4 months ago
- ☆42Updated 11 months ago
- ☆24Updated 2 months ago
- Discover a curated collection of scripts for Microsoft Azure and Microsoft 365 in this repository. Tailored for efficiency and automation…☆30Updated last month
- Sharing presentation slides and workbook templates that can be useful to others to learn more about Azure Active Directory!☆20Updated 7 months ago
- ☆24Updated 2 months ago
- Sentinel Analytics Rule converter PowerShell module☆58Updated 2 months ago