KQL for Azure Resource Manager and AppID search
☆23Aug 15, 2024Updated last year
Alternatives and similar repositories for kql
Users that are interested in kql are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Random Powershell scripts☆13Feb 13, 2024Updated 2 years ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Jun 22, 2026Updated last week
- ☆11Mar 29, 2022Updated 4 years ago
- Sharing my KQL queries for Azure Sentinel☆222Jun 13, 2026Updated 2 weeks ago
- Microsoft Entra ID App Audit Solution (AADAppAudit)☆84Aug 28, 2024Updated last year
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- PowerShell module to help getting tokens using managed identities☆17Dec 29, 2024Updated last year
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- Workflows for scheduled export of settings from an Azure AD tenant☆16Jun 19, 2026Updated last week
- MISP to Microsoft Defender integration☆17Jun 19, 2026Updated last week
- Automatic Microsoft Sentinel Deployment☆16Apr 1, 2025Updated last year
- Sentinel Threat Intelligence Upload Toolkit☆18Jul 15, 2024Updated last year
- Extensible Azure Security Tool - Documentation☆83Jun 1, 2023Updated 3 years ago
- A collection of Microsoft Sentinel workbooks and analytics rules.☆111Feb 8, 2024Updated 2 years ago
- Think of this PS-module as a helper for Microsoft Graph version-management, connectivity and data management using Microsoft Graph.☆15Apr 28, 2025Updated last year
- End-to-end encrypted email - Proton Mail • AdSpecial offer: 40% Off Yearly / 80% Off First Month. All Proton services are open source and independently audited for security.
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆65Mar 30, 2026Updated 3 months ago
- MS Entra ID Protection Guidance☆22Apr 2, 2024Updated 2 years ago
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated 11 months ago
- Collection of Microsoft Identity Threat Detection and Response resources.☆54Jun 1, 2026Updated 3 weeks ago
- PDump is a project for dumping leaked credentials from DEHASHED☆17Jan 21, 2024Updated 2 years ago
- A guide to using Azure Data Explorer and KQL for DFIR☆124May 16, 2022Updated 4 years ago
- Sharing presentation slides and workbook templates that can be useful to others to learn more about Azure Active Directory!☆21Aug 23, 2024Updated last year
- ☆93Jan 10, 2024Updated 2 years ago
- Tools for Microsoft cloud fans☆376Nov 26, 2024Updated last year
- Wordpress hosting with auto-scaling - Free Trial Offer • AdFully Managed hosting for WordPress and WooCommerce businesses that need reliable, auto-scalable performance. Cloudways SafeUpdates now available.
- A hackathon idea to hide sensitive information in the Azure Portal☆145May 22, 2026Updated last month
- ☆19Dec 18, 2024Updated last year
- A WDAC configuration repository with the sole intention of enriching MDE☆30Jun 18, 2025Updated last year
- You wonder how to manage your travelers ? In this scenario we describe how to manage them with Identity Governance and Conditional Access…☆11Mar 20, 2024Updated 2 years ago
- This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deployin…☆17Mar 10, 2023Updated 3 years ago
- A Post-exploitation Toolset for Interacting with the Microsoft Graph API☆16Nov 16, 2023Updated 2 years ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆69Apr 1, 2026Updated 2 months ago
- Share your own Graph PowerShell samples in the Discussions tab.☆80Jul 4, 2023Updated 2 years ago
- Deploy open-source AI quickly and easily - Special Bonus Offer • AdRunpod Hub is built for open source. One-click deployment and autoscaling endpoints without provisioning your own infrastructure.
- Discover a curated collection of scripts for Microsoft Azure and Microsoft 365 in this repository. Tailored for efficiency and automation…☆39Oct 21, 2025Updated 8 months ago
- Script and stuff for use in my blogposts☆18Feb 19, 2025Updated last year
- Azure AD Incident Response☆28Oct 8, 2021Updated 4 years ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆139Jun 18, 2026Updated last week
- Azure Resource Inventory .NET Tool - Inventories and documents Azure Tenant resources☆32Jun 23, 2026Updated last week
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 3 months ago
- ☆68Apr 13, 2023Updated 3 years ago