KQL for Azure Resource Manager and AppID search
☆23Aug 15, 2024Updated last year
Alternatives and similar repositories for kql
Users that are interested in kql are comparing it to the libraries listed below
Sorting:
- Random Powershell scripts☆13Feb 13, 2024Updated 2 years ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Feb 24, 2026Updated 3 weeks ago
- ☆11Mar 29, 2022Updated 3 years ago
- Sharing my KQL queries for Azure Sentinel☆208Feb 9, 2026Updated last month
- Microsoft Entra ID App Audit Solution (AADAppAudit)☆84Aug 28, 2024Updated last year
- PowerShell module to help getting tokens using managed identities☆17Dec 29, 2024Updated last year
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆21Nov 15, 2024Updated last year
- Workflows for scheduled export of settings from an Azure AD tenant☆15Mar 3, 2026Updated 2 weeks ago
- MISP to Microsoft Defender integration☆17Feb 24, 2026Updated 3 weeks ago
- Automatic Microsoft Sentinel Deployment☆16Apr 1, 2025Updated 11 months ago
- Sentinel Threat Intelligence Upload Toolkit☆18Jul 15, 2024Updated last year
- ☆22Aug 29, 2023Updated 2 years ago
- Extensible Azure Security Tool - Documentation☆83Jun 1, 2023Updated 2 years ago
- A collection of Microsoft Sentinel workbooks and analytics rules.☆111Feb 8, 2024Updated 2 years ago
- Azure AiTM Function PoC to phish Entra ID Credentials☆28Nov 21, 2025Updated 4 months ago
- Think of this PS-module as a helper for Microsoft Graph version-management, connectivity and data management using Microsoft Graph.☆14Apr 28, 2025Updated 10 months ago
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆63Jul 27, 2025Updated 7 months ago
- MS Entra ID Protection Guidance☆22Apr 2, 2024Updated last year
- Sharing presentation slides and workbook templates that can be useful to others to learn more about Azure Active Directory!☆21Aug 23, 2024Updated last year
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated 7 months ago
- Collection of Microsoft Identity Threat Detection and Response resources.☆52Mar 1, 2026Updated 2 weeks ago
- PDump is a project for dumping leaked credentials from DEHASHED☆17Jan 21, 2024Updated 2 years ago
- Azure AD Security controls check.☆16Feb 25, 2023Updated 3 years ago
- A guide to using Azure Data Explorer and KQL for DFIR☆124May 16, 2022Updated 3 years ago
- Azure Feed Newsletters☆13Sep 23, 2023Updated 2 years ago
- ☆90Jan 10, 2024Updated 2 years ago
- A hackathon idea to hide sensitive information in the Azure Portal☆134Oct 11, 2024Updated last year
- Tools for Microsoft cloud fans☆373Nov 26, 2024Updated last year
- ☆19Dec 18, 2024Updated last year
- A WDAC configuration repository with the sole intention of enriching MDE☆30Jun 18, 2025Updated 9 months ago
- You wonder how to manage your travelers ? In this scenario we describe how to manage them with Identity Governance and Conditional Access…☆11Mar 20, 2024Updated 2 years ago
- This repository is used by FalconForce to release parts of the internal tools used for maintaining, validating and automatically deployin…☆18Mar 10, 2023Updated 3 years ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 2 years ago
- Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting☆68Dec 7, 2025Updated 3 months ago
- Share your own Graph PowerShell samples in the Discussions tab.☆80Jul 4, 2023Updated 2 years ago
- Discover a curated collection of scripts for Microsoft Azure and Microsoft 365 in this repository. Tailored for efficiency and automation…☆36Oct 21, 2025Updated 5 months ago
- Script and stuff for use in my blogposts☆18Feb 19, 2025Updated last year
- Azure AD Incident Response☆27Oct 8, 2021Updated 4 years ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆135Updated this week