A repo to hold KQL queries as part of my 100 days of KQL effort.
☆19Aug 5, 2026Updated 2 months ago
Alternatives and similar repositories for 100_days_of_kql_2026
Users that are interested in 100_days_of_kql_2026 are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- Microsoft Sentinel SIEM Log Source Analyzer☆30Updated this week
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or eve…☆290Jun 23, 2026Updated 3 months ago
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆31Aug 4, 2025Updated last year
- KQL Queries☆43Oct 2, 2026Updated last week
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- my MSTICpy practice and custom tools repository☆11Apr 23, 2025Updated last year
- A specialized environment for crafting, validating, and testing LimaCharlie detection rules☆15Sep 14, 2026Updated 3 weeks ago
- PowerShell tool for streamlined Microsoft Defender Advanced Hunting query management with GitHub Copilot integration☆21Aug 31, 2026Updated last month
- Community-driven PowerShell detection indicators☆45Jan 27, 2026Updated 8 months ago
- Digital forensics image that was prepared to cover a full Windows Forensics☆21Dec 26, 2023Updated 2 years ago
- ☆19Aug 24, 2026Updated last month
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆180Updated this week
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆124Jan 18, 2026Updated 8 months ago
- ☆18Jul 20, 2024Updated 2 years ago
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- ☆83Feb 4, 2026Updated 8 months ago
- Detection rules and threat hunting queries in Defender XDR and Azure Sentinel☆17Mar 13, 2026Updated 6 months ago
- A repository of Sysmon For Linux configuration modules☆17Oct 14, 2021Updated 4 years ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- This repository contains various public projects created by the owners of Hybrid Brothers☆21Nov 3, 2023Updated 2 years ago
- A hex viewer for the sleuths!☆20Nov 7, 2025Updated 11 months ago
- ☆55Updated this week
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆82Sep 2, 2026Updated last month
- A PowerShell module for the Defender XDR portal☆140Oct 1, 2026Updated last week
- Open source password manager - Proton Pass • AdSecurely store, share, and autofill your credentials with Proton Pass, the end-to-end encrypted password manager trusted by millions.
- Share Information about Microsoft Security Products☆153Updated this week
- KQL Queries. Microsoft Defender, Microsoft Sentinel☆934Oct 1, 2026Updated last week
- ☆35Oct 20, 2024Updated last year
- Golang C2 Client + PHP API Handler☆15Aug 1, 2023Updated 3 years ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- A schema-aware dataset and Claude AI skill for Microsoft Defender XDR Advanced Hunting.☆36May 6, 2026Updated 5 months ago
- ☆91Sep 25, 2026Updated 2 weeks ago
- Some IR notes☆17Jul 2, 2016Updated 10 years ago
- Cyber Threat Intelligence☆83Dec 7, 2025Updated 10 months ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Automating Cyber Threat Intelligence Reporting with Natural Language Generation☆15Jan 24, 2024Updated 2 years ago
- List with File Extensions used by Ransomware☆42Sep 24, 2026Updated 2 weeks ago
- A curated collection of DFIR skills and workflows for InfoSec practitioners.☆323May 14, 2026Updated 4 months ago
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Aug 17, 2026Updated last month
- Living off the land Data Exfiltration methods☆65May 9, 2026Updated 5 months ago
- Archive of publicly available threat INTel reports (mostly APT Reports but not limited to).☆11Sep 30, 2018Updated 8 years ago
- Everything related to YARA☆16Apr 18, 2026Updated 5 months ago