DEPRECATED -> GO TO https://github.com/microsoft/Microsoft-threat-protection-Hunting-Queries
☆21Apr 22, 2020Updated 5 years ago
Alternatives and similar repositories for MTP-AHQ
Users that are interested in MTP-AHQ are comparing it to the libraries listed below
Sorting:
- Collection of scripts and tools related to the eCTHPv2 exam by INE.☆19Jun 12, 2022Updated 3 years ago
- ☆10Oct 25, 2020Updated 5 years ago
- ☆30Nov 11, 2024Updated last year
- ☆19Sep 3, 2021Updated 4 years ago
- Michael Melone's Kusto Query library☆20Nov 17, 2023Updated 2 years ago
- ☆50Jul 7, 2024Updated last year
- Sample queries for Advanced hunting in Microsoft 365 Defender☆2,051Feb 17, 2022Updated 4 years ago
- ☆29Nov 13, 2020Updated 5 years ago
- Repository to publish sample use cases, templates, solutions, automations for Microsoft Defender Threat Intelligence (MDTI) product☆80Sep 9, 2024Updated last year
- CONVEX is a group of CTFs that are independently deployable into participant Azure environments.☆140May 16, 2022Updated 3 years ago
- A lab environment for learning about MSTICPy☆38Feb 3, 2023Updated 3 years ago
- Admin Submission API allows submission of URLs, mail messages, file mail messages and files to Microsoft to re-scan and get newest verdic…☆10Aug 6, 2021Updated 4 years ago
- A small crappy script I wrote that converts the Sigma Windows Process Creation events to KQL via PySigma. Designed for CI/CD☆10Nov 7, 2023Updated 2 years ago
- KQL queries for Microsoft Defender Advanced Hunting organized around the TTPs of the MITRE ATT&CK framework.☆18Nov 7, 2024Updated last year
- This is just a personal SnapTap Project for CS2 I made in python to get past the recent VAC 3.0 SnapTap & SOCD Detections☆17Sep 6, 2024Updated last year
- Python Wrapper for the Frantrax API☆17Jan 1, 2026Updated 2 months ago
- Sigma Queries turned into KQL for Defender using pysigma☆12Jun 20, 2024Updated last year
- Get started fast with a built out lab, built from scratch via Azure Resource Manager (ARM) and Desired State Configuration (DSC), to test…☆238Jun 25, 2020Updated 5 years ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆40Apr 8, 2021Updated 4 years ago
- The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect…☆77Feb 10, 2026Updated 2 weeks ago
- Send and receive messages over Named Pipes asynchronously.☆39Sep 17, 2021Updated 4 years ago
- KQL queries for Advanced Hunting☆176Jan 16, 2020Updated 6 years ago
- Demonstrate the new FileDispositionInfoEx behavior☆15Nov 6, 2017Updated 8 years ago
- ☆12Jul 12, 2022Updated 3 years ago
- Simple script to generate commands to achieve reverse shells.☆12Aug 12, 2019Updated 6 years ago
- WinDbg Symbols Caching Proxy.☆17Updated this week
- ☆14Jan 18, 2020Updated 6 years ago
- Tiny Windows executable that outputs version information about the OS.☆11Feb 1, 2026Updated last month
- Generates a detailed CSV file containing Sigma Rules statistics for each service or category, and each level, offering a holistic view of…☆10Dec 22, 2023Updated 2 years ago
- CVE-2025-64155: Fortinet FortiSIEM Argument Injection to Remote Code Execution☆30Jan 13, 2026Updated last month
- This config file will automatically convert a temporary Windows Sandbox environment into a Flare VM for malware analysis.☆11Jan 3, 2025Updated last year
- Powershell module for Microsoft Cloud App Security (MCAS)☆10Mar 19, 2021Updated 4 years ago
- Leveraging Platform Trust Technology (PTT) to defeat Driver Signing Enforcement (DSE) to run Kernel Drivers (KMDF) with Secure Boot Enabl…☆14Aug 22, 2022Updated 3 years ago
- Spawn SYSTEM shells like a PRO!☆10Mar 8, 2023Updated 2 years ago
- Metasploit Post-Exploitation Gather module for Exchange Server☆25Mar 26, 2021Updated 4 years ago
- My eJPT exam cheatSheet☆12Nov 9, 2021Updated 4 years ago
- A repo for sample MDATP Power BI Templates☆205Jun 15, 2021Updated 4 years ago
- Sentinel Recon Tools Workbook☆14Aug 24, 2022Updated 3 years ago
- Fake SMB and SAMR data☆11Oct 27, 2019Updated 6 years ago