Michael Melone's Kusto Query library
☆20Nov 17, 2023Updated 2 years ago
Alternatives and similar repositories for KQL
Users that are interested in KQL are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- M365 MDATP Live Response sample scripts☆82Nov 1, 2024Updated last year
- DEPRECATED -> GO TO https://github.com/microsoft/Microsoft-threat-protection-Hunting-Queries☆20Apr 22, 2020Updated 6 years ago
- Firewall & Antivirus Exclusions Migrator☆17Apr 5, 2022Updated 4 years ago
- Advanced Interactive Security Workshop☆20Dec 28, 2020Updated 5 years ago
- Config files for my GitHub profile.☆10Jul 22, 2026Updated 2 weeks ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- ☆51Jul 7, 2024Updated 2 years ago
- List of custom developed KQL queries to help proactive security teams hunt for opportunistic and sophisticated threat activity by develop…☆26Jun 30, 2021Updated 5 years ago
- Hunting Queries for Defender ATP☆84Jul 7, 2026Updated last month
- M365 Defender SOC Playbooks☆24Feb 6, 2023Updated 3 years ago
- ☆20Sep 27, 2024Updated last year
- Sigma Queries turned into KQL for Defender using pysigma☆12Mar 29, 2026Updated 4 months ago
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.☆132Feb 10, 2026Updated 6 months ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆142Jul 29, 2026Updated last week
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Bulk turn on Analytic rules in Azure Sentinel☆18Oct 7, 2021Updated 4 years ago
- Repository with simples C binary samples for beginners REs & Defenders☆10May 29, 2024Updated 2 years ago
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated last year
- Random Powershell scripts☆13Feb 13, 2024Updated 2 years ago
- My useful KQL and Azure Monitor workbooks (Public)☆117Jun 19, 2026Updated last month
- Manage Engine Decrypter☆29Oct 17, 2022Updated 3 years ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆40Apr 8, 2021Updated 5 years ago
- ☆38Nov 12, 2024Updated last year
- Create a Word document showing your Sentinel configuration☆14Nov 7, 2023Updated 2 years ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- various tools for Microsoft Sentinel☆32Jun 17, 2026Updated last month
- ☆14Sep 22, 2023Updated 2 years ago
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 3 years ago
- ☆15Jul 1, 2026Updated last month
- Solution to deploy a Sentinel playground demo environment☆58Jun 9, 2023Updated 3 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆24Jan 8, 2024Updated 2 years ago
- Hands-on Security Labs focused on Azure IaaS Security☆62Jan 19, 2020Updated 6 years ago
- Public Archive for CSAW 2024 Quals☆11Sep 19, 2024Updated last year
- Repository with Sample KQL Query examples for Threat Hunting☆220Sep 1, 2022Updated 3 years ago
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- GetSimple CMS Custom JS Plugin Exploit RCE Chain☆11Mar 8, 2023Updated 3 years ago
- ☆71Apr 20, 2026Updated 3 months ago
- Sample queries for Advanced hunting in Microsoft 365 Defender☆2,085Feb 17, 2022Updated 4 years ago
- A Microsoft Sentinel toolkit for generating and ingesting **realistic sample data** into Log Analytics tables via the Azure Monitor Logs …☆20Jun 8, 2026Updated 2 months ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆22Nov 15, 2024Updated last year
- ☆17Mar 8, 2024Updated 2 years ago
- Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.☆491Nov 22, 2024Updated last year