Michael Melone's Kusto Query library
☆20Nov 17, 2023Updated 2 years ago
Alternatives and similar repositories for KQL
Users that are interested in KQL are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- M365 MDATP Live Response sample scripts☆81Nov 1, 2024Updated last year
- DEPRECATED -> GO TO https://github.com/microsoft/Microsoft-threat-protection-Hunting-Queries☆20Apr 22, 2020Updated 5 years ago
- Firewall & Antivirus Exclusions Migrator☆16Apr 5, 2022Updated 4 years ago
- Advanced Interactive Security Workshop☆20Dec 28, 2020Updated 5 years ago
- ☆50Jul 7, 2024Updated last year
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- List of custom developed KQL queries to help proactive security teams hunt for opportunistic and sophisticated threat activity by develop…☆26Jun 30, 2021Updated 4 years ago
- Hunting Queries for Defender ATP☆83Apr 1, 2026Updated last week
- This repository is for public files shared by the Microsoft Information Protection Team☆25Jan 6, 2021Updated 5 years ago
- KQL queries for Advanced Hunting☆177Jan 16, 2020Updated 6 years ago
- M365 Defender SOC Playbooks☆24Feb 6, 2023Updated 3 years ago
- Config files for my GitHub profile.☆10Updated this week
- Sigma Queries turned into KQL for Defender using pysigma☆12Mar 29, 2026Updated last week
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant.☆133Feb 10, 2026Updated 2 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click and start building anything your business needs.
- ☆68Mar 9, 2026Updated last month
- Bulk turn on Analytic rules in Azure Sentinel☆19Oct 7, 2021Updated 4 years ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆138Mar 31, 2026Updated last week
- Repository with simples C binary samples for beginners REs & Defenders☆10May 29, 2024Updated last year
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated 8 months ago
- Create a Word document showing your Sentinel configuration☆14Nov 7, 2023Updated 2 years ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆40Apr 8, 2021Updated 5 years ago
- various tools for Microsoft Sentinel☆32Jun 26, 2025Updated 9 months ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆21Nov 15, 2024Updated last year
- End-to-end encrypted cloud storage - Proton Drive • AdSpecial offer: 40% Off Yearly / 80% Off First Month. Protect your most important files, photos, and documents from prying eyes.
- GitHub action for validating Microsoft Sentinel detection rules☆14May 22, 2023Updated 2 years ago
- ☆15Jun 28, 2024Updated last year
- ☆14Sep 22, 2023Updated 2 years ago
- This is a backup/test setup for the /r/ActiveDirectory reddit wiki and resource posts.☆19Mar 5, 2026Updated last month
- ☆45May 9, 2023Updated 2 years ago
- This script validates the most common Conditional Access policies in Microsoft 365.☆10May 27, 2024Updated last year
- Azure AD Incident Response☆28Oct 8, 2021Updated 4 years ago
- ☆20Sep 27, 2024Updated last year
- A very in development/test of a chrome extension to see who is conducting what fingerprinting when you visit a website. use at own risk☆100Updated this week
- DigitalOcean Gradient AI Platform • AdBuild production-ready AI agents using customizable tools or access multiple LLMs through a single endpoint. Create custom knowledge bases or connect external data.
- Hands-on Security Labs focused on Azure IaaS Security☆61Jan 19, 2020Updated 6 years ago
- Solution to deploy a Sentinel playground demo environment☆58Jun 9, 2023Updated 2 years ago
- These are some of the commands which I use frequently during Malware Analysis and DFIR.☆24Jan 8, 2024Updated 2 years ago
- Microsoft Defender Advanced Threat Protection☆49Jan 28, 2026Updated 2 months ago
- ☆11Dec 25, 2020Updated 5 years ago
- Repository with Sample KQL Query examples for Threat Hunting☆218Sep 1, 2022Updated 3 years ago
- misp-cloud - Cloud-ready images of MISP☆74Aug 24, 2022Updated 3 years ago