A schema-aware dataset and Claude AI skill for Microsoft Defender XDR Advanced Hunting.
☆36May 6, 2026Updated 2 months ago
Alternatives and similar repositories for defender-xdr-advanced-hunting
Users that are interested in defender-xdr-advanced-hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Microsoft Sentinel toolkit for generating and ingesting **realistic sample data** into Log Analytics tables via the Azure Monitor Logs …☆20Jun 8, 2026Updated last month
- Share Information about Microsoft Security Products☆115Updated this week
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆231Updated this week
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆66Mar 30, 2026Updated 4 months ago
- ☆84Feb 4, 2026Updated 5 months ago
- Simple, predictable pricing with DigitalOcean hosting • AdAlways know what you'll pay with monthly caps and flat pricing. Enterprise-grade infrastructure trusted by 600k+ customers.
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆118Jul 15, 2026Updated 2 weeks ago
- Miscellaneous stuff I create☆75Jul 15, 2026Updated 2 weeks ago
- An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bice…☆67Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- PowerShell tool for streamlined Microsoft Defender Advanced Hunting query management with GitHub Copilot integration☆18Jul 27, 2026Updated last week
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆31Aug 4, 2025Updated last year
- ☆85Updated this week
- A production-ready, enterprise-grade MDR framework that transforms chaotic security alerts into structured, actionable intelligence.☆23Feb 14, 2026Updated 5 months ago
- Sharing my KQL queries for Azure Sentinel☆225Jun 13, 2026Updated last month
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆17May 13, 2026Updated 2 months ago
- Collection of Microsoft Identity Threat Detection and Response resources.☆54Updated this week
- Microsoft Sentinel SIEM Log Source Analyzer☆28Jun 10, 2026Updated last month
- Visualize Microsoft Defender XDR process trees and security events☆33Aug 24, 2025Updated 11 months ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆122Jan 18, 2026Updated 6 months ago
- My Azure Sentinel Ninja ideas, thoughts and contributions☆25Jul 10, 2026Updated 3 weeks ago
- A Triage Agent for reducing junior analyst manual activiites☆44May 11, 2026Updated 2 months ago
- Velociraptor Server hosted in Azure App Service☆59Jun 4, 2025Updated last year
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Jul 8, 2026Updated 3 weeks ago
- Deploy on Railway without the complexity - Free Credits Offer • AdConnect your repo and Railway handles the rest with instant previews. Quickly provision container image services, databases, and storage volumes.
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Sentinel Threat Intelligence Upload Toolkit☆18Jul 15, 2024Updated 2 years ago
- KQL Queries☆42Jun 30, 2026Updated last month
- A curated list of Ransomware resources☆40May 11, 2026Updated 2 months ago
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- how to strangle threats☆58Updated this week
- Guidance and collateral for troubleshooting and managing Azure Sentinel data costs.☆28Oct 9, 2023Updated 2 years ago
- ☆15May 19, 2026Updated 2 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated 11 months ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- Block abused TLDs in Tenant Allow BlockList☆15Jun 4, 2026Updated 2 months ago
- ☆20Mar 24, 2026Updated 4 months ago
- File type examples, useful for security testing.☆17Jun 6, 2026Updated last month
- ☆15Mar 22, 2026Updated 4 months ago
- The Sentinel.blog Repository provides automation tools for updating Analytics Rules, Content Hub Solutions, and Workbooks, eliminating re…☆22Updated this week
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆30May 21, 2026Updated 2 months ago
- KQL example queries for working in Azure☆38Dec 1, 2025Updated 8 months ago