A schema-aware dataset and Claude AI skill for Microsoft Defender XDR Advanced Hunting.
☆36May 6, 2026Updated 3 months ago
Alternatives and similar repositories for defender-xdr-advanced-hunting
Users that are interested in defender-xdr-advanced-hunting are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- A Microsoft Sentinel toolkit for generating and ingesting **realistic sample data** into Log Analytics tables via the Azure Monitor Logs …☆20Jun 8, 2026Updated 2 months ago
- Share Information about Microsoft Security Products☆117Updated this week
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆239Updated this week
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆67Mar 30, 2026Updated 4 months ago
- ☆84Feb 4, 2026Updated 6 months ago
- Managed Database hosting by DigitalOcean • AdPostgreSQL, MySQL, MongoDB, Kafka, Valkey, and OpenSearch available. Automatically scale up storage and focus on building your apps.
- Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MIT…☆171Updated this week
- Miscellaneous stuff I create☆75Jul 15, 2026Updated last month
- An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bice…☆73Updated this week
- KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Micro…☆158Apr 1, 2026Updated 4 months ago
- PowerShell tool for streamlined Microsoft Defender Advanced Hunting query management with GitHub Copilot integration☆20Aug 17, 2026Updated last week
- KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries…☆31Aug 4, 2025Updated last year
- ☆85Updated this week
- A production-ready, enterprise-grade MDR framework that transforms chaotic security alerts into structured, actionable intelligence.☆25Feb 14, 2026Updated 6 months ago
- Sharing my KQL queries for Azure Sentinel☆225Aug 4, 2026Updated 2 weeks ago
- Virtual machines for every use case on DigitalOcean • AdGet dependable uptime with 99.99% SLA, simple security tools, and predictable monthly pricing with DigitalOcean's virtual machines, called Droplets.
- This operational dashboard correlates data from Microsoft Defender for Endpoint/Server (MDE) and Azure Monitor Agent (AMA) to identify co…☆18May 13, 2026Updated 3 months ago
- Collection of Microsoft Identity Threat Detection and Response resources.☆54Updated this week
- Microsoft Sentinel SIEM Log Source Analyzer☆29Jun 10, 2026Updated 2 months ago
- Visualize Microsoft Defender XDR process trees and security events☆33Aug 24, 2025Updated 11 months ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆123Jan 18, 2026Updated 7 months ago
- My Azure Sentinel Ninja ideas, thoughts and contributions☆25Aug 14, 2026Updated last week
- A Triage Agent for reducing junior analyst manual activiites☆45May 11, 2026Updated 3 months ago
- Velociraptor Server hosted in Azure App Service☆59Jun 4, 2025Updated last year
- KQL Sentinel and Defender Detection and Hunting Queries.☆16Updated this week
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated last year
- Sentinel Threat Intelligence Upload Toolkit☆18Jul 15, 2024Updated 2 years ago
- KQL Queries☆42Aug 10, 2026Updated 2 weeks ago
- A curated list of Ransomware resources☆40May 11, 2026Updated 3 months ago
- ResearchDev - XDR & SIEM Detection☆66Apr 16, 2025Updated last year
- how to strangle threats☆61Updated this week
- Guidance and collateral for troubleshooting and managing Azure Sentinel data costs.☆28Oct 9, 2023Updated 2 years ago
- ☆15May 19, 2026Updated 3 months ago
- Track C2 servers, tools, and botnets over time by framework and location☆16Aug 17, 2025Updated last year
- Managed Kubernetes at scale on DigitalOcean • AdDigitalOcean Kubernetes includes the control plane, bandwidth allowance, container registry, automatic updates, and more for free.
- Block abused TLDs in Tenant Allow BlockList☆15Aug 9, 2026Updated 2 weeks ago
- ☆21Aug 15, 2026Updated last week
- File type examples, useful for security testing.☆17Jun 6, 2026Updated 2 months ago
- ☆15Aug 15, 2026Updated last week
- The Sentinel.blog Repository provides automation tools for updating Analytics Rules, Content Hub Solutions, and Workbooks, eliminating re…☆22Updated this week
- First-ever decryptor for The Gentlemen ransomware — recovers encryption keys from process memory dumps using X25519 ephemeral key extract…☆31May 21, 2026Updated 3 months ago
- KQL example queries for working in Azure☆39Dec 1, 2025Updated 8 months ago