KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
-
Updated
Oct 31, 2024 - Python
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
Hunting queries and detections
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
MDATP
Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant
Collection of Remote Management Monitoring tool artifacts, for assisting forensics and investigations
ASR Configurator, Essentials and Atomic Testing
Microsoft Intune Custom Compliance
This repository will describe the details surrounding the SIEM (wazuh) mini project, which will cover all aspects of topology design, deployment, rules, integration, and fine tune.
Python for Security is the home of all open source Python projects that can integrate with Microsoft Technologies.
Repository for Software Certs for easy software blocking across corp environments, for example, using MDE IOC
Microsoft Defender for Endpoint PowerShell module
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
A PowerShell module to interact with Microsoft's Defender for Endpoint API.
Repo includes KQL queries that you can run in your Azure Log Analyics environment.
K9-Defender is highly Simple with a Sophisticated Watchdog System and a Powerful Process Scanning both for Windows 10 and 11
Defender for Endpoint Advanced Hunting Queries
Resource Level Enabled for Defender for Servers P1
Setting Up Wazuh SIEM/XDR Homelab and Integration of Microsoft Defender into it.
Threat-Hunting KQL query which identifies machines that utilize powershell, cmd or wmic to connect to any URL that includes “cdn.discordapp.com” ,where the action was initiated by a script execution ( .vbs , .bat etc)
Add a description, image, and links to the defender-for-endpoint topic page so that developers can more easily learn about it.
To associate your repository with the defender-for-endpoint topic, visit your repo's landing page and select "manage topics."