KQL Queries. Microsoft Defender, Microsoft Sentinel
-
Updated
Jun 29, 2026
KQL Queries. Microsoft Defender, Microsoft Sentinel
MDE Tester is designed to help testing various features in Microsoft Defender for Endpoint.
Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.
Shadow Throne is the command center for the Shadow Suite, providing a unified operational dashboard to launch, manage, and monitor Microsoft Defender deployment, validation, investigation, and governance tools.
Parse Ransomwatch results in python and create MDE IOC lists as you search
This template provides to write tag as Azure subscription name for Azure VM installed Defender for Servers (MDE)
A collection of Microsoft Security MacOS policy to help organizations automate onboarding/offboarding of Macbook's to/from Defender with Intune, accelerate secure deployments and implement Microsoft Security best practices with Zero trust principles.
This baseline delivers a hardened Windows 11 configuration that minimizes the risk of unauthorized third-party AI access while maintaining a productive user experience
Usefull tools, scripts and queries for MS Defender for Endpoint
A collection of Microsoft Security Windows Server policies to help organizations accelerate secure deployments to servers with Defender for Servers (Defender for Cloud), Defender Business for Servers and Endpoint for Servers with Intune.
To associate your repository with the defenderforendpoint topic, visit your repo's landing page and select "manage topics."