KQL Queries. Microsoft Defender, Microsoft Sentinel
-
Updated
Oct 4, 2026 - JavaScript
KQL Queries. Microsoft Defender, Microsoft Sentinel
KQL Queries. Microsoft Defender, Microsoft Sentinel
A mirror image of my detection rules
A set of importable Intune policies that simplify onboarding/offboarding MacOS devices to/from Defender for Business/Endpoint.
Microsoft Defender XDR threat hunting KQL queries
JSON-driven Microsoft Defender for Endpoint policy deployment toolkit focused on repeatable endpoint hardening, validation, and deployment consistency using Microsoft Graph.
KQL-Queries 🐙 provides ready KQL scripts for Microsoft Defender XDR threat hunting, helping security teams detect, investigate, and respond to threats.
KQL Queries for Microsoft Sentinel and Microsoft Defender XDR
Searchable library of KQL queries for Microsoft security products, with category browsing and one-click copy.
To associate your repository with the defenderxdr topic, visit your repo's landing page and select "manage topics."