Skip to content

benscha/KQLAdvancedHunting

Repository files navigation

KQL Advanced Hunting Queries for Microsoft Defender and Sentinel

KQLNinja
This repository contains a curated collection of **KQL (Kusto Query Language) queries** for **Microsoft Defender Advanced Hunting** and Sentinel, designed to help security analysts and IT administrators improve threat detection and incident response.

🔍 What’s Inside?

  • Practical Advanced Hunting queries for Microsoft 365 Defender
  • Security monitoring scripts for Endpoint, Identity, and Cloud
  • Incident Response-focused KQL examples
  • Optimized filters for tables like DeviceProcessEvents, EmailEvents, and AlertEvidence

Why This Repository?

  • Real-world KQL examples for proactive threat hunting
  • Easy customization for your own security scenarios
  • Keywords for better visibility:
    KQL, Microsoft Defender, Advanced Hunting, Security Queries, Threat Detection

🔗 Connect with Me

Follow me on LinkedIn: https://www.linkedin.com/in/benjamin-zulliger/?follow

Maintained by Benjamin Zulliger

About

some KQL Queries for Advanced Hunting

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors