A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Apr 9, 2025
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
A framework for converting natural language text inputs to corresponding Pandas, MongoDB, Kusto and Neo4j (Cypher) queries.
A technical blog about Kusto
A series of cloud focused KQL queries for threat hunting and DFIR
KQL queries for monitor log analytics
Microsoft Technical Essentials Workshop is a technical training program to empower veterans. Supported by LA County WDACS; LAVTTA; Microsoft Learning; LA Mayor; Fast Lane; JVS SoCal; and more.
A comprehensive collection of Kusto Query Language (KQL) scripts and tools for simplified log analysis and troubleshooting in Azure and DevOps environments.
KQL query framework for Azure Log Analytics - organize, execute, and automate queries with flexible outputs.
Powershell scripts repo
KQL Local Manager, allows you to manage and organize KQL Queries in a central Database.
Add a description, image, and links to the kusto-query-language topic page so that developers can more easily learn about it.
To associate your repository with the kusto-query-language topic, visit your repo's landing page and select "manage topics."