A collection of KQL detection and hunting queries for Microsoft Sentinel and Defender XDR, designed to help defenders identify threats, support investigations, and enhance detection coverage.
Each query lives in its own file and follows the same structure: a rule summary, the reasoning behind the detection logic, the KQL itself, an ATT&CK mapping, and references to the reporting or documentation it is based on.
Queries are provided as-is and should be tested and validated in your environment before deployment. Detection coverage, performance, and results may vary depending on available telemetry and configuration.