Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Sep 15, 2026 - PowerShell
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bicep) with PowerShell automation to streamline the deployment of Sentinel solutions, analytics rules, and workbooks.
Detection rules and threat hunting queries in Defender XDR and Azure Sentinel
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
Automated daily Microsoft Defender XDR security briefing delivered to Microsoft Teams using Azure Logic Apps, KQL Advanced Hunting, and Microsoft Graph.
KQL detection and hunting queries for Microsoft Sentinel and Defender XDR
A PowerShell MVP who is passionate about helping others succeed with Active Directory, Entra ID, Defender XDR, and Microsoft 365. Always learning! ✝️👨👩👧👦☕
TUI for Defender XDR using PwshSpectreConsole
A concise, practical look at strengthening email security with Defender for Office 365 and effective phishing response.
KQL Collection
Security License Lens — see what you paid for but never turned on (Microsoft security license utilization & config debt)
Self-hosted, strictly read-only MCP server for Microsoft Defender XDR. Bring your own AI to your Defender telemetry — delegated per-user auth, no write path, production guardrails.
MS-102: Microsoft 365 Administrator Expert — Study Notes & Exam Prep.
Validate. Verify. Defend. A Microsoft Defender validation framework with guided testing experiences and analyst-focused reporting.
Private, policy-enforced reference pattern for governed Microsoft Sentinel automation using Azure Logic Apps Agent Loop, Azure Function PEP, Entra ID, managed identity, and Private Endpoints.
Collection of Threat Hunts in Jupyter Notebooks
Detection-as-code for Microsoft Sentinel and Defender XDR. 12 analytic rules, 10 hunting queries, 4 SOAR playbooks, ATT&CK Navigator coverage, CI validation, and full L3 SOC workflow documentation.
Major rewrite of `mcp-defender` to add Interactive auth and support for modern defender xdr + sentinel APIs. Claude skill included. Full GH security enabled on repo (Dependabot, CodeQL, etc)
To associate your repository with the defender-xdr topic, visit your repo's landing page and select "manage topics."