Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Sep 15, 2026 - PowerShell
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
Microsoft Entra ID Security Assessment Tool
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
🛡️ Scripts and articles about Microsoft Defender M365
Microsoft 365 administration laboratory: tenant design, identity and licensing, Exchange Online, Teams, SharePoint, Purview and Intune. Built on Microsoft Graph PowerShell.
To associate your repository with the m365-defender topic, visit your repo's landing page and select "manage topics."