KQL Queries. Microsoft Defender, Microsoft Sentinel
-
Updated
Aug 25, 2025 - JavaScript
KQL Queries. Microsoft Defender, Microsoft Sentinel
KQL Queries. Microsoft Defender, Microsoft Sentinel
A set of importable Intune policies that simplify onboarding/offboarding MacOS devices to/from Defender for Business/Endpoint.
This repository contains a selection of Kusto Query Language (KQL) queries designed for proactive threat hunting. Aligned with the MITRE ATT&CK framework, these queries are crafted to detect and address potential threats effectively.
KQL Library provides a clean, intuitive interface for security professionals to search and copy kusto queries. Featuring category-based organization and instant search capabilities.
Microsoft Defender XDR threat hunting KQL queries
KQL-Queries 🐙 provides ready KQL scripts for Microsoft Defender XDR threat hunting, helping security teams detect, investigate, and respond to threats.
🛡️ Simplify onboarding and offboarding of MacOS devices with importable Intune policies for Defender for Business and Endpoint.
Add a description, image, and links to the defenderxdr topic page so that developers can more easily learn about it.
To associate your repository with the defenderxdr topic, visit your repo's landing page and select "manage topics."