AzureHunter
Hunting-Queries-Detection-Rules
AzureHunter | Hunting-Queries-Detection-Rules | |
---|---|---|
2 | 7 | |
764 | 1,007 | |
- | - | |
0.0 | 9.3 | |
over 1 year ago | 2 days ago | |
PowerShell | Python | |
MIT License | BSD 3-clause "New" or "Revised" License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
AzureHunter
Hunting-Queries-Detection-Rules
- Advanced Hunting queries every admin should use
- Hunting Querie into a Detection rule
- MS Sentinel Analytics & KQL
- Analytical rules
- MDE Repointing Frequency
-
Least occurrence in MDE
This will be the query that you are looking for. I do have a lot more queries if you are interested: https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules
- Must have analytic rules
What are some alternatives?
DetectionLabELK - DetectionLabELK is a fork from DetectionLab with ELK stack instead of Splunk.
Microsoft-365-Defender-Hunting-Queries - Sample queries for Advanced hunting in Microsoft 365 Defender
sysmon-modular - A repository of sysmon configuration modules
chatgpt-raycast - ChatGPT raycast extension
CloudShell - Container Image for Azure Cloud Shell (https://azure.microsoft.com/en-us/features/cloud-shell/)
kusto-queries - example queries for learning the kusto language
beagle - Beagle is an incident response and digital forensics tool which transforms security logs and data into graphs.
Sentinel-Queries - Collection of KQL queries
ARI - Azure Resource Inventory - It's a Powerful tool to create EXCEL inventory from Azure Resources with low effort
Linux Security - Ways to attack and protect Linux 🧢
Trawler - PowerShell script to help Incident Responders discover potential adversary persistence mechanisms.
KQL - Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.