WindowsDefenderATP-Hunting-Queries
Sample queries for Advanced hunting in Microsoft Defender ATP (by alexverboon)
SentinelKQL
Azure Sentinel KQL (by rod-trent)
WindowsDefenderATP-Hunting-Queries | SentinelKQL | |
---|---|---|
2 | 5 | |
30 | 361 | |
- | - | |
0.0 | 8.1 | |
over 2 years ago | 7 days ago | |
Jupyter Notebook | ||
MIT License | - |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
WindowsDefenderATP-Hunting-Queries
Posts with mentions or reviews of WindowsDefenderATP-Hunting-Queries.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-10-07.
SentinelKQL
Posts with mentions or reviews of SentinelKQL.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2021-10-07.
- Powershell logging
-
Custom IOC list query
Here's a standard Watchlist query example that may help: https://github.com/rod-trent/SentinelKQL/blob/master/Watchlist_Basics
-
Detect Azure RBAC Changes
Something like the following for a start? https://github.com/rod-trent/SentinelKQL/blob/master/SuccessfulRoleAssignments.txt
-
KQl Query
There's a few Intune queries here: https://github.com/rod-trent/SentinelKQL
- KQL Repository/Database
What are some alternatives?
When comparing WindowsDefenderATP-Hunting-Queries and SentinelKQL you can also consider the following projects:
Sentinel-Queries - Collection of KQL queries