awesome-kql-sentinel
A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel (by reprise99)
blue-teaming-with-kql
Repository with Sample KQL Query examples for Threat Hunting (by ashwin-patil)
Our great sponsors
awesome-kql-sentinel | blue-teaming-with-kql | |
---|---|---|
2 | 1 | |
180 | 187 | |
- | - | |
0.0 | 10.0 | |
about 1 year ago | over 1 year ago | |
- | MIT License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
awesome-kql-sentinel
Posts with mentions or reviews of awesome-kql-sentinel.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-01-08.
-
Microsoft Sentinel - the whys of KQL
This should get you started - including some additional insight into threat hunting use cases: https://github.com/reprise99/awesome-kql-sentinel
-
List of all sources that have KQL queries/analytic rules etc
Reprise99's list: https://github.com/reprise99/awesome-kql-sentinel
blue-teaming-with-kql
Posts with mentions or reviews of blue-teaming-with-kql.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2023-01-08.
-
Microsoft Sentinel - the whys of KQL
Also: - https://threathunt.blog/tag/kql/ - MDE-specific: https://learn.microsoft.com/en-us/microsoft-365/security/defender/advanced-hunting-query-language?view=o365-worldwide - https://github.com/ashwin-patil/blue-teaming-with-kql
What are some alternatives?
When comparing awesome-kql-sentinel and blue-teaming-with-kql you can also consider the following projects:
Sentinel-Queries - Collection of KQL queries
awesomekql - Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs