kusto-queries
example queries for learning the kusto language (by tobiasmcvey)
Hunting-Queries-Detection-Rules
KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. (by Bert-JanP)
kusto-queries | Hunting-Queries-Detection-Rules | |
---|---|---|
1 | 7 | |
84 | 1,007 | |
- | - | |
0.0 | 9.3 | |
almost 3 years ago | about 18 hours ago | |
Python | ||
MIT License | BSD 3-clause "New" or "Revised" License |
The number of mentions indicates the total number of mentions that we've tracked plus the number of user suggested alternatives.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
kusto-queries
Posts with mentions or reviews of kusto-queries.
We have used some of these posts to build our list of alternatives
and similar projects.
-
I am a software geek in Cloud Security, reducing risk @ exascale. AMA!
Unfortunately I'm not familiar with Kusto, but I phoned a friend and got this which they said was "helpful" - https://github.com/tobiasmcvey/kusto-queries/blob/main/README.md
Hunting-Queries-Detection-Rules
Posts with mentions or reviews of Hunting-Queries-Detection-Rules.
We have used some of these posts to build our list of alternatives
and similar projects. The last one was on 2022-12-11.
- Advanced Hunting queries every admin should use
- Hunting Querie into a Detection rule
- MS Sentinel Analytics & KQL
- Analytical rules
- MDE Repointing Frequency
-
Least occurrence in MDE
This will be the query that you are looking for. I do have a lot more queries if you are interested: https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules
- Must have analytic rules
What are some alternatives?
When comparing kusto-queries and Hunting-Queries-Detection-Rules you can also consider the following projects:
azure-service-bus - ☁️ Azure Service Bus service issue tracking and samples
Microsoft-365-Defender-Hunting-Queries - Sample queries for Advanced hunting in Microsoft 365 Defender
azure-kusto-spark - Apache Spark Connector for Azure Kusto
chatgpt-raycast - ChatGPT raycast extension
ApplicationInsights-dotnet - ApplicationInsights-dotnet
Sentinel-Queries - Collection of KQL queries
learning-cloud - Courses, sample code, articles & screencasts - AWS, Azure, & GCP
AzureHunter - A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365
kusto-queries vs azure-service-bus
Hunting-Queries-Detection-Rules vs Microsoft-365-Defender-Hunting-Queries
kusto-queries vs azure-kusto-spark
Hunting-Queries-Detection-Rules vs chatgpt-raycast
kusto-queries vs ApplicationInsights-dotnet
Hunting-Queries-Detection-Rules vs Sentinel-Queries
kusto-queries vs learning-cloud
Hunting-Queries-Detection-Rules vs AzureHunter