KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Device Query
Potential User Signed Into Edge Browser From Unmanaged Or Unregistered Device
SigninLogs
Author:
Jay Kerai
Released:
September 8th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Rclone Copy Process Args
DeviceProcessEvents
Author:
Jay Kerai
Released:
September 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Function App Stopped Or Deleted
AzureActivity
Author:
Jay Kerai
Released:
September 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Communication Services Deleted
AzureActivity
Author:
Jay Kerai
Released:
September 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Logic App Disabled Or Deleted
AzureActivity
Author:
Jay Kerai
Released:
September 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AAD Sign In Events Beta Hunting Potential Seamless SSO Usage
AADSignInEventsBeta
Author:
Jay Kerai
Released:
August 30th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Multiple Verified Threat Actor IP
AADUserRiskEvents
SecurityAlert
SigninLogs
Author:
Jose Sebastián Canós
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Multiple Suspicious API Traffic
AADUserRiskEvents
SecurityAlert
AADNonInteractiveUserSignInLogs
Author:
Jose Sebastián Canós
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID Entra Connect Sync Audit Events
SecurityEvent
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Purview Entra CA Block Insider Risk
SigninLogs
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
TH Use Of Administrator Account
DeviceLogonEvents
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Suspicious TCP Flags
DeviceNetworkEvents
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
TH Top Level Domains
DeviceNetworkEvents
EmailUrlInfo
EmailEvents
UrlClickEvents
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Sense Triggers Power Shell Public IP
DeviceNetworkEvents
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AD Account Last Logon
IdentityInfo
IdentityLogonEvents
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Dev Ops Repositories
ExposureGraphNodes
Author:
Alex Verboon
Released:
August 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Multiple Leaked Credentials
AADUserRiskEvents
SecurityAlert
Author:
Jose Sebastián Canós
Released:
August 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Fetch Dynamic And Manual Tags For Active Devices
DeviceInfo
Author:
Michalis Michalos
Released:
August 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Set Persistence Using Event Viewer Microsoft Redirection Program
DeviceRegistryEvents
Author:
Jay Kerai
Released:
August 27th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Domains With Seamless Sso Enabled
DeviceInfo
IdentityLogonEvents
Author:
Robbe Van den Daele
Released:
August 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enrollment Attempt With Adcsesc1honeypot Template
SecurityEvent
Author:
Fabian Bader
Released:
August 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
File From Host Collected
CloudAppEvents
Author:
Bert-Jan Pals
Released:
August 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Onmicrosoft Domains Impacted By Email Exchange Restrictions With External Domains
EmailEvents
Author:
Sergio Albea
Released:
August 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDI Dormant Accounts
IdentityInfo
IdentityDirectoryEvents
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
D4IOT Connector State
iotsecurityresources
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDXDR Attack Disruption And Response
DisruptionAndResponseEvents
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Arc Compare MDE
Resources
DeviceInfo
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDI Identify Service Account O Us
IdentityInfo
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
EEG Assets Allowing Remote Access
ExposureGraphNodes
DeviceInfo
Author:
Alex Verboon
Released:
August 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AAD Service Principal Risk Events Service Principal At Risk
AADServicePrincipalRiskEvents
Author:
Jose Sebastián Canós
Released:
August 21th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Assignment Of Local Administrator Entra Role
AuditLogs
Author:
Jay Kerai
Released:
August 20th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sentinel Workspace Disconnected
CloudAppEvents
Author:
Bert-Jan Pals
Released:
August 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra Auditing Tenant Restrictions V2 Events
SigninLogs
Author:
Jay Kerai
Released:
August 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sign In Logs B2B Access Restrictions
SigninLogs
Author:
Jay Kerai
Released:
August 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events Graph URIAPI Request Stats
GraphAPIAuditEvents
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events Graph Resource API Request Stats
GraphAPIAuditEvents
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events Azure Hound
MicrosoftGraphActivityLogs
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events User Enrichment
GraphAPIAuditEvents
IdentityInfo
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events App Enrichment External Data
GraphAPIAuditEvents
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events App Enrichment AAD Non Interactive User Sign In Logs
GraphAPIAuditEvents
AADNonInteractiveUserSignInLogs
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Graph API Audit Events IP Enrichment
GraphAPIAuditEvents
Author:
Bert-Jan Pals
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Request An Actor Token For Graphwindowsnet Using Service To Service S2S
AuditLogs
Author:
Jay Kerai
Released:
August 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Email Events Sender TLD Count
EmailEvents
Author:
Jay Kerai
Released:
August 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Risk Based Step Up Consent RBSU For Application
AuditLogs
Author:
Jay Kerai
Released:
August 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
App Consent To Risky Application
AuditLogs
Author:
Jay Kerai
Released:
August 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Ip Assets From Mdeasm In Exposure Management That Match Ti
ThreatIntelligenceIndicator
ExposureGraphNodes
Author:
Michalis Michalos
Released:
August 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Mdeasm Hosts With High Or Critical Vulnerabilities And A Cvss Score Over 8
ExposureGraphNodes
Author:
Michalis Michalos
Released:
July 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Assets From Mdeasm In Exposure Management That Match Ti
ThreatIntelligenceIndicator
ExposureGraphNodes
Author:
Michalis Michalos
Released:
July 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Cves In Mdeasm Web Pages Through Exposure Management
ExposureGraphNodes
ExposureGraphEdges
Author:
Michalis Michalos
Released:
July 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Assets From Mdeasm In Exposure Management
ExposureGraphNodes
Author:
Michalis Michalos
Released:
July 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X