KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Submit query
Device Query
Visualizing Fortigate Cve 2022 40684 Belsen Group Leaked Affected Ips
RawFortiGateIPs
Author:
Michalis Michalos
Released:
January 17th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
KQL Wiz PDF NTLM Leak Detector
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
January 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Ivanti Vulnerabilities CVE 2025 0282 And CVE 2025 0283
DeviceTvmSoftwareInventory
Author:
Sergio Albea
Released:
January 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Base64 Code In Commands
DeviceFileEvents
Author:
Sergio Albea
Released:
January 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Fasthttp Bruteforce Campaign
AADSignInEventsBeta
Author:
Steven Lim
Released:
January 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Lumma Stealer Commands
DeviceFileEvents
Author:
Sergio Albea
Released:
January 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
DeviceFileEvents
Author:
Sergio Albea
Released:
January 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt For High Volume Phish ISP
CloudAppEvents
EmailEvents
Author:
Steven Lim
Released:
January 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDO Email Threat Classification By ISP
CloudAppEvents
EmailEvents
Author:
Steven Lim
Released:
January 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDO Email Threat Classification By Country
EmailEvents
Author:
Steven Lim
Released:
January 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Non Euclid RAT
DeviceFileEvents
DeviceEvents
Author:
Steven Lim
Released:
January 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Aqua Blizzards
DeviceNetworkEvents
Author:
Steven Lim
Released:
January 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure P2S Point To Site Connection Success Username And IP Parser
AzureDiagnostics
AADNonInteractiveUserSignInLogs
Author:
Jay Kerai
Released:
January 9th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVES Cases
DeviceTvmSoftwareInventory
Author:
Sergio Albea
Released:
January 9th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Signin Logs Potential Compliant Device Bypass Attempt
SigninLogs
Author:
Jose Sebastián Canós
Released:
January 8th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2024 43452 Po C Detection
DeviceTvmSoftwareVulnerabilities
DeviceFileEvents
DeviceFileCertificateInfo
DeviceEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
January 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2024 49113 LDAP Nightmare
DeviceNetworkEvents
Author:
Bert-Jan Pals
Released:
January 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Resource Lock Deletion For Azure Monitor Rule
AzureActivity
Author:
Jay Kerai
Released:
January 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Machine Onboarded
AzureActivity
Author:
Bert-Jan Pals
Released:
January 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
LDAP Nightmare POC Detection
DnsEvents
Author:
Steven Lim
Released:
January 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Log Analytic Workspace Deletions
AzureActivity
Author:
Jay Kerai
Released:
January 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sentinel Incident Deletions
AzureActivity
Author:
Jay Kerai
Released:
January 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Monitor Rule Disabled
AzureActivity
Author:
Jay Kerai
Released:
January 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Bring Your Own Minifilter EDR Bypass
DeviceProcessEvents
DeviceRegistryEvents
Author:
Jay Kerai
Released:
December 31th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Living Off The Tunnels IOCS
DeviceNetworkEvents
Author:
Jay Kerai
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Security Event AD Unusual Operation
SecurityEvent
Author:
Jose Sebastián Canós
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Malicious Chrome Extension
DeviceFileEvents
Author:
Steven Lim
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Custom Detection Disabled
CloudAppEvents
Author:
Bert-Jan Pals
Released:
December 28th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2024 3393 DDOS Detection
CommonSecurityLog
Author:
Steven Lim
Released:
December 27th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Malicious Senders Hidden Behind Anonymous Proxies
CloudAppEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Rating IS Ps To Detect Potential Malicious Domains Sending Threats
EmailEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detection Of OOF Message Delivered Externally
EmailEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Spoofed Email Cases
EmailEvents
IdentityInfo
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
September Updates
DeviceTvmSoftwareVulnerabilities
DeviceTvmSoftwareVulnerabilitiesKB
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Anonymized Microsoft Graph Activity Logs
MicrosoftGraphActivityLogs
Author:
Bert-Jan Pals
Released:
December 23th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Monitor Exclusion Into Conditional Access Policies
AADSignInEventsBeta
Author:
Sergio Albea
Released:
December 23th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
TI Feed Tor Connections
DeviceNetworkEvents
Author:
Bert-Jan Pals
Released:
December 21th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Advanced Vishing KQL Detection
TeamsCallLog
Author:
Steven Lim
Released:
December 19th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Url Haus Abusech Hits In Microsoft Teams
CloudAppEvents
Author:
Sergio Albea
Released:
December 18th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Power Shell Self Pwn
IdentityInfo
DeviceEvents
DeviceProcessEvents
Author:
Steven Lim
Released:
December 17th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Ransomware Tool Matrix Defender Lookup
DeviceProcessEvents
Author:
Jay Kerai
Released:
December 16th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting For Registry Artifacts Of Service Creation
DeviceRegistryEvents
Author:
Sergio Albea
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting For Process Command Line Artifacts Of Service Creation
DeviceProcessEvents
Author:
Sergio Albea
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Old BIOS Versions
BiosInfo
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Find Processes With Unusually High Thread Or Handle Counts
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Flag Processes With Disproportionately Large Virtual Memory Usage
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Top Disk IO Processes
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Programs Set To Auto Run At Startup
WindowsRegistry
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Check If TPM 20 Is Available
Tpm
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Microsoft Graph Activity Logs Missing Logs
MicrosoftGraphActivityLogs
Author:
Jose Sebastián Canós
Released:
December 12nd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X