KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Device Query
Hunt Mdi Not Installed
DeviceTvmSoftwareInventory
ExposureGraphNodes
Author:
Robbe Van den Daele
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Analytics Entra ID Role Assignments
AuditLogs
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Entra ID Role Assignment
EntraIDRoleAssignments
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Entra ID B2C Settings Modified
AuditLogs
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Analytics Unexpected Entra ID Device
_GetWatchlist
AuditLogs
SigninLogs
AADNonInteractiveUserSignInLogs
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Multiple Unexpected Entra ID Device
UnexpectedEntraIDDevice
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Entra ID Unusual Operation
AuditLogs
Author:
Jose Sebastián Canós
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Connections Affected By The Blocking Legacy Authentication Enforcement Expected By July 2025
AADSignInEventsBeta
Author:
Sergio Albea
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Unified Identity Info Xdr
IdentityInfo OAuthAppInfo ExposureGraphNodes ExposureGraphEdges
Author:
Thomas Naunheim
Released:
June 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sniffing Out UNC3944 On Teams
IdentityInfo
MessageEvents
MessageUrlInfo
Author:
Steven Lim
Released:
June 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Cloudflared Tunnel
DeviceProcessEvents
Author:
C.J. May
Released:
June 20th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
External Attack Surface Monitoring KQL
ExposureGraphNodes
DeviceNetworkEvents
Author:
Steven Lim
Released:
June 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Social Engineering Attack Detection
EmailEvents
DeviceNetworkEvents
RMMList
Author:
Steven Lim
Released:
June 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
User Account Deletion
SecurityEvent
Author:
Bert-Jan Pals
Released:
June 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Changes To Connect Sync Application
AuditLogs
Author:
Robbe Van den Daele
Released:
June 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Cred Add To Connect Sync Application
AuditLogs
Author:
Robbe Van den Daele
Released:
June 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
TA4557 Drops More Eggs
DeviceEvents
Author:
Steven Lim
Released:
June 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2025 33073 Detection
DeviceInfo
DnsEvents
Author:
Steven Lim
Released:
June 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID Enterprise Apps Deleted
AuditLogs
Author:
Alex Verboon
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID PIM Role Activations
AuditLogs
Author:
Alex Verboon
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID Disabled Userswith Priv Roles
IdentityInfo
Author:
Alex Verboon
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Defenderpassivemode
DeviceTvmInfoGathering
Author:
Alex Verboon
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Windows Server Client Missing Updates Summary
DeviceTvmSoftwareVulnerabilities
DeviceInfo
Author:
Alex Verboon
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Discord Invite Hijacking Detection
DeviceNetworkEvents
Author:
Steven Lim
Released:
June 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Office365version History
DeviceTvmSoftwareInventory
Author:
Alex Verboon
Released:
June 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Suspicious O Auth Applications Used To Retrieve And Send Emails
OAuthAppInfo
Author:
Steven Lim
Released:
June 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Potential Commands Executed By A Power Shellexe Renamed
DeviceProcessEvents
Author:
Sergio Albea
Released:
June 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt MSOL Azure AD Connect Or Entra Sync Servers
DeviceTvmSoftwareInventory
Author:
Robbe Van den Daele
Released:
June 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
APT Stealth Falcon CVE 2025 33053 Detection
DeviceFileEvents
DeviceProcessEvents
Author:
Steven Lim
Released:
June 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Conditional Access Baseline Gap Detected Due Policy Change
AuditLogs
Maester_CL
Author:
Thomas Naunheim
Released:
June 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Auth Methods Token Bounded Cae
SigninLogs
AADNonInteractiveUserSignInLogs
Author:
Thomas Naunheim
Released:
June 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit User Tries To Change Password To A Non Complying Password
AuditLogs
Author:
Jay Kerai
Released:
June 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Disabled Account Attack Disruption
CloudAppEvents
Author:
Bert-Jan Pals
Released:
June 8th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ANYRUN Obfuscated BAT Dropper Delivers Net Support RAT Post
DeviceProcessEvents
DeviceRegistryEvents
Author:
Steven Lim
Released:
June 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
3 Finding Sensitive Roles With CSPM Posture And Used By O Auth
WorkloadIdentityInfoXdr
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
1 Correlation Between Alert And Attack Path
securityresources
SecurityAlert
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
2 Sensitive Labels In Azure Resources
securityresources
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
3 EPM Insights
securityresources
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
2 Adv Correlation Between Alert And Attack Path
SecurityAlert
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
1 List Of Critical Azure Resources In XSPM
ExposureGraphNodes
AlertEvidence
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
2 Custom Graph Query On Recommendations And Target
ExposureGraphEdges
ExposureGraphNodes
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
3 Correlation Between CSPM And Identity Info
securityresources
IdentityInfo
authorizationresources
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
1 Overview Of Attack Paths
securityresources
Author:
Thomas Naunheim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Quarantined Messages
MessagePostDeliveryEvents
MessageEvents
MessageUrlInfo
Author:
Jose Sebastián Canós
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Quarantined Emails
EmailPostDeliveryEvents
EmailEvents
Author:
Jose Sebastián Canós
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Ottercookie Detection
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
June 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
NTL Mv2 Hash Leak Via COM Detection
DeviceLogonEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
May 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
O Auth App Using The OD File Picker Permission
OAuthAppInfo
Author:
Steven Lim
Released:
May 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
One Click ANY RUN Storm 1747 KQL Scan
WeeklyOSINT
EmailAttachmentInfo
EmailUrlInfo
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
May 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Dragon Force With ANYRUN Threat Intelligence
WeeklyOSINT
EmailAttachmentInfo
DeviceFileEvents
Author:
Steven Lim
Released:
May 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X