KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Submit query
Device Query
Hunting Ingress Nightmare CVSS 98
DeviceInfo
DeviceProcessEvents
Author:
Steven Lim
Released:
March 25th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Active Exploitation Of Critical Apache Tomcat RCE Vulnerability
DeviceInfo
DeviceProcessEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
March 21th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Misconfigured EXO Transport Rules
EmailEvents
Author:
Steven Lim
Released:
March 21th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ZDI CAN 25373 Windows Shortcut Exploit Abused Detection
DeviceEvents
Author:
Steven Lim
Released:
March 20th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Device Discovery Subnet Ranges
DeviceNetworkInfo
Author:
Robbe Van den Daele
Released:
March 19th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Device Network Events Uncommon Process Connection To Cloudfront Domain
DeviceNetworkEvents
Author:
Jose Sebastián Canós
Released:
March 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
7Z To SM Bshare
DeviceProcessEvents
Author:
Ali Hussein
Released:
March 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Matching Url Redirectors From Urlclickevents Table With Openphish External Threat Intel Source
UrlClickEvents
Author:
Michalis Michalos
Released:
March 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Matching Ip Redirectors From Urlclickevents Table With Urlhaus External Threat Intel Source
UrlClickEvents
Author:
Michalis Michalos
Released:
March 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Unfolding Redirectors Using Urlclickevents Table
UrlClickEvents
Author:
Michalis Michalos
Released:
March 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Privileged Unified Identity Info
IdentityInfo
WorkloadIdentityInfo
Author:
Thomas Naunheim
Released:
March 17th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Unauthorized RMM Instances In Your MDE Environment
DeviceNetworkEvents
Author:
Steven Lim
Released:
March 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Website Redirectors Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
March 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Kerberos Roasting Detection
IdentityLogonEvents
Author:
Steven Lim
Released:
March 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Parsing Sign In Logs Tables
SigninLogs
AADNonInteractiveUserSignInLogs
ADFSSignInLogs
AADServicePrincipalSignInLogs
AADManagedIdentitySignInLogs
Author:
Jose Sebastián Canós
Released:
March 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Malicious Answers By DNS Queries
DeviceNetworkEvents
Author:
Sergio Albea
Released:
March 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Malicious URL Answers By DNS Queries
DeviceNetworkEvents
Author:
Sergio Albea
Released:
March 14th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR Medusa Ransomware Detection
DeviceNetworkEvents
Author:
Steven Lim
Released:
March 13rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Suspicious Run MR Uentries
DeviceRegistryEvents
Author:
Ali Hussein
Released:
March 13rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Cloudflared Argo Tunnel DNS
DeviceNetworkEvents
Author:
Ali Hussein
Released:
March 13rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Node JS Suspicious Executions
DeviceProcessEvents
Author:
Ali Hussein
Released:
March 13rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Service Acc Login On New Device
IdentityInfo
DeviceLogonEvents
Author:
Robbe Van den Daele
Released:
March 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR Weekly OSINT Indicators Scan 10032025
EmailAttachmentInfo
EmailUrlInfo
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
March 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR LDAP Enumeration Detection
IdentityQueryEvents
Author:
Steven Lim
Released:
March 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
End Of Life Software With File Paths Using TVM
DeviceTvmSoftwareInventory
DeviceTvmSoftwareEvidenceBeta
Author:
Jay Kerai
Released:
March 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Critical Vulnerability In Elastic Kibana
DeviceInfo
DeviceProcessEvents
Author:
Steven Lim
Released:
March 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect CVE 2025 27607 CVSS 88
DeviceProcessEvents
Author:
Steven Lim
Released:
March 9th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Psexecsvcpy Detection
DeviceFileEvents
DeviceEvents
Author:
Steven Lim
Released:
March 9th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Entra ID User Created By Unexpected Actor
AuditLogs
Author:
Jose Sebastián Canós
Released:
March 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2025 22224 CVSS 93 CRITICAL Internet Facing V Mware Server Discovery
DeviceInfo
DeviceProcessEvents
Author:
Steven Lim
Released:
March 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Zero Day CVE 2025 21333 Privilege Escalation
DeviceProcessEvents
DeviceTvmSoftwareVulnerabilities
DeviceFileEvents
DeviceEvents
Author:
Steven Lim
Released:
March 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt ADWS Requests From Unknown Device
DeviceNetworkInfo
DeviceInfo
DeviceNetworkEvents
Author:
Robbe Van den Daele
Released:
March 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting One On One Chats By Domains
CloudAppEvents
Author:
Sergio Albea
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enriched Entra Sign In Logs Requested Token By Suspicious RT
SigninLogs
AADNonInteractiveUserSignInLogs
NetworkAccessTraffic
AADSignInEventsBeta
Author:
Thomas Naunheim
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enriched Entra Sign In Logs Gsa Enforcement By Ca Policy
SigninLogs
AADNonInteractiveUserSignInLogs
NetworkAccessTraffic
AADSignInEventsBeta
Author:
Thomas Naunheim
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enriched Entra Sign In Logs Suspicious Token Request
SigninLogs
AADNonInteractiveUserSignInLogs
NetworkAccessTraffic
Author:
Thomas Naunheim
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Exposed Tokens Overview Of Token Artifcats
ExposureGraphEdges
ExposureGraphNodes
AlertEvidence
Author:
Thomas Naunheim
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enriched Entra Sign In Logs Token Protection Network Access
SigninLogs
AADNonInteractiveUserSignInLogs
NetworkAccessTraffic
Author:
Thomas Naunheim
Released:
March 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
SLA Time To Respond
SecurityIncident
Author:
Bert-Jan Pals
Released:
March 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Find Devices With Bit Locker Not Enabled
EncryptableVolume
Author:
Ugur Koc
Released:
February 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
System age And Update Status analysis
OsVersion
WindowsQfe
Author:
Ugur Koc
Released:
February 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Devices With Outdated BIOS
BiosInfo
Author:
Ugur Koc
Released:
February 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Find Devices With Multiple Physical Disks
DiskDrive
Author:
Ugur Koc
Released:
February 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify CPU Architecture Distribution
Cpu
Author:
Ugur Koc
Released:
February 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identifying Domains Added Into Browser Security Zones Via CLI
DeviceEvents
Author:
Sergio Albea
Released:
February 27th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Exploring M365 Accounts Investigation
AuditLogs
SigninLogs
CloudAppEvents
Author:
Steven Lim
Released:
February 27th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Kerberos Failures
SecurityEvent
Author:
Daniel Card
Released:
February 27th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Network Info Per Device
DeviceNetworkInfo
Author:
Daniel Card
Released:
February 27th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Parsed User Agent
SigninLogs
AADNonInteractiveUserSignInLogs
Author:
Jay Kerai
Released:
February 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
EDR And AV Killer A Large Scale Driver Exploitation Detection
DeviceFileEvents
Author:
Steven Lim
Released:
February 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X