KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Submit query
Device Query
IO Cs For Smart Ape SG Fake Browser Update Leads To Net Support RAT And Steal C
DeviceNetworkEvents
DeviceFileEvents
DeviceImageLoadEvents
Author:
Sergio Albea
Released:
February 19th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Most Recent Sign In Time For Users In The Last 30 Days
SigninLogs
Author:
Jay Kerai
Released:
February 19th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR Weekly OSINT Indicators Scan
WeeklyOSINT
EmailAttachmentInfo
EmailUrlInfo
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
February 19th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Critical Open SSH Vulnerabilities Patch Prioritization
DeviceInfo
DeviceTvmSoftwareInventory
Author:
Steven Lim
Released:
February 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identifying Devices By Vendor Based On Inbound Connections
DeviceNetworkEvents
Author:
Sergio Albea
Released:
February 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
EDR Evasion Inject Shellcode Via MSSQL CLR Assembly Detection
DeviceFileEvents
DeviceProcessEvents
Author:
Steven Lim
Released:
February 18th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Successful Device Code Authentication Unmanaged Device
AADSignInEventsBeta
SigninLogs
Author:
Bert-Jan Pals
Released:
February 17th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Waffles Exploits Shellcode In Image Files
DeviceFileEvents
Author:
Steven Lim
Released:
February 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
KQL Obfus Guard Detecting Arg Fuscator Obfuscation
KQLObfusGuard
DeviceEvents
Author:
Steven Lim
Released:
February 16th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
The Hunt For Top 10 Self Hosted AI
ExposureGraphNodes
DeviceFileEvents
Author:
Steven Lim
Released:
February 15th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Endpoints With Critical Logged On Users And Shares With Permission Set To Everyone
IdentityInfo
DeviceInfo
DeviceTvmSecureConfigurationAssessment
Author:
Michalis Michalos
Released:
February 12nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Check Link From Email
EmailEvents
UrlClickEvents
EmailUrlInfo
EmailAttachmentInfo
DeviceEvents
DeviceFileEvents
DeviceImageLoadEvents
DeviceProcessEvents
Author:
Jose Sebastián Canós
Released:
February 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Check Email
EmailEvents
EmailUrlInfo
UrlClickEvents
EmailAttachmentInfo
DeviceEvents
DeviceFileEvents
DeviceImageLoadEvents
DeviceProcessEvents
Author:
Jose Sebastián Canós
Released:
February 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting For Malicious Login Attempts Based On Basic Authentication
AADSignInEventsBeta
Author:
Sergio Albea
Released:
February 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Monitoring Copilot Data Exfiltration Via Graph API
MicrosoftGraphActivityLogs
Author:
Steven Lim
Released:
February 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
LLM Hunting In A MDE Environment
ExposureGraphNodes
DeviceFileEvents
Author:
Steven Lim
Released:
February 11st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Using Graph Pre Consent Explorer Data For Microsoft Graph Threat Hunting
MicrosoftGraphActivityLogs
GraphPreConsent
Author:
Steven Lim
Released:
February 10th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Software Download Sites Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 9th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Creation Of Spoof Directories With Unicode Characters
DeviceFileEvents
Author:
Jay Kerai
Released:
February 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
HTTP Client Tools Exploitation For ATO Detection
CloudAppEvents
Author:
Steven Lim
Released:
February 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AWS No Such Bucket Check
AWSCloudTrail
Author:
Steven Lim
Released:
February 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra QR Code Sign In KQL Detection
AuditLogs
Author:
Steven Lim
Released:
February 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR Custom Detection Modifications
CloudAppEvents
Author:
Jay Kerai
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE MMA Agent Cleanup
DeviceNetworkEvents
DeviceProcessEvents
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Antivirus Domains MDE Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Usage Latest
Usage
DeviceFileEvents
DeviceProcessEvents
DeviceLogonEvents
DeviceRegistryEvents
DeviceNetworkEvents
DeviceNetworkInfo
DeviceInfo
DeviceImageLoadEvents
DeviceEvents
DeviceFileCertificateInfo
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Windows11 Issues OS Build 26100 2033
DeviceTvmSoftwareVulnerabilities
DeviceInfo
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Windows OLE Zero Click Vulnerability Let Attacker To Execute Arbitrary Code
EmailAttachmentInfo
EmailEvents
Author:
Sergio Albea
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Crowdstrike Impersonation During Global Outage
CrowdstrikeIOCs
EmailUrlInfo
EmailEvents
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Block List Project Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Adult Content MDE Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sysinternals Tools Zero Day Vulnerability Detection
SysinternalsTools
DeviceEvents
Author:
Steven Lim
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Extracting Bits Of TCP Flags
DeviceNetworkEvents
Author:
Sergio Albea
Released:
February 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Azure RBAC Elevated Access
AuditLogs
Author:
Jose Sebastián Canós
Released:
February 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Active Directory Domain Services Elevation Of Privilege Vulnerability CVE 2025 21293
DeviceInfo
DeviceEvents
DeviceRegistryEvents
Author:
Steven Lim
Released:
February 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ROSTI Repackaged Open Source Intelligence MDE Network Events IOC Hits
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ROSTI Repackaged Open Source Intelligence MDE File Events IOC Hits
DeviceFileEvents
Author:
Jay Kerai
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Rogue Endpoints Via SMB Detection
DeviceEvents
Author:
Steven Lim
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Anonymous Email Sending Domains MDE Traffic
DeviceNetworkEvents
Author:
Jay Kerai
Released:
January 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Global Admin Elevations To User Access Administrator At Root Level
AuditLogs
Author:
Jay Kerai
Released:
January 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Windows File Explorer Elevation Of Privilege Vulnerability CVE 2024 38100 Exploited
DeviceProcessEvents
DeviceInfo
Author:
Sergio Albea
Released:
January 30th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Malicious Impersonation Of Deepseek Domains In Email UR Ls
EmailUrlInfo
EmailEvents
Author:
Steven Lim
Released:
January 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect User Request Token For Admin App
SigninLogs
IdentityInfo
Author:
Robbe Van den Daele
Released:
January 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Securing Your Azure Cloud Finding The Weakest Link In Admin Endpoints
ExposureGraphEdges
ExposureGraphNodes
Author:
Steven Lim
Released:
January 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Token Stealing With Wdac
DeviceEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Suspicious Ca Changes
AuditLogs
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Nnr Health Issues
DeviceNetworkInfo
DeviceNetworkEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Public Devices With Tag
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Devices Supporting Mde Containment
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Public Devices Over Time
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X