KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
News
Popular
Stats
Device
Newsletter
Popular Queries
Statistics
Device Query
SentinelHealth
Sentinel Health Scheduled Analytics Rule Runs Anomaly
Jose Sebastián Canós
|
Mar 12, 2026
Copy
View
DeviceProcessEvents
Advanced Multi Stage Windows Enumeration Post Exploitation Detector
Benjamin Zulliger
|
Mar 10, 2026
Copy
View
DeviceNetworkEvents
Potential Beaconing Activity
Bert-Jan Pals
|
Mar 9, 2026
Copy
View
DeviceProcessEvents
Advanced Multi Stage Linux Enumeration Post Exploitation Detector
Benjamin Zulliger
|
Mar 9, 2026
Copy
View
DeviceEvents
Process Primary Token Elevated To Se Debug Priv
Bert-Jan Pals
|
Mar 8, 2026
Copy
View
DeviceEvents
Scheduled Tasks From App Data Created Or Updated
Bert-Jan Pals
|
Mar 7, 2026
Copy
View
DeviceProcessEvents
DeviceEvents
Defender Exclusion Events
Bert-Jan Pals
|
Mar 7, 2026
Copy
View
DeviceEvents
Rare Lnk File Created On Desktop
Bert-Jan Pals
|
Mar 7, 2026
Copy
View
AuditLogs
AADSignInEventsBeta
Detection Of High Risk Sign Ins From New Or Uncommon I Ps With User Agent Or OS Changes
Benjamin Zulliger
|
Mar 3, 2026
Copy
View
DeviceNetworkEvents
Monitoring Explorer Initiated External Traffic
Sergio Albea
|
Mar 1, 2026
Copy
View
CopilotActivity
Excessive Copilot Prompt Activity
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
CopilotActivity
Microsoft Copilot Access To External Resources XPIA
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
CloudAppEvents
Microsoft Copilot Jailbreak Detected
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
DeviceProcessEvents
Attempt To Disable Syslog Service
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
DeviceProcessEvents
Attempt To Disable Auditd Service
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
ADOAuditLogs_CL
Azure Dev Ops Activity From Newor Rare IP Outside Business Hours
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
ADOAuditLogs_CL
Azure Dev Ops Critical Search Queries
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
ADOAuditLogs_CL
Azure Dev Ops Critical Permission Modification
Benjamin Zulliger
|
Feb 26, 2026
Copy
View
LOLDrivers
DeviceEvents
MDE Asr Vulnerable Signed Driver Blocked
Alex Verboon
|
Feb 23, 2026
Copy
View
DeviceProcessEvents
Click Fix Lo L Bin Abuse
Benjamin Zulliger
|
Feb 23, 2026
Copy
View
DeviceProcessEvents
Click Fix Nslookup DNS Staging
Benjamin Zulliger
|
Feb 23, 2026
Copy
View
DeviceRegistryEvents
Run MRU Click Fix Detection
Benjamin Zulliger
|
Feb 23, 2026
Copy
View
SecurityIncident
SecurityAlert
Alert Efficiency
Bert-Jan Pals
|
Feb 22, 2026
Copy
View
EntraIdSignInEvents
Entra Id Sign In Events Suspicious User Agent
Jay Kerai
|
Feb 17, 2026
Copy
View
EntraIdSignInEvents
Entra Id Sign In Events Hunting Potential Seamless SSO Usage
Jay Kerai
|
Feb 17, 2026
Copy
View
DeviceEvents
DeviceNetworkInfo
Windows Summarise Firewall Outbound Blocks By Firewall Profile
Nathan Hutchinson
|
Feb 17, 2026
Copy
View
DeviceEvents
DeviceNetworkInfo
Windows Outbound Firewall Blocks Filtered By Firewall Profile
Nathan Hutchinson
|
Feb 17, 2026
Copy
View
DeviceEvents
DeviceNetworkInfo
Windows Outbound Firewall Blocks Filter By Device And Firewall Profile
Nathan Hutchinson
|
Feb 17, 2026
Copy
View
DeviceEvents
DeviceNetworkInfo
Windows Windows Firewall Outbound Blocked Connections
Nathan Hutchinson
|
Feb 17, 2026
Copy
View
AuditLogs
Security Copilot Agent Deleted
Jay Kerai
|
Feb 17, 2026
Copy
View
DeviceNetworkEvents
Windows Find Net BIOS Name Service NBNS Usage UDP 137
Nathan Hutchinson
|
Feb 15, 2026
Copy
View
EmailEvents
EmailUrlInfo
Applying Shanon Entropy To Sender Domains Via Kusto
Sergio Albea
|
Feb 12, 2026
Copy
View
IdentityLogonEvents
Windows Detect NTLM Usage In The Environment
Nathan Hutchinson
|
Feb 12, 2026
Copy
View
DeviceEvents
Windows Inbound Firewall Blocks By Process
Nathan Hutchinson
|
Feb 12, 2026
Copy
View
DeviceEvents
Windows All Firewall Inbound Block Events Last 100
Nathan Hutchinson
|
Feb 12, 2026
Copy
View
DeviceTvmSoftwareVulnerabilities
DeviceProcessEvents
DeviceFileEvents
+2
CVE 2026 21510 Windows Shell Security Feature Bypass
Benjamin Zulliger
|
Feb 11, 2026
Copy
View
EntraUsers
Detection Enrichment Entra User
Bert-Jan Pals
|
Feb 11, 2026
Copy
View
EntraGroupMemberships
EntraGroups
Detection Enrichment Entra Group Membership
Bert-Jan Pals
|
Feb 10, 2026
Copy
View
DeviceNetworkEvents
Device IP History
C.J. May
|
Feb 10, 2026
Copy
View
MessageEvents
IdentityInfo
MessageUrlInfo
Detect External User Sending Suspicious Link To Multiple Users
Robbe Van den Daele
|
Feb 10, 2026
Copy
View
MessageEvents
IdentityInfo
Detect Possible Teams Bec Attack By High Teams Recipients
Robbe Van den Daele
|
Feb 10, 2026
Copy
View
MessageEvents
MessageUrlInfo
Detect Malicious Teams Message
Robbe Van den Daele
|
Feb 10, 2026
Copy
View
DeviceRegistryEvents
Image File Execution Options IFEO Or Silent Process Exit Registry Modification
Benjamin Zulliger
|
Feb 9, 2026
Copy
View
DeviceFileEvents
Malicious Browser Extension Downloads Using Device File Events
Jay Kerai
|
Feb 8, 2026
Copy
View
SigninLogs
AADNonInteractiveUserSignInLogs
Detect Potential Consent Fix O Auth Authorisation Code Theft Attempts
Jay Kerai
|
Feb 5, 2026
Copy
View
AuditLogs
MCP Server Registered To Entra
Jay Kerai
|
Feb 5, 2026
Copy
View
AuditLogs
Service Principal Added To Global Administrator Role
Fabian Bader
|
Feb 5, 2026
Copy
View
AuditLogs
Service Principal Adds Client Secret To Target Application
Fabian Bader
|
Feb 5, 2026
Copy
View
StorageBlobLogs
Potential Storage Enumeration Or Brute Force Attack
Fabian Bader
|
Feb 5, 2026
Copy
View
AuditLogs
Privileged Role Assignment Outside Of PIM
Fabian Bader
|
Feb 5, 2026
Copy
View