Query Details
# KQL Community Repositories | Link | Description | Stars | | ------ | ----------- | ----- | | [Azure Sentinel Repository - Azure](https://github.com/Azure/Azure-Sentinel) | Cloud-native SIEM for intelligent security analytics for your entire enterprise | | | [Sentinel-Queries - reprise99](https://github.com/reprise99/Sentinel-Queries) | Collection of KQL queries |  | | [Falcon Friday - FalconForceTeam](https://github.com/FalconForceTeam/FalconFriday) | Hunting queries and detections |  | | [Threat-Hunting-and-Detection - Cyb3r-Monk](https://github.com/Cyb3r-Monk/Threat-Hunting-and-Detection) | Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language). |  | | [Hunting-Queries-Detection-Rules - Bert-JanP](https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules) | KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. |  | | [AzSentinelQueries - f-bader](https://github.com/f-bader/AzSentinelQueries) | Repository with Sentinel Analytics Rules and Hunting Queries |  | | [KQL-threat-hunting-queries - cyb3rmik3](https://github.com/cyb3rmik3/KQL-threat-hunting-queries) | A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender). |  | | [KQL - Wortell](https://github.com/wortell/KQL) | KQL queries for Advanced Hunting |  | | [SentinelKQL - rod-trent](https://github.com/rod-trent/SentinelKQL) | Azure Sentinel KQL |  | | [Sentinel_KQL - ep3p](https://github.com/ep3p/Sentinel_KQL) | In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool). |  | | [AdvancedHuntingQueries - lawndoc](https://github.com/lawndoc/AdvancedHuntingQueries) | Microsoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenant |  | | [MDATP AdvancedHunting - JesseEsquivel](https://github.com/JesseEsquivel/MDATP/tree/master/AdvancedHunting) | Microsoft Defender Advanced Threat Protection |  | | [KQL - mjmelone](https://github.com/mjmelone/KQL/tree/master) | Michael Melone's Kusto Query library |  | | [AzureSentinel - Cloud-Architekt](https://github.com/Cloud-Architekt/AzureSentinel) | Sharing my KQL queries for Azure Sentinel |  | | [Hunting-Queries-Detection-Rules - alexverboon](https://github.com/alexverboon/Hunting-Queries-Detection-Rules) | KQL Queries. Microsoft 365 Defender, Microsoft Sentinel |  | | [KQL Security Queries - Shivammalaviya](https://gist.github.com/Shivammalaviya) | KQL Security Queries |  | | [Invictus-training - KQL-QueryPack - invictus-ir](https://github.com/invictus-ir/Invictus-training/tree/main/KQL-QueryPack) | Invictus: Cloud Incident Response Query Pack |  | | [DefenderATPQueries - 0xAnalyst](https://github.com/0xAnalyst/DefenderATPQueries) | Hunting Queries for Defender ATP |  | | [LearningKijo/KQL](https://github.com/LearningKijo/KQL) | Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint. |  | | [ awesomekql - awesomekql ](https://github.com/cylaris/awesomekql) | Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs |  | | [Hunting-Queries-Detection-Rules - KustoKing](https://github.com/KustoKing/Hunting-Queries-Detection-Rules) | KQL Detections for Microsoft Sentinel and Microsoft 365 Defender |  | [KQL- mr-r3b00t](https://github.com/mr-r3b00t/KQL) | This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet |  | [MustLearnKQL - rod-trent](https://github.com/rod-trent/MustLearnKQL) | Code included as part of the MustLearnKQL blog series |  | | [kql-for-dfir - reprise99](https://github.com/reprise99/kql-for-dfir) | A guide to using Azure Data Explorer and KQL for DFIR |  | | [Invictus-training - Invictus](https://github.com/invictus-ir/Invictus-training/tree/main/KQL-QueryPack) | Cloud Incident Response Query Pack |  | | [MDATP - JesseEsquivel](https://github.com/JesseEsquivel/MDATP/tree/master/AdvancedHunting) | Microsoft Defender Advanced Threat Protection |  | | [DefenderATPQueries - 0xAnalyst](https://github.com/0xAnalyst/DefenderATPQueries) | Hunting Queries for Defender ATP |  | | [KQL - LearningKijo](https://github.com/LearningKijo/KQL) | Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint. |  | | [KQL - KostasKoutrou](https://github.com/KostasKoutrou/KQL/tree/main) | KQL Queries for Advanced Hunting / Log Analytics |  | | [Sentinel-queries - samilamppu](https://github.com/samilamppu/Sentinel-queries) | Sentinel-queries |  | | [Hunting-Queries-Detection-Rules - SlimKQL](https://github.com/SlimKQL/Hunting-Queries-Detection-Rules) | KQL Queries. Microsoft Defender, Microsoft Sentinel |  | | [KustQueryLanguage_kql - m4nbat](https://github.com/m4nbat/KustQueryLanguage_kql) | Cyber Defence related kusto queries for use in Azure Sentinel and Defender advanced hunting |  | | [DE-TH-Aura - SecurityAura](https://github.com/SecurityAura/DE-TH-Aura/tree/main) | Repository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration). |  |
This query lists various GitHub repositories related to Kusto Query Language (KQL) and their applications in security analytics, particularly with Microsoft Sentinel and Microsoft Defender. Each entry includes a link to the repository, a brief description of its content or focus, and a badge displaying the number of stars the repository has received on GitHub. These repositories contain collections of KQL queries for tasks such as threat hunting, detection, and advanced hunting in cloud environments.

Bert-Jan Pals
Released: November 3, 2024
Tables
Keywords
Operators