<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://kqlsearch.com/</loc>
    <changefreq>daily</changefreq>
    <priority>1.0</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/ai</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/devicequery</loc>
    <changefreq>monthly</changefreq>
    <priority>0.8</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/faq</loc>
    <changefreq>monthly</changefreq>
    <priority>0.5</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20TLS%20validation%20bypass%20via%20PowerShell&amp;cmniwj67z0000z5o8c830enkh</loc>
    <lastmod>2026-04-03T12:50:37.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20Claude%20Behavior&amp;cmngf3y0a0000h9aa9q0d1dp4</loc>
    <lastmod>2026-04-01T19:07:20.937Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GitForcePush&amp;cmng2011r0006pvxfz8iv2eok</loc>
    <lastmod>2026-04-01T13:00:23.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GitAbuseHighFidelity&amp;cmng1zw8w0005pvxf73fwnwif</loc>
    <lastmod>2026-04-01T13:00:17.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Execution_Git_Commit_Amend_NoVerify&amp;cmng1zos40004pvxfdu9bk0mu</loc>
    <lastmod>2026-04-01T13:00:07.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Execution_Batch_Git_Abuse&amp;cmng1zg7h0003pvxfc8tdwwgz</loc>
    <lastmod>2026-04-01T12:59:56.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenseEvasion_TimeChange_Git&amp;cmng1zb5c0002pvxfb1cd3msj</loc>
    <lastmod>2026-04-01T12:59:49.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenseEvasion_Git_Config_Masquerade&amp;cmng1z3vx0001pvxf9pre5lcg</loc>
    <lastmod>2026-04-01T12:59:40.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Correlation_Git_And_VSCode_Task_Abuse&amp;cmng1yu3i0000pvxfi09qajx0</loc>
    <lastmod>2026-04-01T12:59:27.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Privileged%20RDP%20Session%20Source%20Mismatch&amp;cmnemru9d00019xmu6vv3c7qz</loc>
    <lastmod>2026-03-31T13:06:20.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IFEO%20%E2%80%93%20Unauthorized%20Debugger%20Registration&amp;cmnemrhe700009xmud6nyq6gt</loc>
    <lastmod>2026-03-31T13:06:03.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/macOS%20Suspicious%20Shell%20or%20Direct%20Process%20Execution%20from%20Browser&amp;cmnd7kwok000156ok39eirfoj</loc>
    <lastmod>2026-03-30T13:13:16.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20TVM%20Secure%20Configuration%20Assessment%20Summary&amp;cmnd7kcyg000056okve85z03a</loc>
    <lastmod>2026-03-30T13:12:51.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VsCodePersistence&amp;cmnc3t7uf000211e892xcnpep</loc>
    <lastmod>2026-03-29T18:39:59.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PolinRiderNode&amp;cmnc3svem000111e85awrvgd2</loc>
    <lastmod>2026-03-29T18:39:43.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NodeC2Polinder&amp;cmnc3sjaz000011e8m3ufth1a</loc>
    <lastmod>2026-03-29T18:39:28.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20-%20AzureActivityCompromisedAccount&amp;cmn3wpbfo000114gy7pjur3tu</loc>
    <lastmod>2026-03-24T00:58:51.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulSigninFromSuspiciousUserAgent&amp;cmn3wp2qq000014gywovst3xc</loc>
    <lastmod>2026-03-24T00:58:40.033Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Local%20Administrator%20Account%20added%20by%20Scheduled%20Task&amp;cmn3k5qjd0000di44totyk5xd</loc>
    <lastmod>2026-03-23T19:07:42.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender%20IOC%20Warning%20Bypass%20or%20Monitor%20Mode%20MDA%20bypass&amp;cmmxuabq80000u5znnd0r0gt4</loc>
    <lastmod>2026-03-19T19:04:35.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/List%20Devices%20(Array)&amp;cmmwf2te70001y4e34un6aszb</loc>
    <lastmod>2026-03-18T19:11:04.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20user%20account%20authentication&amp;cmmwe7kxv0000y4e3jabzoeuc</loc>
    <lastmod>2026-03-18T18:46:47.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIC%5D%20-%20Catching%20emojis%20on%20email%20Subjects&amp;cmmvcldeh0002znasia4ra5o3</loc>
    <lastmod>2026-03-18T01:13:45.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIC%5D%20-%20Catching%20Emojis%20into%20Email%20Attachment%20Files%20names&amp;cmmvcl6mf0001znasxzzjp6db</loc>
    <lastmod>2026-03-18T01:13:36.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIC%5D%20-%20Catching%20Emojis%20into%20File%20Names&amp;cmmvckqog0000znas1vb31hkt</loc>
    <lastmod>2026-03-18T01:13:15.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-FileMaliciousContentInfo&amp;cmmt6gkhn0000rdmx0i5sxcjw</loc>
    <lastmod>2026-03-16T12:46:31.354Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelHealth-Scheduled%20analytics%20rule%20runs%20anomaly&amp;cmmng9yh60000gffdlwldmutt</loc>
    <lastmod>2026-03-12T12:34:41.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Advanced%20Multi-Stage%20Windows%20Enumeration%20%26%20Post-Exploitation%20Detector&amp;cmmkme3fx00009yo4s175pkrl</loc>
    <lastmod>2026-03-10T13:02:34.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialBeaconingActivity&amp;cmmjwpy5q00001kdlq4fz4oij</loc>
    <lastmod>2026-03-10T01:03:57.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Advanced%20Multi-Stage%20Linux%20Enumeration%20%26%20Post-Exploitation%20Detector&amp;cmmjjoweg00006ea217ewxtkk</loc>
    <lastmod>2026-03-09T18:59:13.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ProcessPrimaryTokenElevatedToSeDebugPriv&amp;cmmi340va000071oafk9xrerc</loc>
    <lastmod>2026-03-08T18:27:19.179Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ScheduledTasksFromAppDataCreatedOrUpdated&amp;cmmgnxsxo00023cvq4bwmc6gb</loc>
    <lastmod>2026-03-07T18:34:48.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RareLnkFileCreatedOnDesktop&amp;cmmgnxkfa00013cvqcf2p82pf</loc>
    <lastmod>2026-03-07T18:34:37.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderExclusionEvents&amp;cmmgnx1z300003cvq05s8qz6s</loc>
    <lastmod>2026-03-07T18:34:13.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20of%20High-Risk%20Sign-ins%20from%20New%20or%20Uncommon%20IPs%20with%20User%20Agent%20or%20OS%20Changes&amp;cmmbc9u2g0000r4ole3kyjfql</loc>
    <lastmod>2026-03-04T01:09:23.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20Explorer-Initiated%20External%20Traffic&amp;cmm8ha5rj000012w1nsc8o4d5</loc>
    <lastmod>2026-03-02T01:06:18.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Copilot%20Jailbreak%20Detected&amp;cmm3ttfbo00042pbnvo26ccex</loc>
    <lastmod>2026-02-26T18:58:21.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Attempt%20to%20Disable%20Syslog%20Service&amp;cmm3tt47c00032pbn0fqhde2t</loc>
    <lastmod>2026-02-26T18:58:07.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Attempt%20to%20Disable%20Auditd%20Service&amp;cmm3tsytu00022pbn75jfqq02</loc>
    <lastmod>2026-02-26T18:58:00.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Copilot%20Access%20to%20External%20Resources%20(XPIA)&amp;cmm3tsna600012pbnd6al1rd7</loc>
    <lastmod>2026-02-26T18:57:45.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Excessive%20Copilot%20Prompt%20Activity&amp;cmm3tsgpw00002pbn6zst1iuz</loc>
    <lastmod>2026-02-26T18:57:36.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20DevOps%20Activity%20from%20Newor%20Rare%20IP%20Outside%20Business%20Hours&amp;cmm3gwa2x000214by8brfxrds</loc>
    <lastmod>2026-02-26T12:56:39.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20DevOps%20Critical%20Search%20Queries&amp;cmm3gvzl6000114by22rwdqjr</loc>
    <lastmod>2026-02-26T12:56:26.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20DevOps%20Critical%20Permission%20Modification&amp;cmm3gvs7k000014by05k0t72y</loc>
    <lastmod>2026-02-26T12:56:16.783Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-AsrVulnerableSignedDriverBlocked&amp;cmlzwhhwq0000m9umrdgavj88</loc>
    <lastmod>2026-02-24T01:01:59.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RunMRU%20ClickFix%20Detection&amp;cmlz6jl830002898r4f5yfxrn</loc>
    <lastmod>2026-02-23T12:55:46.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ClickFix%20Nslookup%20DNS%20Staging&amp;cmlz6jf1c0001898r0gaxcmwx</loc>
    <lastmod>2026-02-23T12:55:38.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ClickFix%20LoLBin%20Abuse&amp;cmlz6j9q20000898rwq3ifqee</loc>
    <lastmod>2026-02-23T12:55:31.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AlertEfficiency&amp;cmlxqhpu50000bf2b1mp2i84d</loc>
    <lastmod>2026-02-22T12:38:39.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Windows%20Firewall%20Outbound%20Blocked%20Connections&amp;cmlqz1j3h0005oncwcuu6fhbk</loc>
    <lastmod>2026-02-17T19:03:37.562Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Summarise%20Firewall%20Outbound%20Blocks%20by%20Firewall%20Profile&amp;cmlqz1b5g0004oncw40l6cako</loc>
    <lastmod>2026-02-17T19:03:27.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Outbound%20Firewall%20Blocks%20(Filtered%20by%20Firewall%20Profile)&amp;cmlqz15u50003oncwlse5hdwy</loc>
    <lastmod>2026-02-17T19:03:20.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Outbound%20Firewall%20Blocks%20(Filter%20by%20Device%20and%20Firewall%20Profile)&amp;cmlqz0x6p0002oncwtscf8bbd</loc>
    <lastmod>2026-02-17T19:03:09.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraIdSignInEvents%20-%20Suspicious%20User%20agent&amp;cmlqyz3d10001oncw0cybnzw5</loc>
    <lastmod>2026-02-17T19:01:43.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraIdSignInEvents%20-%20Hunting%20Potential%20Seamless%20SSO%20Usage&amp;cmlqyynhe0000oncwu8tvcou0</loc>
    <lastmod>2026-02-17T19:01:23.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Security%20Copilot%20Agent%20Deleted&amp;cmlqlnipr0000a9k4ln09uw0s</loc>
    <lastmod>2026-02-17T12:48:48.930Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Find%20NetBIOS%20Name%20Service%20(NBNS)%20Usage%20(UDP%2C%20137)&amp;cmlohfgb900004zcn1dunlf5v</loc>
    <lastmod>2026-02-16T01:15:01.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Applying%20Shanon%20Entropy%20to%20SenderDomains%20via%20Kusto&amp;cmlk76m330000147rukzqhuls</loc>
    <lastmod>2026-02-13T01:17:08.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Inbound%20firewall%20blocks%20(by%20process)&amp;cmljgmnv10002y6f5fukplvb7</loc>
    <lastmod>2026-02-12T12:53:47.724Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Detect%20NTLM%20usage%20in%20the%20environment&amp;cmljgmjja0001y6f58a21rkcf</loc>
    <lastmod>2026-02-12T12:53:42.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20All%20firewall%20inbound%20block%20events%20(last%20100)&amp;cmljgmcq60000y6f5pmb53smo</loc>
    <lastmod>2026-02-12T12:53:33.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2026-21510%20-%20Windows%20Shell%20Security%20Feature%20Bypass&amp;cmlie9lhe0001n477v7ycgt72</loc>
    <lastmod>2026-02-11T18:59:52.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20Enrichment%20-%20Entra%20User&amp;cmlidtdcz0000n4773oqcyble</loc>
    <lastmod>2026-02-11T18:47:15.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20Enrichment%20-%20Entra%20Group%20Membership&amp;cmlhbzhuh0000bx7ykdfx8cz6</loc>
    <lastmod>2026-02-11T01:08:15.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceIPHistory&amp;cmlgys0ae0000kedf3f16yi3f</loc>
    <lastmod>2026-02-10T18:58:31.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectPossibleTeamsBecAttackByHighTeamsRecipients&amp;cmlgkx34d00022oczsui1fcs1</loc>
    <lastmod>2026-02-10T12:30:33.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectMaliciousTeamsMessage&amp;cmlgkwvsw00012oczu4z96l82</loc>
    <lastmod>2026-02-10T12:30:24.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectExternalUserSendingSuspiciousLinkToMultipleUsers&amp;cmlgkwpnw00002ocz2m90dt7w</loc>
    <lastmod>2026-02-10T12:30:16.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Image%20File%20Execution%20Options%20(IFEO)%20or%20SilentProcessExit%20Registry%20Modification&amp;cmlf6n8on0000dnac2b5rw95g</loc>
    <lastmod>2026-02-09T13:03:13.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20Browser%20Extension%20Downloads%20using%20DeviceFileEvents&amp;cmldqr0ca0000krg1p8pxlyvx</loc>
    <lastmod>2026-02-08T12:50:29.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20potential%20ConsentFix%20OAuth%20authorisation%20code%20theft%20attempts&amp;cmla6rwf80000xmxv8jj3ut9u</loc>
    <lastmod>2026-02-06T01:08:00.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MCP%20Server%20Registered%20to%20Entra&amp;cml9teit10000x46pl1qcjwxu</loc>
    <lastmod>2026-02-05T18:53:41.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnauthorizedFederatedCredentialAddedToManagedIdentity&amp;cml9geanv000a12v2j3awnox9</loc>
    <lastmod>2026-02-05T12:49:35.454Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulAzureStorageFileAccessFromUnauthorizedGeoLocation&amp;cml9gdyfw000912v207j8gxzw</loc>
    <lastmod>2026-02-05T12:49:19.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServicePrincipalSignInFromNewCountry&amp;cml9gdstr000812v2j8pzp927</loc>
    <lastmod>2026-02-05T12:49:11.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServicePrincipalEnumerationOfAppRoleAssignments&amp;cml9gdl8z000712v2sfxudcpq</loc>
    <lastmod>2026-02-05T12:49:02.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServicePrincipalAddsClientSecretToTargetApplication&amp;cml9gd9r1000612v2r0h5h34k</loc>
    <lastmod>2026-02-05T12:48:47.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServicePrincipalAddedToGlobalAdministratorRole&amp;cml9gd1wy000512v2vz4mwt13</loc>
    <lastmod>2026-02-05T12:48:37.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrivilegedRoleAssignmentOutsideOfPIM&amp;cml9gcup5000412v243e0xk7r</loc>
    <lastmod>2026-02-05T12:48:28.264Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialStorageEnumerationOrBruteForceAttack&amp;cml9gcpdu000312v279esfm89</loc>
    <lastmod>2026-02-05T12:48:21.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GrantingOfHighRiskPrivilegeEscalationPermissionsToServicePrincipal&amp;cml9gch2q000212v2by9pbs2s</loc>
    <lastmod>2026-02-05T12:48:10.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzurekidBlackcatSecurityModuleActivity&amp;cml9gc82s000112v2df9lhxn6</loc>
    <lastmod>2026-02-05T12:47:58.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnonymousRetrievalOfAzureBlobVersions&amp;cml9gc0mc000012v2arnmtspq</loc>
    <lastmod>2026-02-05T12:47:49.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Notepad%2B%2B%20-%20Chrysalis%20Backdoor%20gup.exe%20spawned%20binaries%20excluding%20known-good%20Notepad%2B%2B%20hashes&amp;cml6leu1w0002121xwpq14s0p</loc>
    <lastmod>2026-02-03T12:46:40.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Notepad%2B%2B%20-%20Chrysalis%20Backdoor%20gup.exe%20detection&amp;cml6lelsn0001121xky6e11x4</loc>
    <lastmod>2026-02-03T12:46:29.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Notepad%2B%2B%20-%20Chrysalis%20Backdoor%20Spawned%20binaries%20%2B%20network%20connections%20correlation&amp;cml6lebtt0000121x5fhxztxf</loc>
    <lastmod>2026-02-03T12:46:16.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Trigger%20full%20scan%20for%20devices%20that%20have%20not%20completed%20one&amp;cml5x3nhr000j3h8twrr7fv6p</loc>
    <lastmod>2026-02-03T01:26:07.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Trigger%20full%20scan%20for%20devices%20that%20have%20not%20completed%20one%20(Windows%20Clients%20only)&amp;cml5x3gw2000i3h8tamicsmrf</loc>
    <lastmod>2026-02-03T01:25:59.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Auto%20Disable%20High%20Risk%20AD%20User&amp;cml5x3916000h3h8t3292cf8h</loc>
    <lastmod>2026-02-03T01:25:49.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Emergency%20Access%20Usage%20Alert&amp;cml5x333q000g3h8ts3qqf1qv</loc>
    <lastmod>2026-02-03T01:25:41.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20RBAC%20Elevation%20via%20User%20Access%20Admin%20toggle&amp;cml5x2vkd000f3h8tcrcc75y2</loc>
    <lastmod>2026-02-03T01:25:31.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20-%20Recent%20Devices%20Missing%20Full%20Scan&amp;cml5x2ldw000e3h8tfij5swvi</loc>
    <lastmod>2026-02-03T01:25:17.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Suspicious%20Cron%20Persistence&amp;cml5x2ejp000d3h8tf30hiums</loc>
    <lastmod>2026-02-03T01:25:09.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Script%20Activity%20(ScriptContent)&amp;cml5x28pn000c3h8thfw53gte</loc>
    <lastmod>2026-02-03T01:25:01.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Network%20Events%20Baseline%20(ReportId%20Dedupe)&amp;cml5x2375000b3h8tagl59xeb</loc>
    <lastmod>2026-02-03T01:24:54.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Logon%20Activity&amp;cml5x1ya7000a3h8t22xfz2ur</loc>
    <lastmod>2026-02-03T01:24:48.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20LOLbin%20Downloads%20to%20Temporary%20Directories&amp;cml5x1s2h00093h8tybe2o7tl</loc>
    <lastmod>2026-02-03T01:24:40.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20File%20Activity%20Baseline&amp;cml5x1j0p00083h8tlssrxc0m</loc>
    <lastmod>2026-02-03T01:24:28.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Archive%20Command%20Followed%20by%20Upload%20Egress&amp;cml5x1cpb00073h8t8l5jluuv</loc>
    <lastmod>2026-02-03T01:24:20.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20Antivirus%20Activity&amp;cml5x15hl00063h8tk319jhjs</loc>
    <lastmod>2026-02-03T01:24:11.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20%E2%80%93%20ActionType%20Inventory%20(All%20Tables)&amp;cml5x0wr300053h8t5d60hu8s</loc>
    <lastmod>2026-02-03T01:23:59.674Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20Server%20%E2%80%93%20Public%20Egress%20Baseline%20(High%20Fidelity)&amp;cml5x0pqf00043h8tpjvb31b3</loc>
    <lastmod>2026-02-03T01:23:50.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20Desktop%20%E2%80%93%20Public%20Egress%20Baseline%20(Low%20Noise)&amp;cml5x0h0e00033h8tqe5ba5hl</loc>
    <lastmod>2026-02-03T01:23:39.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20-%20User%20activity%20leading%20up%20to%20exfiltration&amp;cml5x07tj00023h8tgceu8f7l</loc>
    <lastmod>2026-02-03T01:23:27.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20-%20Telemetry%20Validation%20Test%20(Process)&amp;cml5x01aj00013h8ttz4yjxpg</loc>
    <lastmod>2026-02-03T01:23:18.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20-%20Network%20fan%E2%80%91out%20from%20the%20upload%20process&amp;cml5wzri700003h8toscq6oox</loc>
    <lastmod>2026-02-03T01:23:06.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Notepad%2B%2B%20-%20Chrysalis%20Backdoor%20Network%20IOCs&amp;cml5iqsrg0001304fubm3357b</loc>
    <lastmod>2026-02-02T18:44:13.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Notepad%2B%2B%20-%20Chrysalis%20Backdoor%20File%20Hash%20IOCs&amp;cml5iqn3x0000304f0tigybwr</loc>
    <lastmod>2026-02-02T18:44:06.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Office%20Security%20Feature%20Bypass%20Vulnerability%20CVE-2026-21509&amp;cmkwlg4zk0000tn2cws5atixe</loc>
    <lastmod>2026-01-27T12:49:59.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntAccountsWithLeakedCredentials&amp;cmkv4vrrt0000dzc47xk8mw10</loc>
    <lastmod>2026-01-26T12:18:28.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/sign_in_risk_analysis&amp;cmksaeg6c0001d4m3h5tabnud</loc>
    <lastmod>2026-01-24T12:29:40.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/authenticator_device_enrollment_country_risk_baseline&amp;cmksae6550000d4m3s2kiwkpz</loc>
    <lastmod>2026-01-24T12:29:26.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIA%5D%20-%20Threat%20Intelligence%20Feed%20Evaluation%20based%20on%20URL%20IOCs&amp;cmkinlhdj000214il0chao7bn</loc>
    <lastmod>2026-01-17T18:41:21.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIA%5D%20-%20Threat%20Intelligence%20Feed%20Evaluation%20based%20on%20FileHashes%20IOCs&amp;cmkinla5a000114il77o08gaz</loc>
    <lastmod>2026-01-17T18:41:12.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIA%5D%20-%20Threat%20Intelligence%20Feed%20Evaluation%20based%20on%20Domains%20IOCs&amp;cmkinl2zf000014ilwyrwbk36</loc>
    <lastmod>2026-01-17T18:41:02.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20Sign-in%20After%20Phishing%20Link%20Click&amp;cmkft6q4s0000kpaxbg2a6sgw</loc>
    <lastmod>2026-01-15T18:54:31.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20DLLs%20by%20Signer&amp;cmke0d1tr000050d1gbal5y0p</loc>
    <lastmod>2026-01-14T12:39:52.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Certificate%20Issued%20to%20Privileged%20User&amp;cmkcy7rdr0000143ag4keye9x</loc>
    <lastmod>2026-01-13T18:51:59.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectPIMElevationWithUserRisk&amp;cmkb4pk09000713btjs04qowa</loc>
    <lastmod>2026-01-12T12:18:15.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectDeviceCodeWithUserRisk&amp;cmkb4pc5y000613bto2d4ixfp</loc>
    <lastmod>2026-01-12T12:18:05.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectUnsignedExecLaunchFromScheduledTask&amp;cmkb4p35d000513btxcvg0dks</loc>
    <lastmod>2026-01-12T12:17:53.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectUnkownProcessUsingSmbAndWinrm&amp;cmkb4ovxj000413btrnw1687z</loc>
    <lastmod>2026-01-12T12:17:44.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectUnkownProcessLaunchedViaWinRM&amp;cmkb4oofb000313bt1gvzwo8k</loc>
    <lastmod>2026-01-12T12:17:34.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectRareScheduledTaskCreated&amp;cmkb4ogge000213btwonxvqaq</loc>
    <lastmod>2026-01-12T12:17:24.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectMsiexecExecutingDllNetworkConnections&amp;cmkb4o980000113btv80zagef</loc>
    <lastmod>2026-01-12T12:17:14.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectLolDriverDropOrLoadFromUnkownProcess&amp;cmkb4nz0j000013btknln5d0v</loc>
    <lastmod>2026-01-12T12:17:01.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20with%20uncommon%20or%20risky%20behavior%20is%20deploying%20an%20Application%20with%20Intune%20to%20All%20Users%20or%20All%20Devices&amp;cmk4k4iyv0004omo36reg2ioy</loc>
    <lastmod>2026-01-07T21:55:24.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20with%20uncommon%20or%20risky%20behavior%20is%20deploying%20a%20Script%20with%20Intune%20to%20All%20Users%20or%20All%20Devices&amp;cmk4k49jr0003omo3gudiortv</loc>
    <lastmod>2026-01-07T21:55:12.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mass%20Wipe%20or%20Retire%20Device%20Action&amp;cmk4k426c0002omo3cs9s0uo3</loc>
    <lastmod>2026-01-07T21:55:03.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Managed%20Service%20Provider%20User%20(B2B%20or%20GDAP)%20without%20Device%20Compliance%20or%20MFA%20claim%20is%20managing%20Intune&amp;cmk4k3ugl0001omo3wwp0hzsv</loc>
    <lastmod>2026-01-07T21:54:53.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Delete%20an%20Intune%20Multi%20Approval%20Policy%20by%20User%20with%20uncommon%20or%20risky%20behavior&amp;cmk4k3kjx0000omo3nt5fghwa</loc>
    <lastmod>2026-01-07T21:54:40.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConsentFix-HuntingConfidenceOnTokenAndNetworkSignals&amp;cmjx7kdi80000ieuyob2ecv96</loc>
    <lastmod>2026-01-02T18:29:26.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20compromised%20chalk%20packages&amp;cmjud4td1000v12am71khf7g9</loc>
    <lastmod>2025-12-31T18:41:59.461Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/macOS%20User%20added%20to%20Admin%20Group&amp;cmjud4os7000u12amp52xn7ao</loc>
    <lastmod>2025-12-31T18:41:53.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BiDi%20Swap%20URL%20in%20DeviceNetworkEvents&amp;cmjud4ht6000t12amigreojy4</loc>
    <lastmod>2025-12-31T18:41:44.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20URL%20or%20Domain%20Hit%20in%20Teams%20Messages&amp;cmjud4c53000s12amkvv970ng</loc>
    <lastmod>2025-12-31T18:41:37.033Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parse%20Apache%20Access.log&amp;cmjud45d2000r12amutbbx93g</loc>
    <lastmod>2025-12-31T18:41:28.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADSTS_errorcodes_KQL&amp;cmjud3zvd000q12am58r5ybmu</loc>
    <lastmod>2025-12-31T18:41:21.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/macOS%20LoginWindow%20Hooks%20%26%20Authorization%20Plugins&amp;cmjud3vnq000p12amwelubpt4</loc>
    <lastmod>2025-12-31T18:41:15.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/macOS%20Launch%20Agent%20or%20Daemon%20.plist%20File%20Creation%20or%20Modification&amp;cmjud3qru000o12amojuficys</loc>
    <lastmod>2025-12-31T18:41:09.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/macOS%20ClickFix%20Attack%20with%20Base64%20encrypted%20curl%20Command&amp;cmjud3l72000n12am0n5xkc6g</loc>
    <lastmod>2025-12-31T18:41:02.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WScript%5CCScript%20Executing%20JavaScript%20from%20User%20Profile&amp;cmjud3e6r000m12amizd1bsp8</loc>
    <lastmod>2025-12-31T18:40:53.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ValleyRAT_Detection&amp;cmjud39ep000l12am8keavrbv</loc>
    <lastmod>2025-12-31T18:40:46.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Scheduled%20Tasks%20with%20unsigned%20Binaries&amp;cmjud33mc000k12amisqokylc</loc>
    <lastmod>2025-12-31T18:40:39.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Pure%20malware%20family%20Behavior%20Detection&amp;cmjud2xp2000j12amexnnvap0</loc>
    <lastmod>2025-12-31T18:40:31.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShell_Defender_Exclusion_Modification&amp;cmjud2qx3000i12amejb2mqnc</loc>
    <lastmod>2025-12-31T18:40:22.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Obfuscated%20ClickFix%20Powershell%20Command&amp;cmjud2n5p000h12amiy333t9u</loc>
    <lastmod>2025-12-31T18:40:18.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LSASS%20Dump%20via%20comsvcs.dll&amp;cmjud2ib7000g12amf4w5c6hb</loc>
    <lastmod>2025-12-31T18:40:11.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exif%20smuggling%20FileFix%20Detection&amp;cmjud2b9e000f12am7od750u8</loc>
    <lastmod>2025-12-31T18:40:02.689Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EXPLOIT_no-defender-loader-detection&amp;cmjud25et000e12amwl7hfmzz</loc>
    <lastmod>2025-12-31T18:39:54.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Unsigned%20or%20DevSigned%20Appx%20Package%20Installation&amp;cmjud1yxl000d12amrc8tezhj</loc>
    <lastmod>2025-12-31T18:39:46.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CLSID%20override&amp;cmjud1s5o000c12am9oqqu564</loc>
    <lastmod>2025-12-31T18:39:37.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email_GmailSender%20with%20different%20Display%20Names&amp;cmjud1m68000b12amrx3dhlvf</loc>
    <lastmod>2025-12-31T18:39:30.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20IIS%20Logs%20delete&amp;cmjud1glp000a12amfen53hmy</loc>
    <lastmod>2025-12-31T18:39:22.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShell%20LOLBAS%20Execution%20with%20Public%20Network%20Connection&amp;cmjud1bvo000912ambbfs5eo1</loc>
    <lastmod>2025-12-31T18:39:16.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicisous%20Sign%20in%20after%20Network%20Connection%20to%20Lab539%20Clickfix%20List&amp;cmjud14wz000812ami85mazdk</loc>
    <lastmod>2025-12-31T18:39:07.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20unsigned%20File%20executed%20in%20User%20writeable%20Folder&amp;cmjud0wq7000712am893p8mif</loc>
    <lastmod>2025-12-31T18:38:57.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Script%20Interpreter%20Executing%20Commands%20with%20Non-ASCII%20Characters&amp;cmjud0plx000612am29ktvw5y</loc>
    <lastmod>2025-12-31T18:38:47.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risky%20SignIn%20after%20EmailUrlClickEvent&amp;cmjud0f77000512am0nxzrd6l</loc>
    <lastmod>2025-12-31T18:38:34.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Networkconnection_to_High_Confidence_ThreatView_Domain&amp;cmjud096a000412amfg4a96zd</loc>
    <lastmod>2025-12-31T18:38:26.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Lotusblo%20Obfuscated%20Powershell%20Script%20Detection&amp;cmjuczzy5000312amt3wg5a81</loc>
    <lastmod>2025-12-31T18:38:14.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20AD%20Device%20Registration%20from%20New%20IP%20Address&amp;cmjuczq8e000212amwusidybi</loc>
    <lastmod>2025-12-31T18:38:02.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuthAppEvaluation&amp;cmjuczi11000112am0a7yw1g8</loc>
    <lastmod>2025-12-31T18:37:51.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Failed%20AV%20Scan%20on%20Devices%20with%20Vulnerabilities%20and%20related%20Incidents&amp;cmjucz9ic000012amevl8srpr</loc>
    <lastmod>2025-12-31T18:37:40.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKEV-YearToDateVulnerabilitiesReleaseYear&amp;cmjtb3aim00033nfi42kvkvy7</loc>
    <lastmod>2025-12-31T00:57:02.973Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKEV-YearToDateVulnerabilitiesProduct&amp;cmjtb35f900023nfi63i3hf7w</loc>
    <lastmod>2025-12-31T00:56:56.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKEV-YearToDateVulnerabilitiesEdgeDevices&amp;cmjtb30qd00013nfi03sc40ad</loc>
    <lastmod>2025-12-31T00:56:50.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKEV-YearToDateVulnerabilities&amp;cmjtb2ui400003nfi64f0kiwj</loc>
    <lastmod>2025-12-31T00:56:42.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DataCollection&amp;cmjhhvlj30000npi31ypirf3t</loc>
    <lastmod>2025-12-22T18:33:47.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MshtaExecutions&amp;cmjh4zto60000l863c3ikkdwu</loc>
    <lastmod>2025-12-22T12:33:08.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DigiCert%20Global%20Root%20G2&amp;cmjea74vv0000ypu0zubos5ak</loc>
    <lastmod>2025-12-20T12:35:29.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/correlation%20id%20equals%20tenant%20id%20in%20peculiar%20password%20spray&amp;cmjbrqhdo00008771281y3vtd</loc>
    <lastmod>2025-12-18T18:23:07.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousMSBuildRemoteThread&amp;cmj7hoyan0000vvug7m7650tu</loc>
    <lastmod>2025-12-15T18:30:54.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PodContainerexec&amp;cmj5cizro0000bmyc2z87cstp</loc>
    <lastmod>2025-12-14T06:30:46.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExecutableFilesProgramDataFolder&amp;cmj0q1df70000kevi5st6o2b6</loc>
    <lastmod>2025-12-11T00:50:08.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceGroups&amp;cmizzumng00019cpiqpba5hy4</loc>
    <lastmod>2025-12-10T12:37:03.916Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceActiveInactive&amp;cmizzudz900009cpiozav72zd</loc>
    <lastmod>2025-12-10T12:36:52.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20Techniques%20for%20Email%20URL%20Redirect%20Hunting&amp;cmix4sogw0000ps77zjc7sk56</loc>
    <lastmod>2025-12-08T12:32:12.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-Identity-Password%20Security%20Posture%20Assessment&amp;cmiua1ubu0000n696kz1htfc0</loc>
    <lastmod>2025-12-06T12:35:59.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-AutoForwardingMode&amp;cmipzjcri0000w17jkcy68xpf</loc>
    <lastmod>2025-12-03T12:30:36.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20Deleted%20from%20Entra&amp;cmioxhw7b0005w3qkdm4pn7ka</loc>
    <lastmod>2025-12-02T18:45:42.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Password%20Resets&amp;cmioxhk9f0004w3qk800w95w3</loc>
    <lastmod>2025-12-02T18:45:27.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Group%20Changes&amp;cmioxhdp90003w3qkmeb8xvi6</loc>
    <lastmod>2025-12-02T18:45:18.464Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Account%20Disabled&amp;cmioxh5u50002w3qkeyabeyg0</loc>
    <lastmod>2025-12-02T18:45:08.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20Deleted%20from%20Entra&amp;cmioxgwqm0001w3qk5u3iy13j</loc>
    <lastmod>2025-12-02T18:44:56.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20Graph%20-%20APIM%20with%20basic%20auth%20enabled&amp;cmioxg1j70000w3qk3t2hrqah</loc>
    <lastmod>2025-12-02T18:44:16.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20Logic%20Apps%20with%20Office365%20Connections%20using%20Resource%20Query&amp;cminhzjsw0000izfqbmb4tvrg</loc>
    <lastmod>2025-12-01T18:43:46.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Executables%20in%20AppData%20Local%20Roaming&amp;cmihrpll80000104k2hqm7dxh</loc>
    <lastmod>2025-11-27T18:29:21.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UEBA%20-%20Find%20Onpremise%20users%20with%20Password%20Not%20Required&amp;cmihfgzwt0001h87q0zfo114z</loc>
    <lastmod>2025-11-27T12:46:44.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20VM%20sku%20sizes%20Changes&amp;cmihfg4xq0000h87q96v3og3c</loc>
    <lastmod>2025-11-27T12:46:04.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20VM%20sku%20sizes&amp;cmiek3go80000q2s1sswz14dj</loc>
    <lastmod>2025-11-25T12:32:52.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-Automatic%20Windows%20auditing%20configuration&amp;cmiamag8y00005ammvn0nvxrr</loc>
    <lastmod>2025-11-22T18:23:12.950Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BIC%5D%20-Tor%20Exit%20Browser%20hunting%20based%20on%20Device%20Events&amp;cmi5atzeh00001352vqcnjw6y</loc>
    <lastmod>2025-11-19T01:03:37.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/rustdeskexecution&amp;cmhvmr31r0000wjjr58nqhbkm</loc>
    <lastmod>2025-11-12T06:39:36.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntCriticalCredentialsOnNonCredGuardDevices&amp;cmhv9tbq10000hajfgcy0g9mf</loc>
    <lastmod>2025-11-12T00:37:25.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VeeamPSQLDump&amp;cmhu79nqi0001vl2antpelmpa</loc>
    <lastmod>2025-11-11T06:38:23.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataStagingFileZillaPsFTPWinscp&amp;cmhu79gpm0000vl2aus7onfks</loc>
    <lastmod>2025-11-11T06:38:13.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BumbleeBeeInitiailaccess&amp;cmhthjs2x0003sb5x4urg3xbj</loc>
    <lastmod>2025-11-10T18:38:25.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DNSZoneExport&amp;cmhthjb1c0002sb5xkew2snwj</loc>
    <lastmod>2025-11-10T18:38:03.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NTDSdumpwbadmin&amp;cmhthj19d0001sb5xnuri0zhz</loc>
    <lastmod>2025-11-10T18:37:49.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/sshtunneltoexternalhost&amp;cmhthir7l0000sb5xuww0jttp</loc>
    <lastmod>2025-11-10T18:37:37.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%5BLM%5D%20-%20Internal%20Threat%20Hunting%20over%20Routers%20Devices&amp;cmhsfuesg00013hptta2rnzwm</loc>
    <lastmod>2025-11-10T01:02:55.677Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TH-Obfuscated%20or%20Encoded%20Commandline&amp;cmhsfmv8i00003hpt897h7g0d</loc>
    <lastmod>2025-11-10T00:57:03.905Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20abuse%20of%20SyncThing%20tool%20to%20steal%20data&amp;cmho55rqc0000vvj1lcoqqsif</loc>
    <lastmod>2025-11-07T00:52:45.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SliverC2BeaconLoaded&amp;cmhnepz7400007dbiqgbjp5c6</loc>
    <lastmod>2025-11-06T12:32:38.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NRT%20-%20AutoIRHighImpactAlert&amp;cmhkwh5aa0000igw6mrh77eql</loc>
    <lastmod>2025-11-04T18:26:20.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousSpnLogonFromWorkstation&amp;cmhju8gxu00011v7vx7mlld9l</loc>
    <lastmod>2025-11-04T00:35:50.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectDumpGuardNtlmChallenge&amp;cmhju82e100001v7v3iuy2jdx</loc>
    <lastmod>2025-11-04T00:35:31.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Identify%20and%20Map%20Authentication%20Context%20Usage&amp;cmhjhp1zg0000pej0bm5hqr99</loc>
    <lastmod>2025-11-03T18:44:49.456Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Access%20Review%20On%20Role%20Assignable%20Group%20AutoDeleted&amp;cmhi1w9xf0000enln27ylixku</loc>
    <lastmod>2025-11-02T18:34:46.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDR%20-%20UpnAlerts&amp;cmhh03kn10000tb2lcr9aa8hj</loc>
    <lastmod>2025-11-02T00:56:41.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Modification%20of%20Windows%20Security%20Audit%20Policy%20(Auditpol.exe)&amp;cmhcq116g0001mslojx73wtvx</loc>
    <lastmod>2025-10-30T01:03:42.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Execution%20of%20Windows%20Security%20Audit%20Policy%20(Auditpol.exe)&amp;cmhcq0vri0000mslo6zmpqpg8</loc>
    <lastmod>2025-10-30T01:03:34.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/third%20party%20Phishing%20Report%20malfunction&amp;cmh0w3qak0000anuv3g0q6ahp</loc>
    <lastmod>2025-10-21T18:20:31.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20when%20PIM%20fails%20to%20remove%20an%20eligible%20member%20from%20role&amp;cmgxp40a10000v066fzmalqj3</loc>
    <lastmod>2025-10-19T12:41:28.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20LastPass%20Hack%20Emails%20attempts%20to%20trick%20users%20into%20installing%20Malware&amp;cmgtrl0z300007wyidedmd004</loc>
    <lastmod>2025-10-16T18:39:37.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identifying%20File%20Exfiltration%20via%20RDP%20Sessions&amp;cmgrm3wfq0000cwiq8s0furfz</loc>
    <lastmod>2025-10-15T06:30:47.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/cache_smuggle&amp;cmgqjfqwy0000fj9cwqexymp1</loc>
    <lastmod>2025-10-14T12:28:15.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NTDSFileCreateModify&amp;cmgor4ghw0000v9zjlsae02ob</loc>
    <lastmod>2025-10-13T06:27:53.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identities%20Bad%20Reputation%20ASN%20activities&amp;cmgktzt660000wpt4lthdjbyj</loc>
    <lastmod>2025-10-10T12:37:10.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unexpected%20network%20share%20access%20in%20a%20domain%20controller&amp;cmggj518z0000tk0pif4t997v</loc>
    <lastmod>2025-10-07T12:22:13.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectProcessDropViaAzureLateralMovement&amp;cmgf3giuc0003jr8e24zyahv5</loc>
    <lastmod>2025-10-06T12:15:29.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectFirstTimeAzureCustomScriptOrRunCommand&amp;cmgf3gdvc0002jr8e7i320okc</loc>
    <lastmod>2025-10-06T12:15:23.448Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectExecutableDropViaAzure&amp;cmgf3g5y60001jr8eesdsjnz5</loc>
    <lastmod>2025-10-06T12:15:13.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectAzureScriptOrRunCommandByRiskyUser&amp;cmgf3fxn10000jr8ek143o6tm</loc>
    <lastmod>2025-10-06T12:15:02.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20-%20IP%20Address%20Type&amp;cmg9eqtmw0001y3c52ykge77n</loc>
    <lastmod>2025-10-02T12:44:49.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20-%20File%20Download%20by%20Country&amp;cmg9eqo7p0000y3c5uzpvw8cn</loc>
    <lastmod>2025-10-02T12:44:41.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20Role%20Assignment&amp;cmg8bah6z0000xmwzlcswe039</loc>
    <lastmod>2025-10-01T18:20:21.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDR%20-%20DeviceAlerts&amp;cmg4eugro0000sjco47gbb9bo</loc>
    <lastmod>2025-09-29T00:48:48.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20potential%20CA%20policy%20bypass%20by%20privileged%20accounts%20via%20private%20browser%20sessions&amp;cmg413bch0000cbxcbtzu5ykn</loc>
    <lastmod>2025-09-28T18:23:46.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Activity%20from%20anonymous%20IP%20addresses&amp;cmg0td7u00000tkcbh3vuwvwq</loc>
    <lastmod>2025-09-26T12:24:12.920Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IngestionDelays&amp;cmfx9srcq00005h7wz1bld287</loc>
    <lastmod>2025-09-24T00:53:07.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/removed%20device%20events&amp;cmfwvzgyp00001o87g9l7oca1</loc>
    <lastmod>2025-09-23T18:26:25.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMB%20%26%20NTLM%20Negotiation%20to%20Unknown%20Remote%20IPs&amp;cmfvgt4z70000khrux1lvmh63</loc>
    <lastmod>2025-09-22T18:33:49.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Microsoft%20Entra%20threat%20intelligence&amp;cmfpe33zy00004pq9rmn9gnn0</loc>
    <lastmod>2025-09-18T12:30:59.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20KSMBD%20DoS%20(CVE-2025-38501)%20can%20exhaust%20SMB%20connections%20via%20half-open%20TCP%20handshakes&amp;cmfobfjby00027kwtlynsjh1k</loc>
    <lastmod>2025-09-17T18:28:53.951Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Entra%20ID%20Protection%20risk%20events&amp;cmfob5e2y00017kwt2ltnrfak</loc>
    <lastmod>2025-09-17T18:21:00.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-EntraIDProtectionRiskEvents&amp;cmfob4kh600007kwtr1rxve4t</loc>
    <lastmod>2025-09-17T18:20:22.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TH-Wmic-PS-Encoded&amp;cmfnyjanz0003xi4titxnlaah</loc>
    <lastmod>2025-09-17T12:27:54.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-OnboardingStatusTimeline&amp;cmfnyios30002xi4t88gqwrbm</loc>
    <lastmod>2025-09-17T12:27:25.973Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-AggregatedReporting&amp;cmfnyicdf0001xi4tlp9aqyl2</loc>
    <lastmod>2025-09-17T12:27:09.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Risky%20AD%20FS%20sign-in&amp;cmfnyd5300000xi4tl1a47dgs</loc>
    <lastmod>2025-09-17T12:23:07.260Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Windows%20Versions%20reaching%20end%20of%20service%20on%20October%26November%202025&amp;cmfn9m5vw0001z7kjxbtwh41r</loc>
    <lastmod>2025-09-17T00:50:17.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sign-in%20Attempts%20Using%20Deprecated%20TLS%20Versions&amp;cmfn9lw1p0000z7kjn69fr3s1</loc>
    <lastmod>2025-09-17T00:50:05.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntPublicRemotlyExploitableDevicesWithHighEPSS&amp;cmfltkyqf0002j7sqmwztjnoy</loc>
    <lastmod>2025-09-16T00:33:41.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntCriticalCredentialsOnNonTpmDevices&amp;cmfltkq090001j7sqv3dxn0ko</loc>
    <lastmod>2025-09-16T00:33:30.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntCriticalCredentialsOnDevicesWithNonCriticalAccounts&amp;cmfltkizm0000j7sqb56qv1x3</loc>
    <lastmod>2025-09-16T00:33:21.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20for%20Malicious%20ClickFix%20cases%20from%20Airports&amp;cmfh6o53u0000f7k9om77nyj1</loc>
    <lastmod>2025-09-12T18:41:14.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Add%20custom%20security%20attribute%20definition%20in%20an%20attribute%20set&amp;cmfebzxvh000043d48owugysl</loc>
    <lastmod>2025-09-10T18:47:04.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WDAC%20App%20Control%20Collect%20Data%20for%20App%20Control%20Manager&amp;cmfcwrxuw0001se7zv1yxymjw</loc>
    <lastmod>2025-09-09T18:53:10.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceEvents%20-%20AppLocker%20Events&amp;cmfcwrktt0000se7z38sgge2l</loc>
    <lastmod>2025-09-09T18:52:52.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20User%20Signed%20into%20Edge%20Browser%20From%20Unmanaged%20or%20Unregistered%20Device&amp;cmfb3wjxg0000t4gkj6rwuw9z</loc>
    <lastmod>2025-09-08T12:37:10.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rclone%20Copy%20Process%20Args&amp;cmf9opb6d00004nplhghjrl1v</loc>
    <lastmod>2025-09-07T12:43:52.404Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Logic%20App%20Disabled%20or%20Deleted&amp;cmf6tco5i0002hf2gwlasmmir</loc>
    <lastmod>2025-09-05T12:30:42.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Function%20App%20Stopped%20or%20Deleted&amp;cmf6tcjst0001hf2gp96jc3sv</loc>
    <lastmod>2025-09-05T12:30:36.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Communication%20Services%20Deleted&amp;cmf6tcftc0000hf2gmeey2no4</loc>
    <lastmod>2025-09-05T12:30:31.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADSignInEventsBeta%20-%20Hunting%20Potential%20Seamless%20SSO%20Usage&amp;cmey8tt7f0000p6kg95jcdg39</loc>
    <lastmod>2025-08-30T12:34:00.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-SuspiciousTCPFlags&amp;cmex67mia0001vc4aksoblaw6</loc>
    <lastmod>2025-08-29T18:33:00.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-SenseTriggersPowerShellPublicIP&amp;cmex67emn0000vc4avhqxbzx1</loc>
    <lastmod>2025-08-29T18:32:49.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Verified%20threat%20actor%20IP&amp;cmewt271y0001haid5mkw5ir6</loc>
    <lastmod>2025-08-29T12:24:51.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Suspicious%20API%20Traffic&amp;cmewt1ymq0000haidaxbaxw5s</loc>
    <lastmod>2025-08-29T12:24:40.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TH-Use%20of%20Administrator%20Account&amp;cmewg78oi0005vr8xbwvoefrq</loc>
    <lastmod>2025-08-29T06:24:52.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TH-TopLevelDomains&amp;cmewg754x0004vr8xwpnu9lwz</loc>
    <lastmod>2025-08-29T06:24:47.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview-EntraCABlock-InsiderRisk&amp;cmewg6v1e0003vr8x780yn5ri</loc>
    <lastmod>2025-08-29T06:24:34.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-EntraConnectSyncAuditEvents&amp;cmewg6mdn0002vr8xfo68304u</loc>
    <lastmod>2025-08-29T06:24:23.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20%20-%20Repositories&amp;cmewg65zp0001vr8x1ik7fq7x</loc>
    <lastmod>2025-08-29T06:24:01.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-AccountLastLogon&amp;cmewg5za90000vr8xnkfzf56d</loc>
    <lastmod>2025-08-29T06:23:53.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Leaked%20credentials&amp;cmevqk7wl000010h7ppkjafeo</loc>
    <lastmod>2025-08-28T18:27:07.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/fetch-dynamic-and-manual-tags-for-active-devices&amp;cmev0rvn10000jaaapr1psuyy</loc>
    <lastmod>2025-08-28T06:25:14.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Set%20Persistence%20using%20Event%20Viewer%20Microsoft%20Redirection%20Program&amp;cmetyy3lm0000xl4khkif8sv6</loc>
    <lastmod>2025-08-27T12:46:19.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntDomainsWithSeamlessSsoEnabled&amp;cmet8tnj80000obzk0dcx7vzz</loc>
    <lastmod>2025-08-27T00:35:02.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrollmentAttemptWithADCSESC1HoneypotTemplate&amp;cmeq0qv4d0000rz3vby26s9gc</loc>
    <lastmod>2025-08-24T18:25:36.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FileFromHostCollected&amp;cmepnrxn3000011iqh0m6vwtn</loc>
    <lastmod>2025-08-24T12:22:31.694Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Onmicrosoft%20domains%20impacted%20by%20email%20exchange%20restrictions%20with%20External%20Domains&amp;cmeozmeqf0000qmkk2hktxxpi</loc>
    <lastmod>2025-08-24T01:06:23.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-Assets%20allowing%20remote%20access&amp;cmen5tx0d0005z6qzw2d2mwr3</loc>
    <lastmod>2025-08-22T18:24:38.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/D4IOT-ConnectorState&amp;cmen5toge0004z6qzdblcccsj</loc>
    <lastmod>2025-08-22T18:24:27.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDXDR-AttackDisruptionAndResponse&amp;cmen5tf9y0003z6qzvgobdnzw</loc>
    <lastmod>2025-08-22T18:24:15.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-IdentifyServiceAccountOUs&amp;cmen5t55x0002z6qz08chiscu</loc>
    <lastmod>2025-08-22T18:24:02.660Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-DormantAccounts&amp;cmen5t0rq0001z6qz6fvadi7s</loc>
    <lastmod>2025-08-22T18:23:56.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Arc-CompareMDE&amp;cmen5sols0000z6qzq27xxmks</loc>
    <lastmod>2025-08-22T18:23:41.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADServicePrincipalRiskEvents-Service%20principal%20at%20risk&amp;cmeldr9dh0000y3ote47dt08v</loc>
    <lastmod>2025-08-21T12:30:59.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Assignment%20of%20Local%20Administrator%20Entra%20Role&amp;cmekbftv7000013gnv1tn5zb3</loc>
    <lastmod>2025-08-20T18:38:20.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelWorkspaceDisconnected&amp;cmehg4yt60000edba9clhkuov</loc>
    <lastmod>2025-08-18T18:26:33.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInLogs%20-%20B2B%20Access%20Restrictions&amp;cmed68fe80001sze6xf38acts</loc>
    <lastmod>2025-08-15T18:38:13.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20-%20Auditing%20TenantRestrictionsV2%20Events&amp;cmed6846l0000sze6gcbp6ybj</loc>
    <lastmod>2025-08-15T18:37:59.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Request%20an%20actor%20token%20for%20graph.windows.net%20using%20Service%20to%20Service%20(S2S)&amp;cmebef2ss0007wu92qsbofimb</loc>
    <lastmod>2025-08-14T12:51:47.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20UserEnrichment&amp;cmebdwcuz0006wu92ks24r3nr</loc>
    <lastmod>2025-08-14T12:37:15.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20IPEnrichment&amp;cmebdw5j90005wu92ckpjihea</loc>
    <lastmod>2025-08-14T12:37:05.924Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20GraphURIAPIRequestStats&amp;cmebdvywg0004wu928sp8vbjg</loc>
    <lastmod>2025-08-14T12:36:57.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20GraphResourceAPIRequestStats&amp;cmebdvrnt0003wu92vfsvebn8</loc>
    <lastmod>2025-08-14T12:36:47.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20AzureHound&amp;cmebdvkoy0002wu92urrrnsgp</loc>
    <lastmod>2025-08-14T12:36:38.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20AppEnrichmentExternalData&amp;cmebdvbm90001wu92fynr8613</loc>
    <lastmod>2025-08-14T12:36:27.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPIAuditEvents%20-%20AppEnrichmentAADNonInteractiveUserSignInLogs&amp;cmebdv72o0000wu92i2jt7s6u</loc>
    <lastmod>2025-08-14T12:36:20.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents%20-%20Sender%20TLD%20count&amp;cme7g5odj0000g6du716rjyhq</loc>
    <lastmod>2025-08-11T18:29:24.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risk%20Based%20Step%20Up%20Consent%20(RBSU)%20for%20Application&amp;cme118uxa0000mg79soj8mabr</loc>
    <lastmod>2025-08-07T06:45:21.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/App%20Consent%20to%20Risky%20Application&amp;cme0owzwv0000oppwwk6rmu79</loc>
    <lastmod>2025-08-07T01:00:13.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-ip-assets-from-mdeasm-in-exposure-management-that-match-ti&amp;cmdy5pqcv0000110bjeqxp5tg</loc>
    <lastmod>2025-08-05T06:27:09.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-mdeasm-hosts-with-high-or-critical-vulnerabilities-and-a-cvss-score-over-8&amp;cmdrdgr070003uoadyo0r1qds</loc>
    <lastmod>2025-07-31T12:29:43.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-cves-in-mdeasm-web-pages-through-exposure-management&amp;cmdrdgjjs0002uoadlk6l8v5z</loc>
    <lastmod>2025-07-31T12:29:33.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-assets-from-mdeasm-in-exposure-management&amp;cmdrdge7y0001uoadp39z1n1a</loc>
    <lastmod>2025-07-31T12:29:27.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-assets-from-mdeasm-in-exposure-management-that-match-ti&amp;cmdrdg3hf0000uoadva6xx636</loc>
    <lastmod>2025-07-31T12:29:13.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Successful%20join%20of%20fake%20device%20using%20ROPC%20(query%20by%20%40goldjg)&amp;cmdqoolwh00003m6ejdw45fky</loc>
    <lastmod>2025-07-31T00:55:59.875Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Legacy%20protocols%20used%20in%20Entra%20ID%20authentication&amp;cmdqao31k000013xgxexqes0m</loc>
    <lastmod>2025-07-30T18:23:40.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20account%20using%20a%20PowerShell%20app%20in%20Entra%20ID&amp;cmdpxsvnb0000v33t69402u8n</loc>
    <lastmod>2025-07-30T12:23:29.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnifiedMicrosoftGraphLogs&amp;cmdpledym0000agog074toq66</loc>
    <lastmod>2025-07-30T06:36:17.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Attempts%20to%20modify%20Amcache.hve%20or%20SYSTEM%20file&amp;cmdoiqgn00000ukgk4gu5v8dg</loc>
    <lastmod>2025-07-29T12:33:56.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Enabled-data-connectors&amp;cmdntkuzq0000ssqov1q2x2g5</loc>
    <lastmod>2025-07-29T00:49:44.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AuthenticationMethodsChanges&amp;cmdgajnln0001mq5un452hlqa</loc>
    <lastmod>2025-07-23T18:22:32.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AuthenticationMethodChangesOld&amp;cmdgaj7990000mq5uja6slr14</loc>
    <lastmod>2025-07-23T18:22:11.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Last%20Password%20Change%20Time%20with%20Account%20Creation%20Time&amp;cmdevdhdz000093s9m09khvyz</loc>
    <lastmod>2025-07-22T18:30:04.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20Mandatory%20Office%20Days%20using%20Advanced%20Hunting&amp;cmddtqh110001zrjjj1ia0ahu</loc>
    <lastmod>2025-07-22T00:56:24.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20AIREffectiveness&amp;cmddthse00000zrjjn0khd8om</loc>
    <lastmod>2025-07-22T00:49:39.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RDP%20Trace%20Removal%20Detection&amp;cmd8sqkea0000jlydkyxsr80d</loc>
    <lastmod>2025-07-18T12:29:38.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrichedMicrosoftGraphActivity&amp;cmd70hyye0000voiseepk5dt2</loc>
    <lastmod>2025-07-17T06:31:22.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-User%20reported%20unusual%20sign-in%20event%20as%20not%20legitimate&amp;cmd5xtpka0000hucrg3uibv0l</loc>
    <lastmod>2025-07-16T12:28:44.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectDirectSendPhishingEmails&amp;cmd4hx2i000003fzi3xi1w89j</loc>
    <lastmod>2025-07-15T12:15:41.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatIntelIndicators-Stopped%20event%20reception%20-%20ThreatIntelIndicators&amp;cmcvxmdg800015xip6k7t11p4</loc>
    <lastmod>2025-07-09T12:25:20.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommonSecurityLog-Stopped%20event%20reception%20-%20CommonSecurityLog%20-%20DeviceProduct&amp;cmcvxm37s00005xipb4iedwdy</loc>
    <lastmod>2025-07-09T12:25:07.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousExplorerChildProcess&amp;cmcp5648700006jkjn127nm7v</loc>
    <lastmod>2025-07-04T18:22:16.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20DeviceRegistryEvents%20Tampering%20To%20DeviceTag&amp;cmcnpz8z30000jtx5st60r4f0</loc>
    <lastmod>2025-07-03T18:29:15.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Sign-ins%20to%20Legacy%20Azure%20Active%20Directory%20Powershell&amp;cmcnd82jo000013yvqcu39e6f</loc>
    <lastmod>2025-07-03T12:32:11.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20the%20removal%20of%20evidence%20on%20executed%20programs&amp;cmcmop62f0001st0heyrfrkir</loc>
    <lastmod>2025-07-03T01:05:39.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20bcedit%20commands%20related%20to%20boot%20configuration&amp;cmcmoozrb0000st0htrx77mbo</loc>
    <lastmod>2025-07-03T01:05:30.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousBrowserChildProcess&amp;cmcmaaoah0000qekzxysi0yed</loc>
    <lastmod>2025-07-02T18:22:28.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/monitor-for-analytics-editing-in-microsoft-sentinel&amp;cmcj2u9070004jcizzfr6vqsw</loc>
    <lastmod>2025-06-30T12:30:26.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-microsoft-sentinel-changes-from-users-not-defined-within-approved-user-groups&amp;cmcj2u3bo0003jciz4mdjee62</loc>
    <lastmod>2025-06-30T12:30:18.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-log-analytics-contributor-and-data-purger-role-assignment&amp;cmcj2ts6b0002jciz5zqk2jis</loc>
    <lastmod>2025-06-30T12:30:04.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-activities-in-log-analytics-workspace-resource-locks&amp;cmcj2tldw0001jcizxeety6an</loc>
    <lastmod>2025-06-30T12:29:55.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20RBAC%20Elevated%20Access%20operation&amp;cmcj2lk840000jcizi1qe5jbv</loc>
    <lastmod>2025-06-30T12:23:40.595Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CaBypassFirstPartyApps&amp;cmci08gje0003tcsb94xd2ezr</loc>
    <lastmod>2025-06-29T18:29:43.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-Trace%20Lateral%20Movement&amp;cmci05f8t0002tcsb81xbemaf</loc>
    <lastmod>2025-06-29T18:27:22.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-High-Privilege%20Identities%20Across%20Subscriptions&amp;cmci058od0001tcsbdnv6o4q1</loc>
    <lastmod>2025-06-29T18:27:13.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDISensorDeleted&amp;cmci03avj0000tcsb4ulcrbvq</loc>
    <lastmod>2025-06-29T18:25:43.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20anomalous%20external%20OAuthApp%20activity%20using%20ActorInfoString&amp;cmcgypbx00000tzch31hu9ytu</loc>
    <lastmod>2025-06-29T00:59:05.747Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hackers%20Exploit%20Cloudflare%20Tunnels%20to%20Infect%20Windows%20Systems%20With%20Python%20Malware&amp;cmcf5adiq000074qh8nu2leug</loc>
    <lastmod>2025-06-27T18:27:52.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AppConsentAssignment&amp;cmcesg1in0000mxv8hk9zf5we</loc>
    <lastmod>2025-06-27T12:28:22.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Direct%20Send%20Abuse%20Detection&amp;cmcdq8vhe0000n2ev2f5y86bh</loc>
    <lastmod>2025-06-26T18:39:02.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Text%20and%20CSV%20Data%20Dumps%20via%20Command%20Line&amp;cmcdd2ui1000013h3g8s9v2nx</loc>
    <lastmod>2025-06-26T12:30:26.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20CLI%20Obfuscation&amp;cmcco487t000013z2rvm6ns4f</loc>
    <lastmod>2025-06-26T00:51:40.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20MSHTA%20Usage&amp;cmcb9a4rh0000rvw9afkx4ys4</loc>
    <lastmod>2025-06-25T01:08:35.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FileFix%20Detection&amp;cmcaveszu0000n5vfadr7yvuw</loc>
    <lastmod>2025-06-24T18:40:18.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Entra%20ID%20role%20assignment&amp;cmc9fg4cy0002xzw5tjgbumxw</loc>
    <lastmod>2025-06-23T18:25:40.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-EntraIDRoleAssignments&amp;cmc9ff6oo0001xzw5xk2a56ri</loc>
    <lastmod>2025-06-23T18:24:56.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntMdiNotInstalled&amp;cmc9eyari0000xzw58qjie773</loc>
    <lastmod>2025-06-23T18:11:48.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20connections%20affected%20by%20the%20Blocking%20Legacy%20Authentication%20enforcement%20expected%20by%20July%202025.&amp;cmc9342v00005soi1ji64dvwt</loc>
    <lastmod>2025-06-23T12:40:22.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnifiedIdentityInfoXdr&amp;cmc9306va0004soi1flgo115v</loc>
    <lastmod>2025-06-23T12:37:21.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20Entra%20ID%20device&amp;cmc92nc5q0003soi1fb00dxa6</loc>
    <lastmod>2025-06-23T12:27:21.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Entra%20ID%20unusual%20operation&amp;cmc92n0230002soi1t8hi0ig2</loc>
    <lastmod>2025-06-23T12:27:06.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Entra%20ID%20B2C%20settings%20modified&amp;cmc92mpzr0001soi1b73e53b7</loc>
    <lastmod>2025-06-23T12:26:52.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-UnexpectedEntraIDDevice&amp;cmc92ly7o0000soi1aq26ucvm</loc>
    <lastmod>2025-06-23T12:26:16.916Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sniffing%20Out%20UNC3944%20on%20Teams&amp;cmc804p5f00001375om35br2b</loc>
    <lastmod>2025-06-22T18:29:06.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudflaredTunnel&amp;cmc5izy820003dlb5xviz5w7k</loc>
    <lastmod>2025-06-21T00:53:59.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows%20Server%20-%20Client%20-%20Missing%20Updates%20Summary&amp;cmc5iygih0002dlb5yoa28p0b</loc>
    <lastmod>2025-06-21T00:52:49.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Office365VersionHistory&amp;cmc5iy7320001dlb5iwjstkvl</loc>
    <lastmod>2025-06-21T00:52:37.475Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Defenderpassivemode&amp;cmc5ixtc80000dlb54hv2q2b8</loc>
    <lastmod>2025-06-21T00:52:19.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20User%20tries%20to%20change%20password%20to%20a%20non-complying%20password&amp;cmc56h0i7000xd9sb4qs2663x</loc>
    <lastmod>2025-06-20T19:03:20.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-33073%20Detection&amp;cmc56fswh000wd9sbgn2sindj</loc>
    <lastmod>2025-06-20T19:02:24.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TA4557%20drops%20More_Eggs&amp;cmc56fidw000vd9sbdx7vzon6</loc>
    <lastmod>2025-06-20T19:02:10.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20OAuth%20applications%20used%20to%20retrieve%20and%20send%20emails&amp;cmc56f8ki000ud9sbd4ixr8we</loc>
    <lastmod>2025-06-20T19:01:57.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Social%20Engineering%20Attack%20Detection&amp;cmc56f2ag000td9sbnb7hrqm8</loc>
    <lastmod>2025-06-20T19:01:49.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Ottercookie%20Detection&amp;cmc56esbb000sd9sbssofpztg</loc>
    <lastmod>2025-06-20T19:01:36.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/External%20Attack%20Surface%20Monitoring%20KQL&amp;cmc56ec4n000rd9sb2p7haoek</loc>
    <lastmod>2025-06-20T19:01:14.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Discord%20Invite%20Hijacking%20Detection&amp;cmc56drvl000qd9sbysomun44</loc>
    <lastmod>2025-06-20T19:00:49.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/APT%20Stealth%20Falcon%20-%20CVE-2025-33053%20Detection&amp;cmc56d380000pd9sb62majtte</loc>
    <lastmod>2025-06-20T19:00:17.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ANY.RUN%20Obfuscated%20BAT%20Dropper%20Delivers%20NetSupport%20RAT%20post&amp;cmc56csiy000od9sblnm6funx</loc>
    <lastmod>2025-06-20T19:00:03.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20commands%20executed%20by%20a%20powerShell.exe%20renamed&amp;cmc56beb1000nd9sb71xre0qy</loc>
    <lastmod>2025-06-20T18:58:58.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/3%20-%20Finding%20sensitive%20Roles%20with%20CSPM%20posture%20and%20used%20by%20OAuth&amp;cmc5697bj000md9sbiz6sdb8j</loc>
    <lastmod>2025-06-20T18:57:16.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/2%20-%20Custom%20Graph%20Query%20on%20Recommendations%20and%20Target&amp;cmc5691dv000ld9sb41l6s7dc</loc>
    <lastmod>2025-06-20T18:57:08.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/1%20-%20List%20of%20critical%20Azure%20resources%20in%20XSPM&amp;cmc568ub8000kd9sbm3hzkbvt</loc>
    <lastmod>2025-06-20T18:56:59.160Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/3%20-%20Correlation%20between%20CSPM%20and%20IdentityInfo&amp;cmc568mcz000jd9sbq68vlyly</loc>
    <lastmod>2025-06-20T18:56:48.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/2%20-%20Adv.%20Correlation%20between%20Alert%20and%20Attack%20Path&amp;cmc568djz000id9sb1tws8o1z</loc>
    <lastmod>2025-06-20T18:56:37.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/1%20-%20Correlation%20between%20Alert%20and%20Attack%20Path&amp;cmc5681w7000hd9sb2716td71</loc>
    <lastmod>2025-06-20T18:56:22.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/3%20-%20EPM%20Insights&amp;cmc567rj8000gd9sbiciqexja</loc>
    <lastmod>2025-06-20T18:56:08.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/2%20-%20Sensitive%20Labels%20in%20Azure%20Resources&amp;cmc567khc000fd9sbhfkojj1y</loc>
    <lastmod>2025-06-20T18:55:59.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/1%20-%20Overview%20of%20Attack%20Paths&amp;cmc567ihn000ed9sbxlbifj5a</loc>
    <lastmod>2025-06-20T18:55:57.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CaMfaExcludeRuleXdr&amp;cmc5678ai000dd9sbpkwmq6q5</loc>
    <lastmod>2025-06-20T18:55:44.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuthMethods-TokenBoundedCae&amp;cmc56728s000cd9sbksciqmbx</loc>
    <lastmod>2025-06-20T18:55:36.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccessBaselineGapDetectedDuePolicyChange&amp;cmc566jwq000bd9sbz3nk8lzd</loc>
    <lastmod>2025-06-20T18:55:12.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-PIMRoleActivations&amp;cmc564hig000ad9sb9z47aqbn</loc>
    <lastmod>2025-06-20T18:53:35.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-EnterpriseApps-Deleted&amp;cmc5645x60009d9sbd8zr42wz</loc>
    <lastmod>2025-06-20T18:53:21.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-DisabledUserswithPrivRoles&amp;cmc5640ea0008d9sblaag3hrj</loc>
    <lastmod>2025-06-20T18:53:13.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UserAccountDeletion&amp;cmc562yya0007d9sbdjihfywd</loc>
    <lastmod>2025-06-20T18:52:25.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DisabledAccountAttackDisruption&amp;cmc561ypm0006d9sbal6xrscn</loc>
    <lastmod>2025-06-20T18:51:38.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Quarantined%20messages&amp;cmc55zvst0005d9sb7ur789kf</loc>
    <lastmod>2025-06-20T18:50:01.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Quarantined%20emails&amp;cmc55zjsq0004d9sbcwelif3j</loc>
    <lastmod>2025-06-20T18:49:45.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/365DaysofKQL-Day100&amp;cmc55t0820003d9sbhkt6jtuk</loc>
    <lastmod>2025-06-20T18:44:40.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntMSOLAzureADConnectOrEntraSyncServers&amp;cmc55nqos0002d9sbe84olo52</loc>
    <lastmod>2025-06-20T18:40:34.686Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectCredAddToConnectSyncApplication&amp;cmc55ngf60001d9sbytt148k2</loc>
    <lastmod>2025-06-20T18:40:21.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectChangesToConnectSyncApplication&amp;cmc55n9ra0000d9sbc2ympht3</loc>
    <lastmod>2025-06-20T18:40:12.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NTLMv2%20Hash%20Leak%20via%20COM%20Detection&amp;cmbcjv1ua00dvms0f3dr45j5y</loc>
    <lastmod>2025-05-31T18:12:51.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth%20app%20using%20the%20OD%20file%20picker%20permission&amp;cmbc720tq00dmms0fo9tpqu60</loc>
    <lastmod>2025-05-31T12:14:21.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/One-Click%20ANY%20RUN%20Storm-1747%20KQL%20Scan&amp;cmb9p4pko00c3ms0fx38aow2c</loc>
    <lastmod>2025-05-29T18:17:01.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20DragonForce%20with%20ANY.RUN%20Threat%20Intelligence&amp;cmb9p3xxi00c2ms0flzhnrpdc</loc>
    <lastmod>2025-05-29T18:16:25.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOCs%20Associated%20with%20APT41%E2%80%99s%20Malware%20Delivery%20via%20Google%20Calendar&amp;cmb8mgvk900bdms0fszvt6yn9</loc>
    <lastmod>2025-05-29T00:14:44.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppSheet.com%20abused%20to%20send%20Phish&amp;cmb89qzir00b4ms0f6r4prh6b</loc>
    <lastmod>2025-05-28T18:18:40.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20suspicious%20actions%20to%20change%20Desktop%20Background&amp;cmb89m9b700b3ms0fd5qgi8fx</loc>
    <lastmod>2025-05-28T18:15:00.086Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20suspicious%20files%20dropped%20into%20Public%20Folder&amp;cmb89lsjn00b2ms0fkg6wdl37</loc>
    <lastmod>2025-05-28T18:14:38.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ModifyCredentialsEntraConnectAppIdentity&amp;cmb7wmxkw00atms0frnpst80y</loc>
    <lastmod>2025-05-28T12:11:36.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-PIMRoleSettingChanges&amp;cmb2jirhf007gms0f8z669clp</loc>
    <lastmod>2025-05-24T18:05:36.138Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/defendnot%20detection&amp;cmb14kx5s006jms0fg3q20gyt</loc>
    <lastmod>2025-05-23T18:19:36.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Blob%20URI%20Unique%20Domain%20Count&amp;cmb01rvzy005ums0fb217sryc</loc>
    <lastmod>2025-05-23T00:13:16.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/glibc%20critical%20vulnerability%20(CVSS%209.8)&amp;cmazp4x4o005lms0f54ngn3tl</loc>
    <lastmod>2025-05-22T18:19:29.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan%2019052025&amp;cmazp3n7o005kms0fwwt8cklr</loc>
    <lastmod>2025-05-22T18:18:29.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan%2012052025&amp;cmazp3fsi005jms0fsbuop19f</loc>
    <lastmod>2025-05-22T18:18:20.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan%2005052025&amp;cmazp38yv005ims0fcgw2u22z</loc>
    <lastmod>2025-05-22T18:18:11.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVSS%209.8%20Rockwell%20Automation%20Impacted%20by%20High-Severity%20log4net%20Vulnerability&amp;cmazp2p4m005hms0fk10o4f96</loc>
    <lastmod>2025-05-22T18:17:45.910Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-32705%20Out-of-bounds%20Read%20Detection&amp;cmazp2ij5005gms0fbur6czat</loc>
    <lastmod>2025-05-22T18:17:37.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BadSuccessor%20Detection&amp;cmayz8e3h004zms0fjm5fiywp</loc>
    <lastmod>2025-05-22T06:14:21.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malware%20C2%20Comms%20over%20Azure%20Blob%20Metadata&amp;cmay9oaxf004ims0fmpnz7caf</loc>
    <lastmod>2025-05-21T18:18:53.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Global%20Admin%20Entra%20Cookie%20with%20Chrome%20ZeroDay&amp;cmawuf5ja003lms0f9z1owsq1</loc>
    <lastmod>2025-05-20T18:24:06.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Senstive%20Large%20File%20Uploads%20using%20CloudAppEvents&amp;cmawheyaf003cms0f1p6ijnr1</loc>
    <lastmod>2025-05-20T12:20:02.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-UserDeviceObjectOUMoves&amp;cmavr7itc002vms0fkc0s26sq</loc>
    <lastmod>2025-05-20T00:06:25.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-GroupPolicy&amp;cmavr7d4b002ums0f0mr0h5eq</loc>
    <lastmod>2025-05-20T00:06:18.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-ComputerObjectOSNameChanged&amp;cmavr77al002tms0f38fos1qf</loc>
    <lastmod>2025-05-20T00:06:10.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-Account%20Password%20Not%20Required%20changed&amp;cmavr6xvu002sms0fap50pjrk</loc>
    <lastmod>2025-05-20T00:05:58.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices%20with%20High%20severity%20CVEs%20with%20exploits%20available&amp;cmavesbwd002jms0fy04vz572</loc>
    <lastmod>2025-05-19T18:18:41.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraFalcon%20Detection&amp;cmaveqpc0002ims0fp5oe03xc</loc>
    <lastmod>2025-05-19T18:17:25.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Social%20Engineering%20Attacks%20in%20Teams%20with%20KQL&amp;cmasjoerb000pms0fv14bfarb</loc>
    <lastmod>2025-05-17T18:12:17.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20identities%20with%20zero-day%20Chrome%20vulnerability&amp;cmartyd190008ms0fjwz6p4d7</loc>
    <lastmod>2025-05-17T06:12:12.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-4664%20Chrome%20flaw%20with%20public%20exploit&amp;cmar4r9kx02rpp10faqvgwvqg</loc>
    <lastmod>2025-05-16T18:26:50.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identities-set-to-password-never-expires-with-blast-radius-value-or-tagged-as-sensitive&amp;cmar4iz5y02rop10fygny9fa7</loc>
    <lastmod>2025-05-16T18:20:23.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20AI%20Security%20Finding%20Report&amp;cmao9xzsd02pvp10fz35gspuj</loc>
    <lastmod>2025-05-14T18:28:44.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20Information%20collected%20externally%20when%20a%20URL%20is%20clicked&amp;cmao9vc0d02pup10fte3g73j0</loc>
    <lastmod>2025-05-14T18:26:39.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASN%20generating%20high%20number%20of%20connection%20requests%20based%20on%20average&amp;cmao9uy2m02ptp10fhud6wbmh</loc>
    <lastmod>2025-05-14T18:26:21.927Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20User%20Marked%20as%20Compromised%20By%20Admin%20or%20App&amp;cmamul3xy02owp10f4287up4i</loc>
    <lastmod>2025-05-13T18:31:02.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Internet%20facing%20devices%20vulnerablility%20report&amp;cmal2sby602nrp10fi6cu5m0d</loc>
    <lastmod>2025-05-12T12:45:04.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20M365%20Copilot%20Shared%20Agent&amp;cmal2rlk702nqp10fpix15cr5</loc>
    <lastmod>2025-05-12T12:44:29.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Kerberoasting%20attack&amp;cmal1xeqp02npp10f45lho1nh</loc>
    <lastmod>2025-05-12T12:21:01.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Modifications%20To%20ApplicationManagementPolicy%20for%20Entra%20App%20Registrations&amp;cmakcfyt902n8p10f82m247ph</loc>
    <lastmod>2025-05-12T00:27:37.341Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Blob%20URIs%20creation%20trend%20analysis&amp;cmajznq8w02mzp10f29n2rqwu</loc>
    <lastmod>2025-05-11T18:29:44.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview-DLP-Activity-FileUploadedToCloud&amp;cmajzao9j02myp10fhqjc83td</loc>
    <lastmod>2025-05-11T18:19:35.382Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview-DLP-Activity-FilePrinted&amp;cmajzahbm02mxp10fd577zaub</loc>
    <lastmod>2025-05-11T18:19:26.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview-DLP-Activity-FileCopiedToRemoteDesktopSession&amp;cmajza9y902mwp10f4arojjl1</loc>
    <lastmod>2025-05-11T18:19:16.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview-DLP-Activity-FileCopiedToClipboard&amp;cmajza30n02mvp10fnuso76we</loc>
    <lastmod>2025-05-11T18:19:07.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RMM%20Hunting%20with%20Sentinel%20TI&amp;cmaik3dm202lyp10fgk5hczhs</loc>
    <lastmod>2025-05-10T18:26:14.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SAP%20NetWeaver%20Attack%20by%20Chinese%20Threat%20Actor%20Impact%20Assessment&amp;cmaik2kq702lxp10fh3h5603u</loc>
    <lastmod>2025-05-10T18:25:37.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-20188%20CVSS%2010%20out%20of%2010&amp;cmai75zrn02lop10febittr0i</loc>
    <lastmod>2025-05-10T12:24:21.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra-AdministrativeUnits&amp;cmai6v82g02lnp10f4h5ta3qv</loc>
    <lastmod>2025-05-10T12:15:59.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Outlook%20New%20Requirements%20for%20High%E2%80%90Volume%20Senders&amp;cmafpacp102k2p10fg6tfudqb</loc>
    <lastmod>2025-05-08T18:28:19.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Potential%20Golden%20SAML%20authentication&amp;cmafon7yz02k1p10fi03c15q7</loc>
    <lastmod>2025-05-08T18:10:20.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents%20to%20Mitre%20ATTACK%20navigator&amp;cmafcqtq402jsp10fl30008o0</loc>
    <lastmod>2025-05-08T12:37:12.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Copilot%20Agent%20for%20SharePoint&amp;cmafcoj8u02jrp10fm2t4uty8</loc>
    <lastmod>2025-05-08T12:35:26.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/M365%20Copilot%20Gone%20Rouge&amp;cmaezr9yh02jip10ff2a0e57n</loc>
    <lastmod>2025-05-08T06:33:38.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Personal%20OneDrive%20Sync%20on%20corporate%20endpoints&amp;cmaezqhhi02jhp10f63hl09uu</loc>
    <lastmod>2025-05-08T06:33:02.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousFociTokenLoginsV2&amp;cmad5nqys02i4p10f78n638mc</loc>
    <lastmod>2025-05-06T23:43:19.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectEntraTokenRequestViaBofIoC&amp;cmad5nfwc02i3p10fw7an0640</loc>
    <lastmod>2025-05-06T23:43:05.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Teams-Messages&amp;cmacu736r02i2p10fj5ixdsd9</loc>
    <lastmod>2025-05-06T18:22:26.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-WizIssuesOld&amp;cmactve2j02i1p10falu95wic</loc>
    <lastmod>2025-05-06T18:13:21.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-WizDetections&amp;cmactv3kr02i0p10f9xwy8833</loc>
    <lastmod>2025-05-06T18:13:07.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Golden%20Chickens%20TerraLogger%20Detection&amp;cmachngji02hrp10fra17dxcl</loc>
    <lastmod>2025-05-06T12:31:15.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntPrivilegeEscalationPathsWithHighACLs&amp;cmabq7qsf02h2p10f7cy7v8pz</loc>
    <lastmod>2025-05-05T23:43:12.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Golden%20Chickens%20TerraStealerV2%20Malware%20Detection&amp;cmabeznve02h1p10f2jdv8h1g</loc>
    <lastmod>2025-05-05T18:28:59.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/T1555.003%20-%20Credentials%20from%20Web%20Browsers&amp;cma9mh5ie02fwp10fenojwoyn</loc>
    <lastmod>2025-05-04T12:23:00.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20Mshta%20with%20Sentinel%20TI&amp;cma8k9bru02f7p10f2bvy75ed</loc>
    <lastmod>2025-05-03T18:33:10.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-38475%20Apache%20HTTP%20Server%20Improper%20Escaping%20of%20Output%20Vulnerability&amp;cma74nywt02eap10fvquy2a1x</loc>
    <lastmod>2025-05-02T18:28:53.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20ClickFix%20Triage%20Query&amp;cma748glg02e9p10fj6z7a050</loc>
    <lastmod>2025-05-02T18:16:49.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Commvault%20Exploitation%20in%20Azure&amp;cma5p2i2402dcp10f212d8ike</loc>
    <lastmod>2025-05-01T18:24:31.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20CVE-2025-31324&amp;cma4zgg1b02cvp10f9seiz4kh</loc>
    <lastmod>2025-05-01T06:27:31.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20LoadedFiles&amp;cma4m2x9b02cmp10fcq0r902j</loc>
    <lastmod>2025-05-01T00:13:06.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20service%20creation%20in%20a%20domain%20controller&amp;cma497o4c02cdp10ftll2vwnl</loc>
    <lastmod>2025-04-30T18:12:52.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20network%20share%20access%20in%20a%20domain%20controller&amp;cma497dvp02ccp10fv15yokug</loc>
    <lastmod>2025-04-30T18:12:39.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20access%20to%20distinct%20network%20shares&amp;cma4973ag02cbp10fdpx13wej</loc>
    <lastmod>2025-04-30T18:12:25.575Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Possible%20unusual%20remote%20session%20in%20a%20domain%20controller&amp;cma496vb502cap10f2lh8fl0c</loc>
    <lastmod>2025-04-30T18:12:15.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-Unusual%20PowerShell%20execution&amp;cma3wjwqy02c1p10fbilr83ei</loc>
    <lastmod>2025-04-30T12:18:28.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Zscalar%20IP%20Sign-in%20Check&amp;cma2htqs102b4p10f7ysn4xgg</loc>
    <lastmod>2025-04-29T12:38:26.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Uncovering%20Fast%20Flux%20with%20Sentinel%20Threat%20Intelligence&amp;cma1eydwl02afp10f1mb6u1pk</loc>
    <lastmod>2025-04-28T18:30:18.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousNcryptUsageWithSuspiciousRdpSession&amp;cm9yv9vfj028mp10f8ry8jev3</loc>
    <lastmod>2025-04-26T23:43:49.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousNcryptUsageWithSuspiciousAdminRdpSession&amp;cm9yv9obk028lp10fc5cl82zc</loc>
    <lastmod>2025-04-26T23:43:40.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousNcryptUsageByCliToolOrUnknownProcessWithNonce&amp;cm9yv9f4u028kp10fk6q8kdq0</loc>
    <lastmod>2025-04-26T23:43:28.733Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousNcryptUsageByCliToolOrUnknownProcess&amp;cm9yv98m5028jp10frjj8hqml</loc>
    <lastmod>2025-04-26T23:43:20.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectMultipleWhfbPrtTokensUsedSimultaneouslyForOneDevice&amp;cm9yv923t028ip10ffgwz2ckc</loc>
    <lastmod>2025-04-26T23:43:11.848Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntDevicesDoingRdpToNonTpmDevice&amp;cm9yv8v1m028hp10fz1t8frk3</loc>
    <lastmod>2025-04-26T23:43:02.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntDevicesDoingFirstRdpSession&amp;cm9yv8oru028gp10fnfy943nb</loc>
    <lastmod>2025-04-26T23:42:54.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mapping%20Threat%20Intelligence%20to%20MITRE%20ATT%26CK%20Using%20KQL&amp;cm9yjxpjn028fp10f7sqz7eqg</loc>
    <lastmod>2025-04-26T18:26:26.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cookie-Bite%20Detection&amp;cm9vc64wb026ep10frsnrou7l</loc>
    <lastmod>2025-04-24T12:25:44.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Weaponized%20files%20extracting%20.DLL%20files%20after%20execution&amp;cm9umlta5025xp10frtj8vb8b</loc>
    <lastmod>2025-04-24T00:30:05.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousRUNMRUEntry&amp;cm9u9imbx025op10ftcyxzpxq</loc>
    <lastmod>2025-04-23T18:23:41.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADServicePrincipalSignInLogs-Suspicious%20multiple%20service%20principal%20authentication%20from%20IP%20address&amp;cm9tw5xio025fp10fay109bgg</loc>
    <lastmod>2025-04-23T12:09:54.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Cross-tenant%20settings%20modified&amp;cm9tw5lmm025ep10fin00kk97</loc>
    <lastmod>2025-04-23T12:09:39.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Tracking%20Proton66%20Activity%20with%20KQL&amp;cm9rruvoq0241p10f3sr9knt5</loc>
    <lastmod>2025-04-22T00:33:48.265Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20Response%20by%20tracing%20File%20Lineage&amp;cm9r1zq7t023kp10fg46bej17</loc>
    <lastmod>2025-04-21T12:29:44.289Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mitigating%20security%20risks%20in%20MCP%20implementations&amp;cm9pzdviz022vp10flbs1mxm2</loc>
    <lastmod>2025-04-20T18:28:59.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20chrome%20extension%20with%20hidden%20tracking&amp;cm9melrmi020mp10fk54gwmku</loc>
    <lastmod>2025-04-18T06:23:57.058Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-24054%20NTLM%20Exploit%20in%20the%20Wild%20Detection&amp;cm9k9ijhn01z9p10fkdercw34</loc>
    <lastmod>2025-04-16T18:25:56.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-Unexpected%20service%20creation&amp;cm9k8y12b01z8p10f4ysd7p25</loc>
    <lastmod>2025-04-16T18:09:59.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Uncommon%20process%20connection%20to%20suspicious%20domain&amp;cm9k8xsmr01z7p10f3actic91</loc>
    <lastmod>2025-04-16T18:09:48.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Modifications%20to%20SafeLinks%20AllowClickThrough%20Policy&amp;cm9jwmi4901yyp10fjlhifty1</loc>
    <lastmod>2025-04-16T12:25:05.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BurteForceSingleIPmultipledestinationswithin10minutes&amp;cm9jwfi4o01yxp10fr1iwooth</loc>
    <lastmod>2025-04-16T12:19:39.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Overprivileged%20Admin-Consented%20OAuth%20Applications&amp;cm9iu645y01y8p10f14imt202</loc>
    <lastmod>2025-04-15T18:28:35.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureActivity-Snapshot%20of%20monitored%20Azure%20resource&amp;cm9itjw9901y7p10fh1t38z14</loc>
    <lastmod>2025-04-15T18:11:19.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnusedHighPrivPermissions&amp;cm9he78t701xap10fau8runf1</loc>
    <lastmod>2025-04-14T18:13:48.763Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MostUserConsentApplication&amp;cm9he72lb01x9p10fwhv1sf9e</loc>
    <lastmod>2025-04-14T18:13:40.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalApplicationHighPrivPermissions&amp;cm9he6vtl01x8p10frii8ebcs</loc>
    <lastmod>2025-04-14T18:13:31.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ApplicationMailPermission&amp;cm9he6odu01x7p10fvmks7yns</loc>
    <lastmod>2025-04-14T18:13:22.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20-%20OAuth%20App%20Disabled&amp;cm9e6uppn01v6p10f1hxpu3nm</loc>
    <lastmod>2025-04-12T12:24:48.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IngestionSizeSecurityEvents&amp;cm9e6emyc01v5p10ftfm9cvar</loc>
    <lastmod>2025-04-12T12:12:18.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth%20App%20for%20BEC%20%26%20Phishing%20Detection&amp;cm9d4c6uv01ugp10fjxmya7hg</loc>
    <lastmod>2025-04-11T18:26:38.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AntiSleep%20Domains%20-%20MDE%20DeviceNetworkEvents&amp;cm9criqb901u7p10fi7o65x0g</loc>
    <lastmod>2025-04-11T12:27:48.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-29824%20PipeMagic%20Detection&amp;cm9crg2bn01u6p10f4pkl8mp4</loc>
    <lastmod>2025-04-11T12:25:44.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BlackSuitbublupexfil&amp;cm9a9edob01slp10fxukf5gua</loc>
    <lastmod>2025-04-09T18:25:00.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnsginedExecutionsfromuserdirectories&amp;cm9a9e7ao01skp10fjsj873uh</loc>
    <lastmod>2025-04-09T18:24:51.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/check-if-defender-easm-ips-or-hosts-are-mentioned-in-ddosia-project-current-configuration&amp;cm9a9adcn01sjp10fudr4cbrh</loc>
    <lastmod>2025-04-09T18:21:53.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastPasswordChange&amp;cm9a93osk01sip10fzcnl3de1</loc>
    <lastmod>2025-04-09T18:16:41.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkloadIdentityInfoXdr&amp;cm99wgqn401s9p10f46t6htst</loc>
    <lastmod>2025-04-09T12:22:55.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-OauthAppInfo&amp;cm97r18t701qwp10ftdamc8f1</loc>
    <lastmod>2025-04-08T00:15:22.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Review%20required%20outbound%20connections%20to%20work%20wit%20Defender%20for%20Cloud%20Apps&amp;cm97eb18401qnp10fkwwovz57</loc>
    <lastmod>2025-04-07T18:19:03.796Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/runHuntingQueryStatistics&amp;cm97e0x3f01qmp10fgwk8233x</loc>
    <lastmod>2025-04-07T18:11:11.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/runHuntingQueryExecution&amp;cm95lmrht01php10fx3qwcpt0</loc>
    <lastmod>2025-04-06T12:08:36.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-Non-RFC%20Compliant%20Emails&amp;cm94j3oxz01osp10ff4us9mg9</loc>
    <lastmod>2025-04-05T18:10:00.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-BlockedURLs&amp;cm94j3kq001orp10fgyt2z8vo</loc>
    <lastmod>2025-04-05T18:09:55.216Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-ServiceAccounts&amp;cm94j3f1b01oqp10f2fymxpqx</loc>
    <lastmod>2025-04-05T18:09:47.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-PortableApps&amp;cm94j32ws01opp10fty6nfgal</loc>
    <lastmod>2025-04-05T18:09:32.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20domains%20where%20their%20emails%20will%20be%20routed%20to%20Junk%20folders%20due%20to%20new%20Outlook%20requirement&amp;cm93gpi4901o0p10f4i1roauq</loc>
    <lastmod>2025-04-05T00:15:13.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousFociTokenLogins&amp;cm8rn61yr01gfp10fpzw8vvvg</loc>
    <lastmod>2025-03-27T17:42:49.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20HotSpot%20connections%20shared%20via%20IPhone&amp;cm8pw89jn01fip10ft4plxnw6</loc>
    <lastmod>2025-03-26T12:20:56.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20IngressNightmare%20(CVSS%209.8)&amp;cm8ogrbnx01elp10fr69w8x7o</loc>
    <lastmod>2025-03-25T12:20:05.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Misconfigured%20EXO%20Transport%20Rules&amp;cm8j4370h01b8p10fkvne6mmf</loc>
    <lastmod>2025-03-21T18:26:33.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Active%20Exploitation%20of%20Critical%20Apache%20Tomcat%20RCE%20Vulnerability&amp;cm8j42va501b7p10fgvgdlvcy</loc>
    <lastmod>2025-03-21T18:26:18.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ZDI-CAN-25373%20Windows%20Shortcut%20Exploit%20Abused%20Detection&amp;cm8hohxeg01aap10fwhuq37fk</loc>
    <lastmod>2025-03-20T18:22:20.865Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntDeviceDiscoverySubnetRanges&amp;cm8fus1j3018xp10f6opgfbhn</loc>
    <lastmod>2025-03-19T11:42:38.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/7ZToSMBshare&amp;cm8etxacu018gp10fb25lzmjp</loc>
    <lastmod>2025-03-18T18:30:57.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Uncommon%20process%20connection%20to%20cloudfront%20domain&amp;cm8etemc2018fp10f10pxgur8</loc>
    <lastmod>2025-03-18T18:16:26.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/unfolding-redirectors-using-urlclickevents-table&amp;cm8egu78q0186p10f3kc23yen</loc>
    <lastmod>2025-03-18T12:24:38.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/matching-url-redirectors-from-urlclickevents-table-with-openphish-external-threat-intel-source&amp;cm8egu0x10185p10fahw8n5on</loc>
    <lastmod>2025-03-18T12:24:29.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/matching-ip-redirectors-from-urlclickevents-table-with-urlhaus-external-threat-intel-source&amp;cm8egtutl0184p10fcwb0eudg</loc>
    <lastmod>2025-03-18T12:24:22.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrivilegedUnifiedIdentityInfo&amp;cm8cp1w1a016zp10f9jk28dlv</loc>
    <lastmod>2025-03-17T06:39:01.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Unauthorized%20RMM%20Instances%20in%20Your%20MDE%20Environment&amp;cm8bz14xs016ip10f83z0s9qw</loc>
    <lastmod>2025-03-16T18:30:36.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Website%20Redirectors%20DeviceNetworkEvents&amp;cm8akc28d015lp10fuur4es0p</loc>
    <lastmod>2025-03-15T18:51:25.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Kerberos%20Roasting%20Detection&amp;cm8951dv3014op10fonf46ckd</loc>
    <lastmod>2025-03-14T18:55:26.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20unusual%26suspicious%20TTL%20values%20based%20on%20DNS%20Answers&amp;cm88s8t56014fp10fa8st9v39</loc>
    <lastmod>2025-03-14T12:57:18.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20unusual%26suspicious%20RTT%20values%20based%20on%20DNS%20Answers&amp;cm88s8lk7014ep10fis8vu3ko</loc>
    <lastmod>2025-03-14T12:57:08.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Malicious%20answers%20by%20DNS%20queries&amp;cm88s8eby014dp10fozcix9xk</loc>
    <lastmod>2025-03-14T12:56:59.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Malicious%20URL%20answers%20by%20DNS%20queries&amp;cm88s8580014cp10f13ch93ml</loc>
    <lastmod>2025-03-14T12:56:47.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-SignInLogsTables&amp;cm88rr8ak014bp10fnu4r5adv</loc>
    <lastmod>2025-03-14T12:43:38.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Medusa%20Ransomware%20Detection&amp;cm87p2fzh013mp10fitrm5ftn</loc>
    <lastmod>2025-03-13T18:40:36.460Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousRunMRUentries&amp;cm87oywxt013lp10f5ivrgbrb</loc>
    <lastmod>2025-03-13T18:37:51.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NodeJSSuspiciousExecutions&amp;cm87c1btq013cp10fvvpa07jw</loc>
    <lastmod>2025-03-13T12:35:49.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudflaredArgoTunnelDNS&amp;cm87c0pw8013bp10fmdj6kzvu</loc>
    <lastmod>2025-03-13T12:35:20.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectServiceAccLoginOnNewDevice&amp;cm86kezlk012mp10fen7bgers</loc>
    <lastmod>2025-03-12T23:42:37.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan%2010032025&amp;cm85wosf8012dp10fm37hrxbk</loc>
    <lastmod>2025-03-12T12:38:23.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20LDAP%20Enumeration%20Detection&amp;cm84ukxrl011op10flc89yn95</loc>
    <lastmod>2025-03-11T18:51:38.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/End%20of%20Life%20Software%20with%20File%20Paths%20using%20TVM&amp;cm83elfce010rp10fzhsrzvog</loc>
    <lastmod>2025-03-10T18:36:21.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20Vulnerability%20in%20Elastic%20Kibana&amp;cm831x6iv010ip10fiyl5r5m1</loc>
    <lastmod>2025-03-10T12:41:35.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20CVE-2025-27607%20(CVSS%208.8)&amp;cm81yyu9800ztp10f4on2ey5e</loc>
    <lastmod>2025-03-09T18:31:07.284Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/psexecsvc.py%20detection&amp;cm819ahz900zcp10fl8q4wqy0</loc>
    <lastmod>2025-03-09T06:32:21.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Entra%20ID%20user%20created%20by%20unexpected%20actor&amp;cm7yr4te100xrp10fyo8t0epp</loc>
    <lastmod>2025-03-07T12:28:30.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-22224%20(CVSS%209.3%20CRITICAL)%20Internet%20facing%20VMware%20server%20discovery&amp;cm7yedwi900xip10fco1pz2d0</loc>
    <lastmod>2025-03-07T06:31:39.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Zero-Day%20CVE-2025-21333%20Privilege%20Escalation&amp;cm7xc4nx900wtp10flt12ds69</loc>
    <lastmod>2025-03-06T12:40:43.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExposedTokens-OverviewOfTokenArtifcats&amp;cm7xbyozi00wsp10fkuxmg5iu</loc>
    <lastmod>2025-03-06T12:36:04.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrichedEntraSignInLogs-TokenProtectionNetworkAccess&amp;cm7xbye5g00wrp10fjmk1qm9t</loc>
    <lastmod>2025-03-06T12:35:50.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrichedEntraSignInLogs-SuspiciousTokenRequest&amp;cm7xby4i500wqp10fbvvigo1m</loc>
    <lastmod>2025-03-06T12:35:38.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrichedEntraSignInLogs-RequestedTokenBySuspiciousRT&amp;cm7xbxs7l00wpp10f88j046lh</loc>
    <lastmod>2025-03-06T12:35:22.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnrichedEntraSignInLogs-GsaEnforcementByCaPolicy&amp;cm7xbxhjc00wop10fi55e2ia1</loc>
    <lastmod>2025-03-06T12:35:08.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntADWSRequestsFromUnknownDevice&amp;cm7wx70s000w7p10fosdk1sjr</loc>
    <lastmod>2025-03-06T05:42:38.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20OneOnOne%20chats%20by%20Domains&amp;cm7wmcuo600w6p10fs17t3i4w</loc>
    <lastmod>2025-03-06T00:39:15.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SLA%20-%20TimeToRespond&amp;cm7t1gda600tzp10fmyqoane5</loc>
    <lastmod>2025-03-03T12:30:48.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/System%C2%A0Age%20and%20Update%20Status%C2%A0Analysis&amp;cm7p2bto200rap10fbd5x5zsp</loc>
    <lastmod>2025-02-28T17:44:11.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20Devices%20with%20Outdated%20BIOS&amp;cm7p2bo8z00r9p10fa9qqcrmv</loc>
    <lastmod>2025-02-28T17:44:04.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20CPU%20Architecture%20Distribution&amp;cm7p2bkjh00r8p10flcj4mbdw</loc>
    <lastmod>2025-02-28T17:43:59.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Devices%20with%20Multiple%20Physical%20Disks&amp;cm7p2bhyn00r7p10ffnho163b</loc>
    <lastmod>2025-02-28T17:43:56.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Devices%20with%20BitLocker%20Not%20Enabled&amp;cm7p2bcqf00r6p10ft5oxjklm</loc>
    <lastmod>2025-02-28T17:43:49.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identifying%20domains%20added%20into%20browser%20security%20zones%20via%20CLI&amp;cm7o1ruuh00qpp10ffw2t4j2z</loc>
    <lastmod>2025-02-28T00:40:53.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exploring%20M365%20Accounts%20Investigation&amp;cm7npaavq00qgp10f5l3h9gp7</loc>
    <lastmod>2025-02-27T18:51:19.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/kerberos_failures&amp;cm7nbn66p00q7p10foassmc00</loc>
    <lastmod>2025-02-27T12:29:25.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/network_info_per_device&amp;cm7nbmzdc00q6p10ffhz6ccd3</loc>
    <lastmod>2025-02-27T12:29:16.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsed%20User%20Agent&amp;cm7m9ccr300php10fozdyic9t</loc>
    <lastmod>2025-02-26T18:37:15.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EDR%20and%20AV%20Killer%20-%20A%20Large%20Scale%20Driver%20Exploitation%20Detection&amp;cm7ljceib00p0p10fiv3fnmua</loc>
    <lastmod>2025-02-26T06:29:27.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20to%20calculate%20Tenant%20External%20Recipient%20Rate%20Limit&amp;cm7ktqofo00ojp10fnj9fded8</loc>
    <lastmod>2025-02-25T18:32:43.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EventLogTamperingRegistry&amp;cm7ktm9ne00oip10fvwi6ymbo</loc>
    <lastmod>2025-02-25T18:29:17.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-35250&amp;cm7kgwufu00o9p10fnsfcac18</loc>
    <lastmod>2025-02-25T12:33:36.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20CLFS%20Driver%20Load&amp;cm7kgwa8000o8p10ft6v9ab2r</loc>
    <lastmod>2025-02-25T12:33:09.927Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GoogleSheetsC2Query&amp;cm7kgvqxh00o7p10fzml29fgi</loc>
    <lastmod>2025-02-25T12:32:45.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan%2024022025&amp;cm7k3pqqc00nyp10f96lmtel2</loc>
    <lastmod>2025-02-25T06:24:09.724Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADServicePrincipalSignInLogs-Unexpected%20authentication%20failure%20from%20service%20principal&amp;cm7j1smcw00n9p10fvyobjuij</loc>
    <lastmod>2025-02-24T12:42:38.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GitLab%20Threat%20Intelligence%20Identified%2016%20Malicious%20Chrome%20extensions&amp;cm7ioushu00n0p10fky2wrt38</loc>
    <lastmod>2025-02-24T06:40:25.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntMdeWithGsaEvents&amp;cm7hx2es700mbp10fppcrlz02</loc>
    <lastmod>2025-02-23T17:42:31.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TLD%20by%20Count%20for%20DeviceNetworkEvents&amp;cm7hlzoem00map10fgdi0yl2o</loc>
    <lastmod>2025-02-23T12:32:27.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20AuthenticationMethodsUsed&amp;cm7hll5rc00m9p10fssoeftuk</loc>
    <lastmod>2025-02-23T12:21:10.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/M365%20Copilot%20Chat%20SafeLink%20Monitoring&amp;cm7g6uwkb00lcp10f2ri5r2i6</loc>
    <lastmod>2025-02-22T12:41:04.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Palo%20Alto%20Firewall%20Exploits&amp;cm7f4x13m00knp10ftjz6bglq</loc>
    <lastmod>2025-02-21T18:58:58.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulDeviceCodeAuthentication&amp;cm7f4juhu00kmp10fcfhmhzen</loc>
    <lastmod>2025-02-21T18:48:43.553Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20New%20Variant%20of%20Snake%20Keylogger&amp;cm7edx5eb00k5p10fkn0zyj1h</loc>
    <lastmod>2025-02-21T06:23:14.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Most%20Recent%20Sign-in%20time%20for%20users%20in%20the%20last%2030%20days&amp;cm7cm3t3800j0p10fcmr9svig</loc>
    <lastmod>2025-02-20T00:36:49.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOCs%20for%20SmartApeSG%20fake%20browser%20update%20leads%20to%20NetSupport%20RAT%20and%20StealC&amp;cm7clzf7000izp10flwvbf2jg</loc>
    <lastmod>2025-02-20T00:33:25.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Weekly%20OSINT%20Indicators%20Scan&amp;cm7bwbh8400iip10fwt0m4hag</loc>
    <lastmod>2025-02-19T12:34:57.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20OpenSSH%20Vulnerabilities%20%E2%80%93%20Patch%20Prioritization&amp;cm7al92mq00hlp10f9gtvs7e5</loc>
    <lastmod>2025-02-18T14:37:23.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identifying%20Devices%20by%20Vendor%26Country%20based%20on%20Inbound%20Connections&amp;cm7al6v7900hkp10fsw70frpf</loc>
    <lastmod>2025-02-18T14:35:40.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identifying%20Devices%20by%20Vendor%20based%20on%20Inbound%20Connections&amp;cm7al6o9400hjp10f6bxncgym</loc>
    <lastmod>2025-02-18T14:35:31.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EDR%20Evasion%20-%20Inject%20Shellcode%20via%20MSSQL%20CLR%20Assembly%20Detection&amp;cm7a3nfna00hap10fxse8h4tz</loc>
    <lastmod>2025-02-18T06:24:40.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulDeviceCodeAuthenticationUnmanagedDevice&amp;cm79qfvi500h1p10fbx6x61oy</loc>
    <lastmod>2025-02-18T00:14:52.581Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQLObfusGuard%20-%20Detecting%20ArgFuscator%20Obfuscation&amp;cm77yfpbh00fwp10feajamik8</loc>
    <lastmod>2025-02-16T18:23:09.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20WafflesExploits%20Shellcode%20in%20Image%20Files&amp;cm77yfcmc00fvp10f5kzpest5</loc>
    <lastmod>2025-02-16T18:22:52.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/The%20Hunt%20for%20Top%2010%20Self%20Hosted%20AI&amp;cm766b1bk00eqp10ft3mpkchu</loc>
    <lastmod>2025-02-15T12:27:55.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-with-critical-logged-on-users-and-shares-with-permission-set-to-everyone&amp;cm71vz91200c1p10foriw6ppq</loc>
    <lastmod>2025-02-12T12:27:45.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20link%20from%20email&amp;cm70tlhmv00bcp10fjwugcq3a</loc>
    <lastmod>2025-02-11T18:33:17.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20email&amp;cm70tl2y200bbp10ff72rhb8o</loc>
    <lastmod>2025-02-11T18:32:58.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20Copilot%20Data%20Exfiltration%20via%20Graph%20API&amp;cm70iecfg00b2p10fuv9ksoih</loc>
    <lastmod>2025-02-11T13:19:48.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20for%20malicious%20login%20attempts%20based%20on%20basic%20authentication&amp;cm70iamis00b1p10fjv1ypcg2</loc>
    <lastmod>2025-02-11T13:16:55.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LLM%20Hunting%20in%20a%20MDE%20Environment&amp;cm703v5lw00asp10f63r29vf0</loc>
    <lastmod>2025-02-11T06:32:58.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Using%20GraphPreConsentExplorer%20data%20for%20Microsoft%20Graph%20Threat%20Hunting&amp;cm6z1ktp400a3p10f9uj6g4uj</loc>
    <lastmod>2025-02-10T12:41:11.511Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Software%20Download%20Sites%20DeviceNetworkEvents&amp;cm6xlpgss0096p10fvsw872vs</loc>
    <lastmod>2025-02-09T12:29:08.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Creation%20of%20spoof%20directories%20with%20Unicode%20characters&amp;cm6v3x2jb007lp10f06j5w3t2</loc>
    <lastmod>2025-02-07T18:35:37.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HTTP%20Client%20Tools%20Exploitation%20for%20ATO%20Detection&amp;cm6urayil007cp10filqmprzn</loc>
    <lastmod>2025-02-07T12:42:30.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWS%20NoSuchBucket%20Check&amp;cm6tbi6lk006fp10fum4370px</loc>
    <lastmod>2025-02-06T12:32:27.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20QR%20Code%20Sign-In%20KQL%20Detection&amp;cm6syxcbn0066p10fq7ibe16m</loc>
    <lastmod>2025-02-06T06:40:19.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender%20XDR%20Custom%20Detection%20Modifications&amp;cm6s9bv6x005pp10f2gv7bn46</loc>
    <lastmod>2025-02-05T18:43:47.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Antivirus%20Domains%20-%20MDE%20DeviceNetworkEvents&amp;cm6rvvhaw005gp10ftkvjti2w</loc>
    <lastmod>2025-02-05T12:27:07.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-MMA-AgentCleanup&amp;cm6rvjt7j005fp10fxagg9qb9</loc>
    <lastmod>2025-02-05T12:18:03.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20usage%20latest&amp;cm6rix56n0056p10fwuyqhpr0</loc>
    <lastmod>2025-02-05T06:24:30.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows11-Issues-OS%20Build%2026100-2033&amp;cm6riwc4c0055p10fjte68bft</loc>
    <lastmod>2025-02-05T06:23:51.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20OLE%20Zero-Click%20Vulnerability%20Let%20Attacker%20to%20Execute%20Arbitrary%20Code&amp;cm6r6gsiv004wp10ftor8ik3r</loc>
    <lastmod>2025-02-05T00:35:51.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Crowdstrike%20Impersonation%20during%20Global%20Outage&amp;cm6qh6bni004fp10fg4fccy5w</loc>
    <lastmod>2025-02-04T12:47:53.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BlockList%20Project%20DeviceNetworkEvents&amp;cm6qh5wn5004ep10fnrn4v8tt</loc>
    <lastmod>2025-02-04T12:47:33.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Adult%20Content%20MDE%20DeviceNetworkEvents&amp;cm6qh5kwe004dp10fq1so8lws</loc>
    <lastmod>2025-02-04T12:47:18.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sysinternals%20Tools%20Zero%20Day%20Vulnerability%20Detection&amp;cm6qh3l0q004cp10fr43v71ue</loc>
    <lastmod>2025-02-04T12:45:45.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Extracting%20bits%20of%20TCP%20Flags&amp;cm6pr3m35003vp10f7w0w51nk</loc>
    <lastmod>2025-02-04T00:37:56.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20RBAC%20Elevated%20Access&amp;cm6pdnfk9003mp10f6em44mv6</loc>
    <lastmod>2025-02-03T18:21:26.629Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Active%20Directory%20Domain%20Services%20Elevation%20of%20Privilege%20Vulnerability%20(CVE-2025-21293)&amp;cm6nlfg1m002hp10fncbbh01s</loc>
    <lastmod>2025-02-02T12:23:38.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ROSTI%20(Repackaged%20Open%20Source%20Intelligence)%20MDE%20Network%20Events%20IOC%20Hits&amp;cm6mj4gfl001sp10fovakrprv</loc>
    <lastmod>2025-02-01T18:31:20.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ROSTI%20(Repackaged%20Open%20Source%20Intelligence)%20MDE%20File%20Events%20IOC%20Hits&amp;cm6mj48z9001rp10flisd7jjc</loc>
    <lastmod>2025-02-01T18:31:10.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Rogue%20Endpoints%20via%20SMB%20Detection&amp;cm6mj2ejh001qp10fb22rzt63</loc>
    <lastmod>2025-02-01T18:29:44.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anonymous%20Email%20Sending%20Domains%20MDE%20Traffic&amp;cm6lgmply0011p10ftky35kpb</loc>
    <lastmod>2025-02-01T00:33:47.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Global%20Admin%20Elevations%20To%20User%20Access%20Administrator%20at%20Root%20Level&amp;cm6l551pl000sp10fjw0a7trl</loc>
    <lastmod>2025-01-31T19:12:07.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntCompromisedBrowserExtensions&amp;cm6kp5iy5000bp10fw7ruyvc4</loc>
    <lastmod>2025-01-31T11:44:35.883Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CefToCommonSecurityLog&amp;cm6kp5av1000ap10fs6jzu446</loc>
    <lastmod>2025-01-31T11:44:25.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectUserRequestTokenForAdminApp&amp;cm6kp525x0009p10fwmzv0ghr</loc>
    <lastmod>2025-01-31T11:44:14.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectSuspiciousCaChanges&amp;cm6kp4uku0008p10flwrcenla</loc>
    <lastmod>2025-01-31T11:44:04.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntNnrHealthIssues&amp;cm6kp4ihp0007p10flf5l9pb5</loc>
    <lastmod>2025-01-31T11:43:48.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntPublicDevicesWithoutTag&amp;cm6kp49f60006p10fvxssljaz</loc>
    <lastmod>2025-01-31T11:43:36.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntPublicDevicesWithTag&amp;cm6kp41pd0005p10fthoumsgj</loc>
    <lastmod>2025-01-31T11:43:26.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntPublicDevicesOverTime&amp;cm6kp3t750004p10f0d1c5v2l</loc>
    <lastmod>2025-01-31T11:43:15.855Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntOrganizeDevicesBySubnet&amp;cm6kp3iyt0003p10flukj9c0k</loc>
    <lastmod>2025-01-31T11:43:02.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntDevicesSupportingMdeContainment&amp;cm6kp32f70002p10fqblkokcb</loc>
    <lastmod>2025-01-31T11:42:41.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectTokenStealingWithWdac&amp;cm6kp2t100001p10fsziiegnn</loc>
    <lastmod>2025-01-31T11:42:28.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectCveExploitForVulnerableDevice&amp;cm6kp2jst0000p10fs8gd6gqb</loc>
    <lastmod>2025-01-31T11:42:17.017Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20File%20Explorer%20Elevation%20Of%20Privilege%20Vulnerability(CVE-2024-38100)%20Exploited&amp;cm6k3jo4z00f5nw0fk62pxp28</loc>
    <lastmod>2025-01-31T01:39:44.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Malicious%20Impersonation%20of%20Deepseek%20Domains%20in%20Email%20URLs&amp;cm6iaz5jg00e0nw0fq9sa81b7</loc>
    <lastmod>2025-01-29T19:32:11.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Securing%20Your%20Azure%20Cloud%20-%20Finding%20the%20Weakest%20Link%20in%20Admin%20Endpoints&amp;cm6g5s6t900cnnw0f0uuxf3cs</loc>
    <lastmod>2025-01-28T07:31:16.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RID%20Hijacking%20Technique%20and%20Detection&amp;cm6e0lskh00banw0fnx6sfjac</loc>
    <lastmod>2025-01-26T19:30:47.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/leveraging-spamhaus-drop-list-to-identify-suspicious-connections-in-commonsecuritylog-table&amp;cm6dnl3xx00b1nw0f1uwerfer</loc>
    <lastmod>2025-01-26T13:26:20.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/leveraging-spamhaus-drop-list-to-identify-delivered-emails-from-suspicious-source-ips&amp;cm6dnkw5x00b0nw0fdarle3ke</loc>
    <lastmod>2025-01-26T13:26:10.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Subscription%20Budget%20Deletion&amp;cm6b5xk9b009fnw0fpt1d3m2q</loc>
    <lastmod>2025-01-24T19:36:36.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20fake%20Reddit%20sites%20push%20Lumma%20Stealer%20malware%20-%20Part%202&amp;cm6asn9dp0096nw0fg27myf8o</loc>
    <lastmod>2025-01-24T13:24:40.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADNonInteractiveUserSignInLogs-Unexpected%20failures%20in%20non-interactive%20authentications%20from%20an%20app&amp;cm6as3bmy0095nw0fg9u0jhvt</loc>
    <lastmod>2025-01-24T13:09:10.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20fake%20Reddit%20sites%20push%20Lumma%20Stealer%20malware%20-%20Part%201&amp;cm6afw8ir008wnw0f0hl675y3</loc>
    <lastmod>2025-01-24T07:27:44.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADNonInteractiveUserSignInLogs-Unexpected%20authentication%20from%20Windows%20Azure%20Active%20Directory%20app&amp;cm69qinfo008fnw0f4afukiz2</loc>
    <lastmod>2025-01-23T19:37:19.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID%20-%20Suspicious%20activity%20reported&amp;cm68n7xv7007qnw0f6wy5ybun</loc>
    <lastmod>2025-01-23T01:17:15.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID%20-%20SSPR%20Configuration%20Changes&amp;cm68n7tyo007pnw0fer9bygo5</loc>
    <lastmod>2025-01-23T01:17:10.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-PIM-Group-Members&amp;cm68n7l3a007onw0f235jrpp0</loc>
    <lastmod>2025-01-23T01:16:58.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-EnterpriseApps-Disabled&amp;cm68n7egt007nnw0f4zvakhix</loc>
    <lastmod>2025-01-23T01:16:50.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellExecutionsFromClipboard&amp;cm68aikut007enw0fi7ztu28t</loc>
    <lastmod>2025-01-22T19:21:36.531Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Fortigate%20Belsen%20Leak%20KQL%20Check&amp;cm67y7z9r0075nw0f9pa8whkp</loc>
    <lastmod>2025-01-22T13:37:26.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastCheckInArcMachines&amp;cm65fkemh005knw0fpfosih5i</loc>
    <lastmod>2025-01-20T19:19:41.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/summarizing%20user%20searches%20outside%20of%20normal%20working%20hours%20that%20contains%20sensitive%20keywords%20(CISA)&amp;cm652sdrz005bnw0fsnjnm7so</loc>
    <lastmod>2025-01-20T13:21:58.462Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify%20mail%20items%20accessed%20by%20a%20specific%20IP%20address%20(CISA)&amp;cm652s7lm005anw0fnefkb6cy</loc>
    <lastmod>2025-01-20T13:21:50.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risky%20Sign-in%20Keyword%20Search%20(CISA)&amp;cm652s0qs0059nw0f5dw9aa8n</loc>
    <lastmod>2025-01-20T13:21:41.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Display%20Teams%20participation%20duration%20of%20account%20associated%20with%20a%20suspicious%20IP%20address&amp;cm652rtk50058nw0fq6h6wtu0</loc>
    <lastmod>2025-01-20T13:21:32.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Windows%20Security%20Event%20Logs%20Cleaned&amp;cm652ned20057nw0frlephbk7</loc>
    <lastmod>2025-01-20T13:18:05.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2025-21298%20Zero-Click%20RCE&amp;cm64px7o2004ynw0fevzq896i</loc>
    <lastmod>2025-01-20T07:21:48.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OnboardedMachinesByResourceGroup&amp;cm63zvdwn004hnw0fpdsy3ie0</loc>
    <lastmod>2025-01-19T19:12:33.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sneaky%202FA%20MDO%20Detection&amp;cm62l3tyl003knw0fa5ca501b</loc>
    <lastmod>2025-01-18T19:31:27.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/visualizing-fortigate-cve-2022-40684-belsen-group-leaked-affected-ips&amp;cm6162r7n002nnw0fcn871pnv</loc>
    <lastmod>2025-01-17T19:42:56.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQLWiz%20PDF%20NTLM%20Leak%20Detector&amp;cm5z0fzyq001anw0f2oeurp0c</loc>
    <lastmod>2025-01-16T07:29:44.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Ivanti%20Vulnerabilities%20CVE-2025-0282%20and%20CVE-2025-0283&amp;cm5xxqxx8000lnw0f475i38xw</loc>
    <lastmod>2025-01-15T13:26:29.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Base64%20Code%20in%20Commands&amp;cm5xxqm0z000knw0f3qpe9zxi</loc>
    <lastmod>2025-01-15T13:26:14.367Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20P2S%20(Point%20to%20site)%20Connection%20Success%20username%20and%20IP%20Parser&amp;cm5xkz7zq000bnw0fuapm9m4k</loc>
    <lastmod>2025-01-15T07:29:01.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%F0%9D%97%97%F0%9D%97%B2%F0%9D%98%81%F0%9D%97%B2%F0%9D%97%B0%F0%9D%98%81%F0%9D%97%B6%F0%9D%97%BB%F0%9D%97%B4%20%F0%9D%97%95%F0%9D%97%AE%F0%9D%98%80%F0%9D%97%B2%F0%9D%9F%B2%F0%9D%9F%B0%20%F0%9D%97%96%F0%9D%97%BC%F0%9D%97%B1%F0%9D%97%B2%20%F0%9D%97%B6%F0%9D%97%BB%20%F0%9D%97%96%F0%9D%97%BC%F0%9D%97%BA%F0%9D%97%BA%F0%9D%97%AE%F0%9D%97%BB%F0%9D%97%B1%F0%9D%98%80&amp;cm5xkvo4p000anw0fs42lpyi0</loc>
    <lastmod>2025-01-15T07:26:15.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Lumma%20Stealer%20commands&amp;cm5xkvh960009nw0f1fpo7v1c</loc>
    <lastmod>2025-01-15T07:26:06.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVES_Cases&amp;cm5xkv6zo0008nw0fk1g938bd</loc>
    <lastmod>2025-01-15T07:25:53.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Aqua%20Blizzards&amp;cm5xj8bx200055idwkw0wkr74</loc>
    <lastmod>2025-01-15T06:40:06.996Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO%20Email%20Threat%20Classification%20By%20ISP&amp;cm5xj7v6l00045idwj1boq931</loc>
    <lastmod>2025-01-15T06:39:45.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO%20Email%20Threat%20Classification%20By%20Country&amp;cm5xj7pvf00035idwelf4dh04</loc>
    <lastmod>2025-01-15T06:39:38.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20fasthttp%20Bruteforce%20Campaign&amp;cm5xj7gxw00025idwhhyf601r</loc>
    <lastmod>2025-01-15T06:39:26.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20NonEuclid%20RAT&amp;cm5xj79ui00015idwuf7sqdgz</loc>
    <lastmod>2025-01-15T06:39:17.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunt%20for%20High%20Volume%20Phish%20ISP&amp;cm5xj73zs00005idw4wmusi4f</loc>
    <lastmod>2025-01-15T06:39:10.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Potential%20compliant%20device%20bypass%20attempt&amp;cm5o83j6100jbtj0fg38wxbe0</loc>
    <lastmod>2025-01-08T18:18:31.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-43452%20PoC%20Detection&amp;cm5m34usl00hytj0frr9mgt94</loc>
    <lastmod>2025-01-07T06:24:02.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-49113%20-%20LDAPNightmare&amp;cm5m2ug9m00hxtj0fdipgpwx7</loc>
    <lastmod>2025-01-07T06:15:57.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Resource%20Lock%20Deletion%20for%20Azure%20Monitor%20Rule&amp;cm5i59n2z00fgtj0fv0ahlim8</loc>
    <lastmod>2025-01-04T12:12:40.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MachineOnboarded&amp;cm5i4vhl800fftj0fzjqgcujl</loc>
    <lastmod>2025-01-04T12:01:40.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LDAPNightmare%20POC%20Detection&amp;cm5gq3c3f00eitj0fzmv4lzfn</loc>
    <lastmod>2025-01-03T12:20:06.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20Incident%20Deletions&amp;cm5fnbn0v00dttj0fxm0o2j3u</loc>
    <lastmod>2025-01-02T18:14:48.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Log%20Analytic%20Workspace%20Deletions&amp;cm5fnbg5r00dstj0fz9545b6c</loc>
    <lastmod>2025-01-02T18:14:39.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Monitor%20Rule%20Disabled&amp;cm5e7uplf00cvtj0fl743il40</loc>
    <lastmod>2025-01-01T18:13:58.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Bring%20Your%20Own%20Minifilter%20-%20EDR%20Bypass&amp;cm5d5hxdq00c6tj0fx7c5mivj</loc>
    <lastmod>2025-01-01T00:20:16.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Living%20Off%20The%20Tunnels%20IOCS&amp;cm5bpz7oo00b9tj0f2peo6wm0</loc>
    <lastmod>2024-12-31T00:18:03.047Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AD%20unusual%20operation&amp;cm5azuidq00astj0f850n89zg</loc>
    <lastmod>2024-12-30T12:06:33.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Malicious%20Chrome%20Extension&amp;cm5anndpp00ajtj0ffls3oony</loc>
    <lastmod>2024-12-30T06:25:05.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CustomDetectionDisabled&amp;cm5852vul008ytj0fv870vpp7</loc>
    <lastmod>2024-12-28T12:09:43.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-3393%20DDOS%20Detection&amp;cm56q42uv0081tj0f4e2dxv6v</loc>
    <lastmod>2024-12-27T12:22:59.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rating%20ISPs%20to%20detect%20potential%20malicious%20domains%20sending%20threats&amp;cm5608jo4007ktj0f1twxc7pl</loc>
    <lastmod>2024-12-27T00:18:37.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20of%20OOF%20message%20delivered%20externally&amp;cm5608ex0007jtj0fiyuiphme</loc>
    <lastmod>2024-12-27T00:18:31.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20spoofed%20email%20cases&amp;cm5608ag0007itj0fgqlh0kmg</loc>
    <lastmod>2024-12-27T00:18:25.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/September_updates&amp;cm5608513007htj0fb3bwh9k1</loc>
    <lastmod>2024-12-27T00:18:18.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20Senders%20hidden%20behind%20anonymous%20proxies&amp;cm5607v61007gtj0fytekyfnl</loc>
    <lastmod>2024-12-27T00:18:05.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Exclusion%20into%20Conditional%20Access%20Policies&amp;cm51cygqa004jtj0fc8rktvew</loc>
    <lastmod>2024-12-23T18:15:51.192Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnonymizedMicrosoftGraphActivityLogs&amp;cm51co2bd004itj0fg4x9oyam</loc>
    <lastmod>2024-12-23T18:07:46.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20TorConnections&amp;cm4y540jd002htj0f1wiw072q</loc>
    <lastmod>2024-12-21T12:12:54.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Advanced%20Vishing%20KQL%20Detection&amp;cm4uxn480000gtj0fhammt4qs</loc>
    <lastmod>2024-12-19T06:20:30.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UrlHaus%20Abuse.ch%20Hits%20in%20Microsoft%20Teams&amp;cm4twge7e00mcmc0l2b00amad</loc>
    <lastmod>2024-12-18T12:59:31.033Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShell%20Self-Pwn&amp;cm4s4093o00l7mc0lprkceo3c</loc>
    <lastmod>2024-12-17T06:55:22.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RansomwareToolMatrix%20Defender%20Lookup&amp;cm4rdw7wg00kqmc0lcglgvsv4</loc>
    <lastmod>2024-12-16T18:44:24.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20for%20registry%20artifacts%20of%20service%20creation&amp;cm4ngshme00i9mc0l5r2oexqj</loc>
    <lastmod>2024-12-14T00:54:24.565Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20for%20process%20command%20line%20artifacts%20of%20service%20creation&amp;cm4ngsds800i8mc0lcer4zjud</loc>
    <lastmod>2024-12-14T00:54:19.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20Programs%20Set%20to%20Auto-Run%20at%20Startup&amp;cm4n2cqc700hrmc0l2uw2wzmb</loc>
    <lastmod>2024-12-13T18:10:14.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20if%20TPM%202.0%20is%20available&amp;cm4n2ck2400hqmc0l8vo8w1y5</loc>
    <lastmod>2024-12-13T18:10:06.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20Top%20Disk%20IO%20Processes&amp;cm4n2cf8z00hpmc0lb6ndeay7</loc>
    <lastmod>2024-12-13T18:10:00.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Flag%20Processes%20With%20Disproportionately%20Large%20Virtual%20Memory%20Usage&amp;cm4n2cb2h00homc0lyxab5acw</loc>
    <lastmod>2024-12-13T18:09:54.952Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Processes%20With%20Unusually%20High%20Thread%20or%20Handle%20Counts&amp;cm4n2c6ot00hnmc0lqbj0yk33</loc>
    <lastmod>2024-12-13T18:09:49.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Old%20BIOS%20Versions&amp;cm4n2brr800hmmc0lnww2e7ud</loc>
    <lastmod>2024-12-13T18:09:29.923Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DocuShield%20-%20NRT%20Anti-Impersonation%20Email%20Purge&amp;cm4lonn7900gxmc0lat0dfhsm</loc>
    <lastmod>2024-12-12T18:59:03.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MicrosoftGraphActivityLogs%20missing%20logs&amp;cm4lo7lz200gwmc0l4wvhchhu</loc>
    <lastmod>2024-12-12T18:46:34.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Teams%20Red%20Team%20Tool%20ConvoC2&amp;cm4k9a28800g7mc0lkni4kfkx</loc>
    <lastmod>2024-12-11T19:00:48.967Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Zloader%20DNS%20Tunneling&amp;cm4jvwmtg00fymc0lfigzlgw1</loc>
    <lastmod>2024-12-11T12:46:27.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20M.Teams%20activities%20such%20as%20shared%20URLs%2C%20OneToOne%20chats%20and%20Domains%20participating%20into%20meetings&amp;cm4itbaq800f9mc0l78x2xl8g</loc>
    <lastmod>2024-12-10T18:46:06.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%22UrlHaus%20Abuse.ch%20Hits%20in%20Microsoft%20Teams&amp;cm4itb4az00f8mc0lvd2jy7b1</loc>
    <lastmod>2024-12-10T18:45:58.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Enhanced%20Cloudflare%20Phishing%20Email%20Detections&amp;cm4igh8ra00ezmc0ljsgscmnv</loc>
    <lastmod>2024-12-10T12:46:48.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20CodeRecommendations&amp;cm4hqubd000eimc0ld5gr6yfw</loc>
    <lastmod>2024-12-10T00:49:08.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behaviour%20-%20SuspiciousNamedPipes&amp;cm4hdlh7u00e9mc0lw6qa6l60</loc>
    <lastmod>2024-12-09T18:38:21.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Black%20Basta%20Ransomware%20Campaign%20RMMTools%20Deployment&amp;cm4h0yois00e0mc0lg853mppr</loc>
    <lastmod>2024-12-09T12:44:42.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20DefenderXDR%20services%20and%20features%20disabled%20on%20devices&amp;cm4gb3us600djmc0lvf4u2cya</loc>
    <lastmod>2024-12-09T00:40:53.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BlueAlpha%20GammaDrop%20Detection&amp;cm4dsyxt800bymc0l2amjubpy</loc>
    <lastmod>2024-12-07T06:37:39.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20URL%20File%20NTLM%20Hash%20Disclosure%20Vulnerability%20Detection%20(0day)&amp;cm4dg9awy00bpmc0lawbnuai1</loc>
    <lastmod>2024-12-07T00:41:47.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20Events%20from%20Email%20Providers&amp;cm4d3uydu00bgmc0l56sqvfio</loc>
    <lastmod>2024-12-06T18:54:42.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20malicious%20oauth%20grant%20by%20phished%20user&amp;cm4bbf5nm00abmc0lgs01rc6o</loc>
    <lastmod>2024-12-05T12:50:50.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-non-compliant-controls-with-relevant-remediation-actions&amp;cm4bb99tq00aamc0ls4t1l1pn</loc>
    <lastmod>2024-12-05T12:46:15.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-and-summarize-processor-families-in-your-environment&amp;cm4bb94fh00a9mc0lcbebptn9</loc>
    <lastmod>2024-12-05T12:46:08.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ActiveCISAKEV&amp;cm495qqyf008wmc0lu5tp87ag</loc>
    <lastmod>2024-12-04T00:36:20.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Abuse%20of%20Wevtutil.exe%20in%20LOLBAS%20Attacks&amp;cm483xqk70087mc0l81wgz8m9</loc>
    <lastmod>2024-12-03T06:58:01.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Classifying%20Browser%20Extension%20by%20Type%20and%20risk%20severity&amp;cm47qq2md007ymc0ldul8ipna</loc>
    <lastmod>2024-12-03T00:48:09.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Any.Run%20Corrupt%20File%20Zero%20Day%20Attack&amp;cm47dxfgb007pmc0lqwxy9uaq</loc>
    <lastmod>2024-12-02T18:49:57.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LargeNumberOfAnalyticsRulesDeleted&amp;cm47dnt95007omc0lfsri69gj</loc>
    <lastmod>2024-12-02T18:42:28.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20Timeroasting%20KQL%20detection&amp;cm46o4s4d0077mc0ltqndvh12</loc>
    <lastmod>2024-12-02T06:47:50.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20KQL%20Detection%20for%20ShadowHound&amp;cm45lk3ar006imc0liyrbuzao</loc>
    <lastmod>2024-12-01T12:47:59.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/InboundAuthenticationFromPublicIP&amp;cm45l9gvi006hmc0les58lh4v</loc>
    <lastmod>2024-12-01T12:39:44.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20Justifications%20for%20PIM%20Requests&amp;cm44j2dil005smc0lpvkomory</loc>
    <lastmod>2024-11-30T18:50:27.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Disabling%20Global%20Secure%20Access%20by%20Registry&amp;cm44j21b8005rmc0lz5pqdgbq</loc>
    <lastmod>2024-11-30T18:50:11.875Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Rockstar%202FA&amp;cm433j0rv004umc0lywf39qqf</loc>
    <lastmod>2024-11-29T18:47:44.298Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Social%20Engineering%20Attack%20Monitor%20-%20Teams%20%26%20Emails&amp;cm42djfoq004dmc0lxtac2fwl</loc>
    <lastmod>2024-11-29T06:40:13.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADSignInEventsBeta%20-%20Suspicious%20User%20agent&amp;cm41bafn5003omc0lawkttvvj</loc>
    <lastmod>2024-11-28T12:49:28.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudApp%20Suspicious%20Copilot%20Agent%20Detection&amp;cm3zvzrkd002rmc0lzaugay86</loc>
    <lastmod>2024-11-27T12:53:30.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint%20SMB%20exposed%20on%20Public%20Internet&amp;cm3y3cdt1001mmc0loqvaw3ui</loc>
    <lastmod>2024-11-26T06:43:43.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Unusual%20anomaly&amp;cm3x0z37e000xmc0lmfmpl0uh</loc>
    <lastmod>2024-11-25T12:49:38.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/get-to-know-your-misp-threat-intelligence-feed&amp;cm3wbd1pi000gmc0l2d9uu74x</loc>
    <lastmod>2024-11-25T00:52:39.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/office%20Add-in%20Installs&amp;cm3vwrcef000v5ieomukchxn3</loc>
    <lastmod>2024-11-24T18:03:52.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Temporary%20Email%20Addresses&amp;cm3vwr7v7000u5ieo9gf3lmtl</loc>
    <lastmod>2024-11-24T18:03:46.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20File%20Extension%20Upload%20to%20Office%20365&amp;cm3vwr371000t5ieo5prpdjtb</loc>
    <lastmod>2024-11-24T18:03:40.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OnionMail%20EmailAddresses&amp;cm3vwqyty000s5ieo8wccmxz9</loc>
    <lastmod>2024-11-24T18:03:34.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CockLi%20Abused%20Email%20Provider&amp;cm3vwqscn000r5ieohdyzz4vk</loc>
    <lastmod>2024-11-24T18:03:26.075Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignIns%20with%20Country%20Name&amp;cm3vwqnjw000q5ieouefh32fi</loc>
    <lastmod>2024-11-24T18:03:19.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Get%20Tenant%20ID%20for%20Given%20Domain&amp;cm3vwqdes000p5ieo7irhj3jk</loc>
    <lastmod>2024-11-24T18:03:06.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Smart%20Lockout%20Tampering&amp;cm3vwq7uh000o5ieozpr1vzv4</loc>
    <lastmod>2024-11-24T18:02:59.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Creation%20of%20new%20Azure%20Tenant&amp;cm3vwpy5z000n5ieodnocha5l</loc>
    <lastmod>2024-11-24T18:02:46.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20Justifications%20for%20Self%20Approval%20PIM%20Requests&amp;cm3vwpsed000m5ieo5xdm3l0l</loc>
    <lastmod>2024-11-24T18:02:39.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Unsigned%20script%20execution%20enabled%20for%20live%20response&amp;cm3vwpmos000l5ieof3rdvkd6</loc>
    <lastmod>2024-11-24T18:02:32.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/USB_Data_Exfiltration&amp;cm3vwpflu000k5ieo6jdxy6uj</loc>
    <lastmod>2024-11-24T18:02:22.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Total%20Device%20Risk%20Score&amp;cm3vwp7ip000j5ieomfxbl4sl</loc>
    <lastmod>2024-11-24T18:02:12.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Streaming%20Sites%20-%20DeviceNetworkEvents&amp;cm3vwot02000i5ieokif6lqx2</loc>
    <lastmod>2024-11-24T18:01:53.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Remote%20Management%20Tools%20(RMM)%20-%20DeviceNetworkEvents%20Domains&amp;cm3vwomx4000h5ieoejkua7g1</loc>
    <lastmod>2024-11-24T18:01:45.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potentially%20Unsanctioned%20Application%20Usage&amp;cm3vwog2b000g5ieod04bc0h1</loc>
    <lastmod>2024-11-24T18:01:36.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potentially%20Ungoverned%20AI%20Domains%20such%20as%20chatgpt&amp;cm3vwo8ez000f5ieoshessyjo</loc>
    <lastmod>2024-11-24T18:01:26.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20Credential%20Dumping&amp;cm3vwo3bx000e5ieopww9vp2y</loc>
    <lastmod>2024-11-24T18:01:20.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Piracy%20Domains%20-%20DeviceNetworkEvents&amp;cm3vwnx68000d5ieo0avinphr</loc>
    <lastmod>2024-11-24T18:01:12.367Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Personal%20Messaging%20Domains%20-%20DeviceNetworkEvents&amp;cm3vwnln1000c5ieo875ueyw4</loc>
    <lastmod>2024-11-24T18:00:57.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Paste%20and%20Anonymous%20File%20Transfer%20Sites%20-%20DeviceNetworkEvents&amp;cm3vwnc66000b5ieocjoxggph</loc>
    <lastmod>2024-11-24T18:00:45.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20Blocks%20by%20Application%20and%20URL&amp;cm3vwn3y4000a5ieo70o18qtq</loc>
    <lastmod>2024-11-24T18:00:34.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Gaming%20Domains%20-%20DeviceNetworkEvents&amp;cm3vwmvtb00095ieo6y96hw42</loc>
    <lastmod>2024-11-24T18:00:23.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exploitable_CVE_AllDevices&amp;cm3vwmpuq00085ieo3gpnfbst</loc>
    <lastmod>2024-11-24T18:00:16.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices%20with%20the%20most%20known%20exploited%20vulnerabilities&amp;cm3vwmj3q00075ieogrb1k63w</loc>
    <lastmod>2024-11-24T18:00:07.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Tor%20DNS%20request&amp;cm3vwmds500065ieo0yruizgh</loc>
    <lastmod>2024-11-24T18:00:00.579Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Consumer%20VPN%20Domains%20-%20DeviceNetworkEvents&amp;cm3vwm8ka00055ieowim0c9bc</loc>
    <lastmod>2024-11-24T17:59:53.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Connections%20to%20abused%20TLDs%20-%20DeviceNetworkEvents&amp;cm3vwm2kb00045ieoc6dd5fq7</loc>
    <lastmod>2024-11-24T17:59:46.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE%20Check%20with%20Software%20Evidence&amp;cm3vwlvae00035ieohcx9icpf</loc>
    <lastmod>2024-11-24T17:59:36.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Browser%20Extension%20Downloads%20using%20DeviceFileEvents&amp;cm3vwlobg00025ieox93vw2fv</loc>
    <lastmod>2024-11-24T17:59:27.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Browser%20Domains%20-%20DeviceNetworkEvents&amp;cm3vwliry00015ieojjeplhu7</loc>
    <lastmod>2024-11-24T17:59:20.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anti-lock%20or%20Idle%20Software&amp;cm3vwlcov00005ieo8u0jsaot</loc>
    <lastmod>2024-11-24T17:59:12.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20Malicious%20Copilot%20Agent&amp;cm3vpygcq00015izw6bxvg3y9</loc>
    <lastmod>2024-11-24T14:53:26.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Phishing%20Emails%20with%20Cloudflare%20R2%20URLs&amp;cm3vpya3900005izw3237lady</loc>
    <lastmod>2024-11-24T14:53:18.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rating%20ISP%20to%20detect%20potential%20attacks%20and%20IOCs%20source&amp;cm3rs37e800dnmc0ty3cj8iid</loc>
    <lastmod>2024-11-21T20:42:02.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20Campaign%20-%20Exploiting%20SVG%20Files%20and%20trycloudflare.com%20to%20Spread%20Malware&amp;cm3r1xdgh00d6mc0tk9ewh7nk</loc>
    <lastmod>2024-11-21T08:29:40.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ClickFix%20social%20engineering%20attack%20detection&amp;cm3pn4l6i00c9mc0tntr7iwih</loc>
    <lastmod>2024-11-20T08:47:36.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20BrazenBamboo&apos;s%20FortiClient%20Exploit%20-%20A%20KQL%20Approach&amp;cm3okb8ss00bkmc0tlg0pe9ht</loc>
    <lastmod>2024-11-19T14:41:02.283Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-0012%20PAN-OS%20-%20Authentication%20Bypass%20in%20the%20Management%20Web%20Interface&amp;cm3nhrhz000avmc0tbkj4z1ha</loc>
    <lastmod>2024-11-18T20:41:55.343Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20Third-Party%20application%20Access%20via%20OAuth&amp;cm3nhhb1a00aumc0tehfhf3hm</loc>
    <lastmod>2024-11-18T20:34:00.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20SSH%20Authentication&amp;cm3nhh62c00atmc0th2t3me8e</loc>
    <lastmod>2024-11-18T20:33:53.651Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20Log%20Audit%20Events&amp;cm3nhh1uu00asmc0to0gp0357</loc>
    <lastmod>2024-11-18T20:33:48.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20External%20Guest%20Access&amp;cm3nhgwal00armc0th4s2kpcm</loc>
    <lastmod>2024-11-18T20:33:40.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20Enable%20IP%20Conditional%20Access%20policy%20validation&amp;cm3nhgomq00aqmc0tpqjzp6i6</loc>
    <lastmod>2024-11-18T20:33:30.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20Allow%20Public%20Projects&amp;cm3nhgk3v00apmc0tw5i4890h</loc>
    <lastmod>2024-11-18T20:33:25.193Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDevOps%20-%20Additional%20Protection%20when%20using%20public%20package%20registries&amp;cm3nhgcdy00aomc0t07rz261u</loc>
    <lastmod>2024-11-18T20:33:14.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Brands%20Impersonation%20Phishing%20Trend&amp;cm3mrw7m400a7mc0t0gzr45wr</loc>
    <lastmod>2024-11-18T08:37:45.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Innovative%20Detection%20Techniques%20Against%20ZIP%20Concatenation%20Attacks&amp;cm3m1tygz009qmc0tu32pjq3t</loc>
    <lastmod>2024-11-17T20:28:10.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-49039%20Windows%20Task%20Scheduler%20Elevation%20of%20Privilege%20Vulnerability&amp;cm3iu7vh4007pmc0tsi877fgv</loc>
    <lastmod>2024-11-15T14:31:44.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20break%20the%20glass%20Groups&amp;cm3iu2y9b007omc0t0xvt1rsz</loc>
    <lastmod>2024-11-15T14:27:54.335Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Privileged%20Role%20Assignments&amp;cm3iu2r07007nmc0t520k52lw</loc>
    <lastmod>2024-11-15T14:27:45.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Missing%20DlpRuleMatch%20entities%20in%20CloudAppEvents&amp;cm3itp8cp007mmc0tqu8pedto</loc>
    <lastmod>2024-11-15T14:17:14.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20authentication%20failure%20status&amp;cm3hrkf9z006xmc0to5b6w8j5</loc>
    <lastmod>2024-11-14T20:29:44.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DnsEvents-Possible%20DNSRecon%20query&amp;cm3heju1n006omc0tc4z4ftxv</loc>
    <lastmod>2024-11-14T14:25:21.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BigYellowTaxi%20-%20SignIn&amp;cm3gc9wok005zmc0tgcqha9yc</loc>
    <lastmod>2024-11-13T20:33:53.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Weird%20DNS%20queries&amp;cm3gc4b7f005ymc0tmf37xv73</loc>
    <lastmod>2024-11-13T20:29:32.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20Cross-Tenant%20Abuse%20by%20Threat%20Actors&amp;cm3fzmal5005pmc0tk0diigv3</loc>
    <lastmod>2024-11-13T14:39:36.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-43451%20Zero-Day%20(NTLM%20Hash%20Disclosure%20Spoofing%20Vulnerability)&amp;cm3fmd6m4005gmc0tmtc1gzcc</loc>
    <lastmod>2024-11-13T08:28:36.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20FIDO2%20Passkey%20Abuse&amp;cm3ekotg4004rmc0tlesbbqlj</loc>
    <lastmod>2024-11-12T14:53:53.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Phishing%20by%20Design%20Two-Step%20Attacks%20Using%20vsdx%20Files&amp;cm3e78trj004imc0tbqe7bq2q</loc>
    <lastmod>2024-11-12T08:37:32.629Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DnsEvents-Unusual%20DNS%20query%20type%20of%20internal%20domain&amp;cm3dh07vp0041mc0tqe13g6hi</loc>
    <lastmod>2024-11-11T20:23:01.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Zscaler%20Registry%20Tampering%20Detection&amp;cm3bo4n7z002omc0teky967fl</loc>
    <lastmod>2024-11-10T14:06:52.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Zscaler%20Private%20Access%20Data%20Gap%20Detection&amp;cm3bo4k4e002nmc0tl5dvzpwt</loc>
    <lastmod>2024-11-10T14:06:48.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Zscaler%20Internet%20Access%20Data%20Gap%20Detection&amp;cm3bo4g8j002mmc0tl3f8bmqs</loc>
    <lastmod>2024-11-10T14:06:43.364Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ZAP%20Email%20Click%20Detection&amp;cm3bo4cwd002lmc0tdz7psp1m</loc>
    <lastmod>2024-11-10T14:06:39.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20Security%20Log%20Enumeration%20Detection&amp;cm3bo48ds002kmc0tezilk5fj</loc>
    <lastmod>2024-11-10T14:06:33.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WiFi%20Password%20Dumping%20Detection&amp;cm3bo43oj002jmc0tdaqt0fvg</loc>
    <lastmod>2024-11-10T14:06:27.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vulnerable%20Inactive%20Devices%20Detection&amp;cm3bo405o002imc0tabjyxcjf</loc>
    <lastmod>2024-11-10T14:06:22.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VIP%20Mailbox%20Permission%20Change%20Detection&amp;cm3bo3v1h002hmc0tajaggq4g</loc>
    <lastmod>2024-11-10T14:06:16.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VBScript%20Usage%20Detection&amp;cm3bo3plu002gmc0tk6bw0zab</loc>
    <lastmod>2024-11-10T14:06:08.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20Application%20Brute%20Force%20Detection&amp;cm3bo3hzd002fmc0tm7xmhnj6</loc>
    <lastmod>2024-11-10T14:05:59.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UrlClickEvents%20to%20OpenPhish%20URL&amp;cm3bo3dsc002emc0trlxb3za5</loc>
    <lastmod>2024-11-10T14:05:53.675Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Unusual%20Software%20Certificate%20Detection&amp;cm3bo382v002dmc0tyqzfy5sh</loc>
    <lastmod>2024-11-10T14:05:46.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/URL%20Download%20Source%20Finder&amp;cm3bo32a3002cmc0tbvka25yk</loc>
    <lastmod>2024-11-10T14:05:38.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TrustedInstaller%20Abuse%20Detection&amp;cm3bo2yim002bmc0th9m1kf70</loc>
    <lastmod>2024-11-10T14:05:33.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Volexity%20Feed%20Urls%20in%20EmailUrlInfo&amp;cm3bo2uo4002amc0tsvsdhn6z</loc>
    <lastmod>2024-11-10T14:05:28.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20User%20Risk%20Event%20IP%20in%20Firehol%20IPset%20List&amp;cm3bo2qgi0029mc0t8hj5o1s4</loc>
    <lastmod>2024-11-10T14:05:23.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Urlhaus%20Feed%20Hit%20in%20EmailUrlInfo&amp;cm3bo2kvs0028mc0t6vrdfith</loc>
    <lastmod>2024-11-10T14:05:16.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20TweetFeed%20URLs%20in%20Emails&amp;cm3bo2fj50027mc0toyah4efp</loc>
    <lastmod>2024-11-10T14:05:09.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20PhishingArmy%20Hit%20in%20EmailUrlInfo&amp;cm3bo2ax90026mc0tr3u6svix</loc>
    <lastmod>2024-11-10T14:05:03.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20NetworkEvents%20listed%20on%20Threatfox%20abuse.ch&amp;cm3bo277p0025mc0t52rq943g</loc>
    <lastmod>2024-11-10T14:04:58.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20NetworkEvent%20with%20Urlhaus%20abuse.ch%20Hit&amp;cm3bo23pe0024mc0tgh8a30b8</loc>
    <lastmod>2024-11-10T14:04:53.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Malicious%20Connection%20to%20Firehol%20Ipset%20List&amp;cm3bo1yc20023mc0trehdkzzf</loc>
    <lastmod>2024-11-10T14:04:46.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20AbuseCH%20Malicious%20Hash&amp;cm3bo1oab0022mc0t16bbx2ue</loc>
    <lastmod>2024-11-10T14:04:33.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Botvrji%20Url%20in%20EmailUrlInfo&amp;cm3bo1iqx0021mc0tbfe1wkk8</loc>
    <lastmod>2024-11-10T14:04:26.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20Directory%20Sync%20Account%20Sign%20ins&amp;cm3bo1eoe0020mc0tid2j73uz</loc>
    <lastmod>2024-11-10T14:04:21.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Shadow%20Credentials%20Attack%20Detection&amp;cm3bo18rx001zmc0tu2jtjh3b</loc>
    <lastmod>2024-11-10T14:04:13.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Server%20Domain%20Firewall%20Profile%20Check&amp;cm3bo142l001ymc0tthtqku08</loc>
    <lastmod>2024-11-10T14:04:07.772Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sent%20Items%20Deletion%20Detection&amp;cm3bo10xu001xmc0tuz9wn2mv</loc>
    <lastmod>2024-11-10T14:04:03.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Safeboot%20Registry%20Modification%20Detection&amp;cm3bo0vvh001wmc0ti5xg1ped</loc>
    <lastmod>2024-11-10T14:03:57.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/STOP%20Ransomware%20Command%20Detection&amp;cm3bo0si7001vmc0t94b8e0nu</loc>
    <lastmod>2024-11-10T14:03:52.640Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rule%20Aggregation%20Template&amp;cm3bo0owy001umc0ta19t1ccx</loc>
    <lastmod>2024-11-10T14:03:48.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rogue%20Device%20Detection&amp;cm3bo0jeq001tmc0tekvwfyw4</loc>
    <lastmod>2024-11-10T14:03:40.993Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risky%20Sign%20in%20after%20UrlClick%20to%20MontySecurity%20GoPhish%20IP&amp;cm3bo0e6z001smc0tl0bucb5e</loc>
    <lastmod>2024-11-10T14:03:34.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risky%20Sign%20in%20after%20Tweetfeed%20URL%20IP%20Click&amp;cm3bo09fg001rmc0t4ngwkb46</loc>
    <lastmod>2024-11-10T14:03:28.054Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Risky%20Sign%20in%20Followed%20by%20MFA%20Registration&amp;cm3bo01hw001qmc0trv3ylk5g</loc>
    <lastmod>2024-11-10T14:03:17.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Related%20Processes%20via%20DeviceProcessEvents&amp;cm3bnzuy5001pmc0t0joez41a</loc>
    <lastmod>2024-11-10T14:03:09.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RDP%20Toggle%20Lateral%20Movement%20Detection&amp;cm3bnzqni001omc0tqif3ojg8</loc>
    <lastmod>2024-11-10T14:03:03.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Quasar%20RAT%20IOC%20Detection&amp;cm3bnzlse001nmc0t9mabqwp5</loc>
    <lastmod>2024-11-10T14:02:57.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20Audit%20Search%20Monitoring&amp;cm3bnzhzi001mmc0ti4spy8a5</loc>
    <lastmod>2024-11-10T14:02:52.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShell%20Defensive%20Evasion%20Detection&amp;cm3bnze4k001lmc0tnhuwu8sv</loc>
    <lastmod>2024-11-10T14:02:47.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20Phishing%20Hosting%20Site%20URL%20Clicks&amp;cm3bnzb50001kmc0tk8p1hir5</loc>
    <lastmod>2024-11-10T14:02:43.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Password%20Success%20from%20Malicious%20IP&amp;cm3bnz8ms001jmc0trluntfla</loc>
    <lastmod>2024-11-10T14:02:40.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Non%20Familiar%20DHCP%20Domains%20Detection&amp;cm3bnyzq0001imc0t1xc2v0vj</loc>
    <lastmod>2024-11-10T14:02:28.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Nmap%20Reconnaissance%20Detection&amp;cm3bnyvun001hmc0tgbqiuv13</loc>
    <lastmod>2024-11-10T14:02:23.806Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20Office%20365%20Activity%20Detection&amp;cm3bnypy8001gmc0t09bdriqt</loc>
    <lastmod>2024-11-10T14:02:16.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20Entra%20ID%20Audit%20Operations%20Detection&amp;cm3bnym7b001fmc0t2n70z7qs</loc>
    <lastmod>2024-11-10T14:02:11.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20Services%20Port%20Protocol%20Mapping&amp;cm3bnygy0001emc0t9ainnkqw</loc>
    <lastmod>2024-11-10T14:02:04.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Netskope%20Malicious%20CloudWorker%20Detection&amp;cm3bnydao001dmc0tva45gduz</loc>
    <lastmod>2024-11-10T14:01:59.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MpCmdRun%20Custom%20Scan%20Path%20Detection&amp;cm3bny8fb001cmc0tz8csx1ak</loc>
    <lastmod>2024-11-10T14:01:53.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Most%20Attacked%20VIPs&amp;cm3bny3v2001bmc0t7ukei2vt</loc>
    <lastmod>2024-11-10T14:01:47.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Missing%20Recommended%20Security%20Updates%20Detection&amp;cm3bnxx46001amc0tnxk09z6g</loc>
    <lastmod>2024-11-10T14:01:38.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Phishing%20Subdomain%20Detection&amp;cm3bnxt7x0019mc0tydg3nkzp</loc>
    <lastmod>2024-11-10T14:01:33.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MalwareBazaar%20Certificate%20Blocklist%20Detection&amp;cm3bnxn4r0018mc0tixrlb7da</loc>
    <lastmod>2024-11-10T14:01:25.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malware%20Sending%20Domains%20with%20Inbox%20Delivery&amp;cm3bnxi680017mc0t3teqw6c3</loc>
    <lastmod>2024-11-10T14:01:19.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20Zoom%20Installer%20Detection&amp;cm3bnx93r0016mc0tzw0f99fp</loc>
    <lastmod>2024-11-10T14:01:07.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20ISP%20Detection&amp;cm3bnx5y60015mc0tq24jrxvc</loc>
    <lastmod>2024-11-10T14:01:03.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDAV%20Scan%20Status%20None%20Cancelled%20Full%20Scans&amp;cm3bnx0xh0014mc0tgsija4ua</loc>
    <lastmod>2024-11-10T14:00:57.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20Custom%20Warn%20Indicators%20Report&amp;cm3bnww8j0013mc0t9etsaxfa</loc>
    <lastmod>2024-11-10T14:00:50.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Log%20Analytics%20Workspace%20Daily%20Ingestion&amp;cm3bnwqp40012mc0t6r3wp74q</loc>
    <lastmod>2024-11-10T14:00:43.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20Privileged%20Command%20Detection&amp;cm3bnwhmd0011mc0t3xjfgqqf</loc>
    <lastmod>2024-11-10T14:00:32.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20Nmap%20Reconnaissance%20Detection&amp;cm3bnwdgc0010mc0tn1459x6l</loc>
    <lastmod>2024-11-10T14:00:26.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20MDE%20Missing%20Vulnerabilities%20Detection&amp;cm3bnw9me000zmc0tht4ejnor</loc>
    <lastmod>2024-11-10T14:00:21.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Known%20Bad%20Hash%20Process%20Detection&amp;cm3bnw5w1000ymc0twbqr9o34</loc>
    <lastmod>2024-11-10T14:00:16.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOC%20Check%20in%20Multiple%20Sources&amp;cm3bnw052000xmc0tx2u49x9c</loc>
    <lastmod>2024-11-10T14:00:09.255Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hanada%20Group%20Crowdstrike%20Impersonation%20Detection&amp;cm3bnvuna000wmc0tb8igi1c4</loc>
    <lastmod>2024-11-10T14:00:02.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphStrike%20C2%20Beacon%20Detection&amp;cm3bnvqxp000vmc0tiq71cbu9</loc>
    <lastmod>2024-11-10T13:59:57.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Fake%20CAPTCHA%20Campaign%20PowerShell%20Detection&amp;cm3bnvmqi000umc0tckpzyl57</loc>
    <lastmod>2024-11-10T13:59:51.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FOCI%20Client%20ID%20Detection&amp;cm3bnvi2l000tmc0tcyp41gbd</loc>
    <lastmod>2024-11-10T13:59:45.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FIDO%20AAGUID%20Passkey%20Explorer&amp;cm3bnvcz4000smc0ts948d4m7</loc>
    <lastmod>2024-11-10T13:59:39.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/External%20Email%20Forwarding%20Rule%20Detection&amp;cm3bnv7h9000rmc0trfpkdgrd</loc>
    <lastmod>2024-11-10T13:59:32.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/External%20Device%20Logon%20Detection&amp;cm3bnv3q2000qmc0t1zqnggf0</loc>
    <lastmod>2024-11-10T13:59:27.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20ID%20Service%20Principal%20Sign%20in%20Insights&amp;cm3bnuyz9000pmc0tjk268wl0</loc>
    <lastmod>2024-11-10T13:59:21.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Enabled%20Account%20Password%20Spray%20Detection&amp;cm3bnuvnh000omc0td4zry4k3</loc>
    <lastmod>2024-11-10T13:59:16.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20TI%20Url%20listed%20on%20Threatfox%20in%20EmailUrlInfo&amp;cm3bnupl1000nmc0trp0uqgb2</loc>
    <lastmod>2024-11-10T13:59:09.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Domain%20Extensions%20by%20Country%20Analysis&amp;cm3bnuixj000mmc0tp5q22p2l</loc>
    <lastmod>2024-11-10T13:59:00.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents%20Blocklist%20Project%20Hits&amp;cm3bnuduk000lmc0t0zggtvu0</loc>
    <lastmod>2024-11-10T13:58:53.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20ATP%20Tampering%20Detection&amp;cm3bnua80000kmc0tthjyeslk</loc>
    <lastmod>2024-11-10T13:58:49.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detection%20of%20Spoofed%20Emails&amp;cm3bnu3vs000jmc0twpg3iniw</loc>
    <lastmod>2024-11-10T13:58:40.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Deleted%20Mail%20Items%20Monitoring&amp;cm3bntzd3000imc0tcnkx7xxt</loc>
    <lastmod>2024-11-10T13:58:35.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender%20Script%20Scanning%20Disable%20Detection&amp;cm3bntsb6000hmc0tzpsa311t</loc>
    <lastmod>2024-11-10T13:58:25.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender%20AV%20Failed%20Full%20Scans&amp;cm3bnos9t000gmc0tbdpo66lb</loc>
    <lastmod>2024-11-10T13:54:32.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Default%20Local%20Admin%20Logon%20Detection&amp;cm3bnonwv000fmc0tre8vb2xs</loc>
    <lastmod>2024-11-10T13:54:26.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data%20Ingestion%20Status%20Monitoring&amp;cm3bnoj1b000emc0te6jox3fo</loc>
    <lastmod>2024-11-10T13:54:20.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Daily%20Data%20Usage%20and%20User%20Analysis&amp;cm3bnoeqk000dmc0tdsus3o7o</loc>
    <lastmod>2024-11-10T13:54:15.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Daggerfly%20IOC%20Detection&amp;cm3bnoazg000cmc0tqmejy2z9</loc>
    <lastmod>2024-11-10T13:54:10.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Daggerfly%20IOC%20Detection%20Sentinel&amp;cm3bno5n2000bmc0t0zq39ymw</loc>
    <lastmod>2024-11-10T13:54:03.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Custom%20IOC%20Block%20Events&amp;cm3bno1zi000amc0tkuiwqmqv</loc>
    <lastmod>2024-11-10T13:53:58.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cryptocurrency%20Domain%20Detection&amp;cm3bnnwmh0009mc0t35xm332o</loc>
    <lastmod>2024-11-10T13:53:51.592Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Correlated%20IP%20Events%20from%20Important%20Watchlist&amp;cm3bnnt800008mc0t8w1lblc1</loc>
    <lastmod>2024-11-10T13:53:47.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudWorker%20Abuse%20Detection&amp;cm3bnnobo0007mc0t6156wvd4</loc>
    <lastmod>2024-11-10T13:53:40.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Chinese%20APT%20VS%20Code%20Exploitation%20Detection&amp;cm3bnnkkv0006mc0t625367sz</loc>
    <lastmod>2024-11-10T13:53:35.983Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Binaries%20using%20AnyDesk%20Compromised%20Certificate&amp;cm3bnnetw0005mc0tnd3ksrt6</loc>
    <lastmod>2024-11-10T13:53:28.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Accounts%20Under%20Attack%20From%20Multiple%20Countries&amp;cm3bnn8pc0004mc0trkdq6axu</loc>
    <lastmod>2024-11-10T13:53:20.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Access%20Global%20Failed%20Login&amp;cm3bnn3h00003mc0twjxynmqy</loc>
    <lastmod>2024-11-10T13:53:13.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWS%20GPU%20Instance%20Launch%20Detection&amp;cm3bnmzl10002mc0ts01clmyj</loc>
    <lastmod>2024-11-10T13:53:08.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/APT29%20TeamViewer%20Activity%20Detection&amp;cm3bnmv900001mc0t1ovd53s7</loc>
    <lastmod>2024-11-10T13:53:03.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD%20Provisioning%20Attribute%20Modification%20Report&amp;cm3bnmq4q0000mc0tbcvx22xg</loc>
    <lastmod>2024-11-10T13:52:56.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20External%20Microsoft%20Teams%20Spray&amp;cm38ib0mx02gjmc0pxv9unpdc</loc>
    <lastmod>2024-11-08T09:00:33.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AdvancedFeatureDisabled&amp;cm37suiaj02g2mc0p0lqt9q7m</loc>
    <lastmod>2024-11-07T21:07:52.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Abusing%20Intune%20Permissions%20for%20Lateral%20Movement&amp;cm373u3wp02flmc0p4xfswxg3</loc>
    <lastmod>2024-11-07T09:27:43.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-10443%20Hunting%3A%20RISK%3ASTATION&amp;cm35ofvdk02eomc0po3ayk2f5</loc>
    <lastmod>2024-11-06T09:28:59.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20VEILDrive%20C2&amp;cm35ald0702efmc0p72kdt25e</loc>
    <lastmod>2024-11-06T03:01:20.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDCA%20MDO%20-%20MailItemsAccessedByCompromisedAccount&amp;cm34xj1pg02e6mc0plg5r03a5</loc>
    <lastmod>2024-11-05T20:55:37.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EDRSandblast&amp;cm335iavb02d1mc0pn0n1t9wo</loc>
    <lastmod>2024-11-04T15:03:27.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/suspicious-rdp-files-in-outlook-temporary-folders&amp;cm323abar02ccmc0px0tvca7w</loc>
    <lastmod>2024-11-03T21:13:29.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Community%20Repositories&amp;cm3233qy702cbmc0pniv7lsec</loc>
    <lastmod>2024-11-03T21:08:22.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20WordPress%20plugins%20from%20HTTP%20requests&amp;cm2xsjto6029mmc0pthdjkghw</loc>
    <lastmod>2024-10-31T21:01:52.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LargeNumberOfVMsStarted&amp;cm2xs9tid029lmc0plbt4ltf6</loc>
    <lastmod>2024-10-31T20:54:05.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20CopilotModelsUsed&amp;cm2uxf0xm027smc0p81yxuv4a</loc>
    <lastmod>2024-10-29T20:54:48.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20potential%20sign-In%20Attempts%20from%20Airport%20Networks&amp;cm2nh2w3c0233mc0pa8fxzz01</loc>
    <lastmod>2024-10-24T15:43:05.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-browser-extensions-with-can-turnoff-malware-protections-permissions-in-endpoints-with-no-tamper-protection&amp;cm2hcjsx801zamc0ptk6admnv</loc>
    <lastmod>2024-10-20T08:49:39.108Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Honeypot%20Threat%20Intelligence%20(TI)%20Data&amp;cm2gng5it01ytmc0pn51q8tjt</loc>
    <lastmod>2024-10-19T21:06:58.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO%20-%20Enhancing%20Email%20Security%20with%20NRD%20Filtering&amp;cm2dg3w8r01wsmc0pr2rza91a</loc>
    <lastmod>2024-10-17T15:18:10.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Port%20Scanning%20on%20Internet-Facing%20Devices&amp;cm2ccwfcx01w3mc0p0o005i4c</loc>
    <lastmod>2024-10-16T21:00:37.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20sensitive%20and%20confidential%20files%20sent%20by%20Email&amp;cm2c15w5e01vumc0pmok8booj</loc>
    <lastmod>2024-10-16T15:32:03.457Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender%20XDR%20alert%20evidence%20summarized&amp;cm2c0serf01vtmc0pnsdl1c7l</loc>
    <lastmod>2024-10-16T15:21:34.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20M365%20Copilot%20Extensions%20Threat%20Monitoring&amp;cm2bn6ju901vkmc0peh883o1k</loc>
    <lastmod>2024-10-16T09:00:39.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20User%20Account%20Compromised%20by%20C2&amp;cm2almszf01uvmc0pxrw6kyhr</loc>
    <lastmod>2024-10-15T15:29:32.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malfunction%20Hunting%20Query%20not%20working%20in%20Graph%20API&amp;cm2al7v3u01uumc0plywaa4qb</loc>
    <lastmod>2024-10-15T15:17:55.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/The%20Hunt%20for%20Blob%20Phishing%20Mail%20Domain&amp;cm29w408a01uhmc0p4q569rrm</loc>
    <lastmod>2024-10-15T03:35:04.858Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrioritizeSecureConfiguration&amp;cm29ikige01u8mc0p8sc2qo38</loc>
    <lastmod>2024-10-14T21:16:00.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/%F0%9D%97%A7%F0%9D%97%B5%F0%9D%97%B2%20%F0%9D%97%9B%F0%9D%98%82%F0%9D%97%BB%F0%9D%98%81%20%F0%9D%97%B3%F0%9D%97%BC%F0%9D%97%BF%20%F0%9D%97%95%F0%9D%97%B9%F0%9D%97%BC%F0%9D%97%AF%20%F0%9D%97%A3%F0%9D%97%B5%F0%9D%97%B6%F0%9D%98%80%F0%9D%97%B5%F0%9D%97%B6%F0%9D%97%BB%F0%9D%97%B4%20%F0%9D%97%A0%F0%9D%97%AE%F0%9D%97%B6%F0%9D%97%B9%20%F0%9D%97%97%F0%9D%97%BC%F0%9D%97%BA%F0%9D%97%AE%F0%9D%97%B6%F0%9D%97%BB&amp;cm296voud01tzmc0pbrfdu45o</loc>
    <lastmod>2024-10-14T15:48:46.453Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Chrome%20extension%20stealth%20persistence%20detection&amp;cm27pozn801t2mc0pwa0y58cx</loc>
    <lastmod>2024-10-13T14:59:54.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/M365%20Copilot%20Extensions%20Threat%20Monitoring&amp;cm27cmt0w01stmc0pytrz6ec4</loc>
    <lastmod>2024-10-13T08:54:17.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20New%20Copilot%20Extensions&amp;cm26mylko01scmc0ptugwdhpg</loc>
    <lastmod>2024-10-12T20:55:37.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Technique%20profile%20eDiscovery%20misuse%20detection&amp;cm257kxe501rfmc0pps01ovxz</loc>
    <lastmod>2024-10-11T20:57:19.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20CVE-2024-43572%20Abuse&amp;cm23f79dr01qamc0p6vfdcmxu</loc>
    <lastmod>2024-10-10T14:55:06.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceRename&amp;cm22pmrbf01ptmc0plirh9u6d</loc>
    <lastmod>2024-10-10T02:59:19.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DefenderExclusionsEnumerations&amp;cm22pmls201psmc0piekrkolz</loc>
    <lastmod>2024-10-10T02:59:12.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AvScanResults&amp;cm21zzsxg01pbmc0pcf0q704o</loc>
    <lastmod>2024-10-09T15:01:37.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-SID-History%20changed&amp;cm21zteu801pamc0ppx7optdl</loc>
    <lastmod>2024-10-09T14:56:39.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-ADFS%20DKM%20property%20read&amp;cm21zt67t01p9mc0p5e76zxlu</loc>
    <lastmod>2024-10-09T14:56:28.600Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-UnifiedAZKVAuditLogs&amp;cm20x4tdn01okmc0pn8vblwts</loc>
    <lastmod>2024-10-08T20:53:46.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CustomDetectionReport&amp;cm20kfng101obmc0psiudqza3</loc>
    <lastmod>2024-10-08T14:58:17.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Mamba%202FA%20phishing-as-a-service&amp;cm20830iz01o2mc0py6yvsi2i</loc>
    <lastmod>2024-10-08T09:12:32.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20PnP%20devices%20connected%20to%20my%20endpoint%20machines&amp;cm1ys20o401n5mc0pzawuatfn</loc>
    <lastmod>2024-10-07T08:56:05.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top%2010%20Most%20Sprayed%20UPNs%20by%20IPs%20and%20Countries%20using%20BehaviourAnalytics&amp;cm1xcrcib01m8mc0p4tvn7uwr</loc>
    <lastmod>2024-10-06T09:00:07.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-network-shares-with-write-permissions-set-to-everyone-in-highly-exposed-devices&amp;cm1xcm02101m7mc0pxjxmp8bj</loc>
    <lastmod>2024-10-06T08:55:58.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/self-signed-certificates&amp;cm1xclvyu01m6mc0pzxgw7w2l</loc>
    <lastmod>2024-10-06T08:55:52.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20-%20Threat%20Hunting%20DNS%20Tunneling&amp;cm1vx4l5v01l9mc0p1mpvs1iq</loc>
    <lastmod>2024-10-05T08:54:45.281Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20-%20Threat%20Hunting%20DNS%20Tunneling&amp;cm1vx3m0x01l8mc0phj7hmnwf</loc>
    <lastmod>2024-10-05T08:53:59.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20-%20MDE%20Network%20Intrusion%20Discovery&amp;cm1ts6hnd01jvmc0pzq80r1fv</loc>
    <lastmod>2024-10-03T21:00:43.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Windows%20Side-Loading%20DLL%20attacks&amp;cm1tf674r01jmmc0pryd2vck9</loc>
    <lastmod>2024-10-03T14:56:34.970Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RMMConnection&amp;cm1sc813e01ixmc0pnjl7noj0</loc>
    <lastmod>2024-10-02T20:46:15.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Missing%20logs%20in%20EmailEvents&amp;cm1rz6o7m01iomc0p6q68uptt</loc>
    <lastmod>2024-10-02T14:41:17.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Measuring%20Sentinel%20WatchList%20Effectiveness%20using%20Behaviour%20Analytics&amp;cm1ncc87s01frmc0p4ho4hhxk</loc>
    <lastmod>2024-09-29T08:50:40.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Custom%20Detection%20for%20CVE-2024-38200%20NTLMv2%20Hash%20Exposure&amp;cm1ncbcpg01fqmc0p81j4n059</loc>
    <lastmod>2024-09-29T08:49:59.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Cross-Tenant%20Activity%20Monitoring&amp;cm1lwxxpt01etmc0p0h710hg0</loc>
    <lastmod>2024-09-28T08:51:53.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Custom%20Detection%20Rule%20for%20CUPS%20Installation%20in%20DefenderXDR&amp;cm1l78xeb01ecmc0pkt79f5f9</loc>
    <lastmod>2024-09-27T20:52:35.986Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Finding%20internet%20facing%20device%20with%20CUPS&amp;cm1k4l3nl01dnmc0phps9eirc</loc>
    <lastmod>2024-09-27T02:50:18.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20malicious%20link%20or%20email&amp;cm1jeplaj01d6mc0pojayqn09</loc>
    <lastmod>2024-09-26T14:45:58.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20Microsoft%20365%20Copilot%20Web%20Search%20Queries%20with%20DefenderXDR&amp;cm1icdafk01chmc0pmuozw00a</loc>
    <lastmod>2024-09-25T20:52:39.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInFromSuspiciousIP&amp;cm1ic1s3w01cgmc0piqzso42v</loc>
    <lastmod>2024-09-25T20:43:42.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellPossibleC2Connection&amp;cm1hmknrb01bzmc0pjvc4eyf9</loc>
    <lastmod>2024-09-25T08:50:32.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20TyposquattedEmailRecieved&amp;cm1gwuxmg01bimc0pkr90gxqs</loc>
    <lastmod>2024-09-24T20:50:42.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Nation-State%20Threat%20Actors%20with%20Custom%20KQL%20Queries&amp;cm1gk63fj01b9mc0px3scqcie</loc>
    <lastmod>2024-09-24T14:55:27.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20DLP%20Endpoint%20alert%20info&amp;cm1f4dumu01acmc0pc43frc7b</loc>
    <lastmod>2024-09-23T14:45:49.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/High-Risk%20assets%20with%20command%20line%20credentials&amp;cm1dp4l6u019fmc0ph2y6lgjl</loc>
    <lastmod>2024-09-22T14:50:57.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitoring%20restricted%20management%20administrative%20units%20abuse&amp;cm1bwvv2o018amc0pu2867ub2</loc>
    <lastmod>2024-09-21T08:52:34.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Password%20Spraying%20Detection%20in%20Active%20Directory&amp;cm19rsfow016xmc0pfzso2a4l</loc>
    <lastmod>2024-09-19T20:54:24.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignatureRingDistribution&amp;cm19rirps016wmc0plfncef7l</loc>
    <lastmod>2024-09-19T20:46:53.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20DLP%20Teams%20alert%20info&amp;cm19ren3o016vmc0p67pvlll0</loc>
    <lastmod>2024-09-19T20:43:40.786Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20DLP%20SharePoint%20alert%20info&amp;cm19rednx016umc0pw8990wq3</loc>
    <lastmod>2024-09-19T20:43:28.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20DLP%20OneDrive%20alert%20info&amp;cm19re5q4016tmc0pxdu8it4m</loc>
    <lastmod>2024-09-19T20:43:18.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Purview%20DLP%20Exchange%20alert%20info&amp;cm19rdvnj016smc0p3t2oxfdz</loc>
    <lastmod>2024-09-19T20:43:05.069Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20API%20Spray%20Attack%20on%20your%20Entra%20High%20Value%20Assets&amp;cm17zgtdf015nmc0prnl9mmb7</loc>
    <lastmod>2024-09-18T14:53:46.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20SSH%20connection%20inspections&amp;cm17mhs5s015emc0pmhp9u95j</loc>
    <lastmod>2024-09-18T08:50:36.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Pivot%20-%20ASRConfig&amp;cm16whml4014xmc0p1d84kq27</loc>
    <lastmod>2024-09-17T20:42:39.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Twill%20Typhoon%20VSCode%20Exploit&amp;cm14ro5bg013kmc0ppgte0hie</loc>
    <lastmod>2024-09-16T08:52:13.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Windows%20Downdate%20Abuse&amp;cm11wp0fc011rmc0pee84txk6</loc>
    <lastmod>2024-09-14T08:49:33.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-suspicious-certificates-in-endpoints-with-zero-keysize-and-no-signature%20algorithm&amp;cm11jpm54011imc0pavit5cdx</loc>
    <lastmod>2024-09-14T02:46:06.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20External%20Sources%20scanning%20my%20exposed%20devices&amp;cm10u3tb70111mc0pdiwvweau</loc>
    <lastmod>2024-09-13T14:49:18.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Interactive_web_login&amp;cm10tkvjh0110mc0ppth4fg8l</loc>
    <lastmod>2024-09-13T14:34:35.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Office365-Recycled-Restored&amp;cm0zrhcol010bmc0pj3gz8z69</loc>
    <lastmod>2024-09-12T20:48:05.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Office365-CustomerLockbox&amp;cm0zrh7jd010amc0pni6r3xn6</loc>
    <lastmod>2024-09-12T20:47:58.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-ExposureLevel&amp;cm0zrgoxn0109mc0poumzis4n</loc>
    <lastmod>2024-09-12T20:47:34.714Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft_September_updates&amp;cm0yc61tb00zcmc0pyzx5t6x0</loc>
    <lastmod>2024-09-11T20:51:37.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devtunnelcodetunneling&amp;cm0v4bph000xbmc0p2epkmm0k</loc>
    <lastmod>2024-09-09T14:48:46.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevtunnelRegistry&amp;cm0v4bkqi00xamc0pla79tfih</loc>
    <lastmod>2024-09-09T14:48:39.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevTunnelFileEvents&amp;cm0v4bh3i00x9mc0pzyi6mlln</loc>
    <lastmod>2024-09-09T14:48:35.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraRolesReport&amp;cm0v44a4k00x8mc0pfx4gsuro</loc>
    <lastmod>2024-09-09T14:42:59.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20Threats%20or%20network%20anomalies%20related%20to%20ICMP%20Inbound%20Connections&amp;cm0urif3s00wzmc0pwrdfee3i</loc>
    <lastmod>2024-09-09T08:50:04.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevTunnelnetworkdetection&amp;cm0urh9na00wymc0p5pu0cn24</loc>
    <lastmod>2024-09-09T08:49:10.677Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20MITRE%20ATT%26CK%20Technique%20Analysis&amp;cm0tox73f00w9mc0pd1z71dk6</loc>
    <lastmod>2024-09-08T14:49:48.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20for%20Entra%20Legacy%20TLS%20Login&amp;cm0tc1f3l00w0mc0pa1evqpc0</loc>
    <lastmod>2024-09-08T08:49:10.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20for%20Azure%20Outdated%20Security%20Protocols&amp;cm0tc1art00vzmc0pkgah6wut</loc>
    <lastmod>2024-09-08T08:49:05.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20AzureHound%20Usage&amp;cm0rwofoy00v2mc0pk4ozczc0</loc>
    <lastmod>2024-09-07T08:51:24.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20BYOVDLL%20Abuse&amp;cm0r6xovm00ulmc0p36re3lkx</loc>
    <lastmod>2024-09-06T20:50:46.306Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-EDRSensorUpdate&amp;cm0pradcp00tomc0p1s75jj1y</loc>
    <lastmod>2024-09-05T20:44:57.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/M365%20Copilot%20Plugins%20Inventory%20Analysis&amp;cm0p1tufg00t7mc0p9aopn4vm</loc>
    <lastmod>2024-09-05T08:52:16.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraGroupMembershipReport&amp;cm0obsdai00sqmc0pwge4h2pk</loc>
    <lastmod>2024-09-04T20:43:17.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UniqueActions&amp;cm0mwczhb00rtmc0puy7mwrig</loc>
    <lastmod>2024-09-03T20:43:39.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SocGhoulish&amp;cm0mw3fgj00rsmc0p388amswm</loc>
    <lastmod>2024-09-03T20:36:13.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Privilege%20User%20SSPR&amp;cm0m6xkk200rbmc0pjb2lph7e</loc>
    <lastmod>2024-09-03T08:51:49.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Non-supported%20Agent%20version%20required%20for%20the%20Contain%20User%20action%20by%20Attack%20Disruption&amp;cm0m6vt1p00ramc0pi9i31oi4</loc>
    <lastmod>2024-09-03T08:50:27.660Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identifying%20methods%20used%20to%20establish%20secure%20communication%20over%20insecure%20channels&amp;cm0k1lmec00pxmc0pi14g98at</loc>
    <lastmod>2024-09-01T20:47:02.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20EDR-killing%20Tool&amp;cm0hwgr8v00okmc0p4ahlvq8f</loc>
    <lastmod>2024-08-31T08:47:44.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Communication%20at%20risk%20due%20to%20the%20encryption%20algorithms%20(Ciphers)%20in%20use&amp;cm0feic9m00mzmc0pmclpurss</loc>
    <lastmod>2024-08-29T14:49:33.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoint-browser-extensions-with-can-turnoff-malware-protections-permissions&amp;cm0fef3z500mymc0pg0a0nfhb</loc>
    <lastmod>2024-08-29T14:47:02.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20Microsoft%20Sway%20Quishing&amp;cm0ebwb4h00m9mc0ppuuvgxk4</loc>
    <lastmod>2024-08-28T20:48:39.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NltestDiscovery&amp;cm0cw9e2q00lcmc0pgr05a5fi</loc>
    <lastmod>2024-08-27T20:43:10.081Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20BYOVD%20Scenarios&amp;cm0cjnns900l3mc0p8bssba0f</loc>
    <lastmod>2024-08-27T14:50:20.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GetsystemelevationCSmetasploit&amp;cm0cjlzxs00l2mc0piw52qvu5</loc>
    <lastmod>2024-08-27T14:49:03.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20with%20MDE%20Device%20Discovery%20and%20SeenBy%20Enrichment%20Function&amp;cm0bh0rt300kdmc0p1z2hnwj2</loc>
    <lastmod>2024-08-26T20:48:47.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RoleReport&amp;cm0bgqnnq00kcmc0pttoieyaf</loc>
    <lastmod>2024-08-26T20:40:55.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/H%F0%9D%97%BC%F0%9D%98%84%20%F0%9D%97%BA%F0%9D%97%AE%F0%9D%97%BB%F0%9D%98%86%20%F0%9D%97%96%F0%9D%97%BF%F0%9D%97%BC%F0%9D%98%84%F0%9D%97%B1%F0%9D%97%A6%F0%9D%98%81%F0%9D%97%BF%F0%9D%97%B6%F0%9D%97%B8%F0%9D%97%B2%20%F0%9D%97%B0%F0%9D%97%B9%F0%9D%97%B6%F0%9D%97%B2%F0%9D%97%BB%F0%9D%98%81%F0%9D%98%80%20%F0%9D%97%BF%F0%9D%98%82%F0%9D%97%BB%F0%9D%97%BB%F0%9D%97%B6%F0%9D%97%BB%F0%9D%97%B4%20%F0%9D%97%BC%F0%9D%97%BB%20%F0%9D%97%A0%F0%9D%97%B6%F0%9D%97%B0%F0%9D%97%BF%F0%9D%97%BC%F0%9D%98%80%F0%9D%97%BC%F0%9D%97%B3%F0%9D%98%81%20%F0%9D%97%94%F0%9D%98%87%F0%9D%98%82%F0%9D%97%BF%F0%9D%97%B2%20%F0%9D%97%B4%F0%9D%97%B9%F0%9D%97%BC%F0%9D%97%AF%F0%9D%97%AE%F0%9D%97%B9%F0%9D%97%B9%F0%9D%98%86&amp;cm0b43hk800k3mc0p5qo6egr8</loc>
    <lastmod>2024-08-26T14:46:59.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AdfindDetection&amp;cm0b41eaj00k2mc0p948prkmx</loc>
    <lastmod>2024-08-26T14:45:21.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GroupMembershipReport&amp;cm0a19n3f00jdmc0phjvsiqeu</loc>
    <lastmod>2024-08-25T20:40:01.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Enriching%20CVE%20Tables%20with%20CVE%20Mitre%20Data&amp;cm09onpbr00j4mc0ptuwj1tb2</loc>
    <lastmod>2024-08-25T14:47:02.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Peaklightinfection&amp;cm09omtfo00j3mc0pw2rdw38q</loc>
    <lastmod>2024-08-25T14:46:20.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/How%20many%20Crowdstrike%20clients%20running%20on%20Microsoft%20Azure%20globally&amp;cm08yxq8y00immc0pqdqk3kpd</loc>
    <lastmod>2024-08-25T02:47:00.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/use-exposure-management-to-identify-local-ntlm-hashes-from-sensitive-users&amp;cm06tpstg00h9mc0pxy436sww</loc>
    <lastmod>2024-08-23T14:45:19.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/use-exposure-management-to-chart-user-groups-with-local-admin-privileges&amp;cm06tporr00h8mc0pv49z70xf</loc>
    <lastmod>2024-08-23T14:45:14.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-7971%20Patch%20Prioritization&amp;cm05ed30800gbmc0pzryyh43w</loc>
    <lastmod>2024-08-22T14:47:46.038Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Infrastructure%20Vulnerability%20Exposure%20to%20Volt%20Typhoon&amp;cm051ioqw00g2mc0p2dnftvw9</loc>
    <lastmod>2024-08-22T08:48:12.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20Bad%20Reputation%20ASN%20activities&amp;cm051hk4e00g1mc0p0bu0d523</loc>
    <lastmod>2024-08-22T08:47:19.837Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20ID%20Administrative%20Role%20(AD-Sync)&amp;cm03m3o6600f4mc0pl50iwo52</loc>
    <lastmod>2024-08-21T08:48:51.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OneDriveSyncFromRareIP&amp;cm02w49rj00enmc0pfw69xbjn</loc>
    <lastmod>2024-08-20T20:41:29.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20RemoteImageLoads&amp;cm02w3ot800emmc0paaq8fx6t</loc>
    <lastmod>2024-08-20T20:41:02.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20to%20check%20Privilege%20Admin%20failing%20Microsoft%20CA%20MFA%20enforcement&amp;cm02jngq100edmc0pksmzq6qe</loc>
    <lastmod>2024-08-20T14:52:29.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Potential%20DLL%20Hijacking%20cases&amp;cm026lt3w00e4mc0pj5m7p4hj</loc>
    <lastmod>2024-08-20T08:47:17.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20analytics%20rule%20for%20Copilot%20Studio%20Bot%20creation%20detection&amp;clzwtsweh00armc0p4jh53m0m</loc>
    <lastmod>2024-08-16T14:50:02.632Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Classifying%20HTTP%20Status%20Code%20and%20detecting%20possible%20Threats&amp;clzwtrdzi00aqmc0pgr9kfenx</loc>
    <lastmod>2024-08-16T14:48:52.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UseCases_by_MITRE&amp;clzwtc1ql00apmc0p3hox6ebo</loc>
    <lastmod>2024-08-16T14:36:56.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Copilot%20Studio%20Bot%20Creation&amp;clzwgxxek00agmc0pmlrnesoi</loc>
    <lastmod>2024-08-16T08:50:02.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-38063%20CVSS%209.8%20Prioritization&amp;clzubqswa0093mc0pitz4vroo</loc>
    <lastmod>2024-08-14T20:48:59.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MFASuspicious&amp;clztz37ok008umc0pdpasn1od</loc>
    <lastmod>2024-08-14T14:54:43.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-38200%20NTLM%20Exposure%20Detection&amp;clzsjidck007xmc0p91wd19il</loc>
    <lastmod>2024-08-13T14:50:50.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potential%20False%20Positives%20related%20to%20Anomalous%20Token%20alerts&amp;clzsjhi43007wmc0p5nrqvj1g</loc>
    <lastmod>2024-08-13T14:50:09.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20UEBA%20Privilege%20Escalation%20Detection&amp;clzrtpjkw007fmc0px4pygh0b</loc>
    <lastmod>2024-08-13T02:48:35.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Power%20Pwn%20(aka%20LOLCopilot)%20Red%20Team%20Tool%20&amp;clzrgvh6o0076mc0plspoefy4</loc>
    <lastmod>2024-08-12T20:49:16.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Spear%20Phishing%20using%20Copilot%20for%20Microsoft%20365&amp;clzpohwf00061mc0plnsoh43y</loc>
    <lastmod>2024-08-11T14:47:08.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exposure%20Management%3A%20Cloud%20or%20On-Prem%20VDI%20Platform%20Blast%20Radius&amp;clzolwygf005cmc0pnx2fhu2p</loc>
    <lastmod>2024-08-10T20:47:05.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Microsoft%20Graph%20API%20Abuse&amp;clznw6ebe004vmc0p5o2o8ceh</loc>
    <lastmod>2024-08-10T08:46:36.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Privilege%20Admin%20under%20AiTM%20attack&amp;clzmtoy8r0046mc0p2o73rqvk</loc>
    <lastmod>2024-08-09T14:49:16.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SummaryOfFirstPartyServicePrincipals_withoutTenantSpecificData&amp;clzmtlwhn0045mc0pnpuf3l61</loc>
    <lastmod>2024-08-09T14:46:54.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SummaryOfFirstPartyServicePrincipals&amp;clzmtlm1t0044mc0pv3up8ut4</loc>
    <lastmod>2024-08-09T14:46:40.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20vulnerable%20device%20with%20Global%20Admin%20browser%20cookie%20credential&amp;clzlec2wf0037mc0p8jayl1mv</loc>
    <lastmod>2024-08-08T14:51:35.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RiskyExternalPrivilegedUsersWithEnrichmentOfKnownAttackPathsAndTiering&amp;clzl1b3oc002ymc0pkrfmon43</loc>
    <lastmod>2024-08-08T08:46:55.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20human-operated%20ransomware%20attacks%20that%20use%20RDP&amp;clzjyvffd0029mc0p61zlb8sr</loc>
    <lastmod>2024-08-07T14:50:58.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Attacker%20in%20the%20Middle%20Precision%20Detection&amp;clzjm4aei0020mc0p7zxghwe7</loc>
    <lastmod>2024-08-07T08:53:56.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MC847884%20-%20Check%20iOS%2016%20mobile%20outlook%20users%20due%20to%20out%20of%20support%20in%20Sep%202024&amp;clziw9xwf001jmc0ponhwhefg</loc>
    <lastmod>2024-08-06T20:50:30.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LatrodectusFileCreation&amp;clziw7yov001imc0pcjcjw8nh</loc>
    <lastmod>2024-08-06T20:48:58.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anonymous%20access%20to%20files%20by%20suspicious%20IP%20addresses&amp;clzij9o8n0019mc0pfz4wzvxc</loc>
    <lastmod>2024-08-06T14:46:22.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20LNK%20Stomping&amp;clzi6j34u0010mc0pvupiai4c</loc>
    <lastmod>2024-08-06T08:49:47.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RemoteDCOMChildProc&amp;clzhthoxw000rmc0ptkspdp6v</loc>
    <lastmod>2024-08-06T02:44:47.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Remote_Actions_By_Compromised_Account&amp;clzhgb316000imc0pqwyi8a5t</loc>
    <lastmod>2024-08-05T20:35:43.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RDP_by_IP&amp;clzhgatku000hmc0pyvyx52vz</loc>
    <lastmod>2024-08-05T20:35:31.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defender_Tampering&amp;clzhg9h3j000gmc0pekud5up6</loc>
    <lastmod>2024-08-05T20:34:28.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualize%20Entra%20Password%20Spray%20Attack%20with%20ADX%20Interactive%20Map&amp;clzh2clqu002v5ivo483dapkz</loc>
    <lastmod>2024-08-05T14:05:00.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Understanding%20Sentinel%20password%20spray%20data%20with%20Copilot%20for%20Microsoft%20365&amp;clzh2cejk002u5ivorik76lq3</loc>
    <lastmod>2024-08-05T14:04:50.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Intelligence%20Data%20from%20Sentinel%20UEBA2&amp;clzh2c7kx002t5ivo9egtvi1m</loc>
    <lastmod>2024-08-05T14:04:41.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Intelligence%20Data%20from%20Sentinel%20UEBA&amp;clzh2bufx002s5ivo002va7nw</loc>
    <lastmod>2024-08-05T14:04:24.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20Hunting%20Nation%20State%20Actors&amp;clzh2blkf002r5ivoko96fq6q</loc>
    <lastmod>2024-08-05T14:04:13.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20All-In-One%20UPN%20ThreatHunt&amp;clzh2beb0002q5ivo4m1opv8o</loc>
    <lastmod>2024-08-05T14:04:03.754Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20All-In-One%20IP%20ThreatHunt&amp;clzh2b648002p5ivo7knnqpqo</loc>
    <lastmod>2024-08-05T14:03:53.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel%20Alerts%20%26%20MITRE%20ATT%26CK%20Analysis&amp;clzh2awm5002o5ivovi5i6z3z</loc>
    <lastmod>2024-08-05T14:03:40.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Phishing%20campaigns%20leveraging%20Microsoft%20Forms&amp;clzh2aqum002n5ivosienpyd7</loc>
    <lastmod>2024-08-05T14:03:33.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Part%202%3A%20DefenderXDR%20KQL%20detection%20for%20fake%20CrowdStrike%20domain%20URL&amp;clzh2abfx002m5ivoqgocaprp</loc>
    <lastmod>2024-08-05T14:03:13.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Part%201%3A%20Custom%20DefenderXDR%20KQL%20detection%20for%20fake%20CrowdStrike%20email%20domain&amp;clzh2a6o2002l5ivokimll7cp</loc>
    <lastmod>2024-08-05T14:03:07.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20Threat%20Actor%20Group%20Signature&amp;clzh29zvj002k5ivo52a378nh</loc>
    <lastmod>2024-08-05T14:02:58.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Nation%20State%20Actors%20via%20Microsoft%20Graph&amp;clzh29tt4002j5ivobfwy8o11</loc>
    <lastmod>2024-08-05T14:02:50.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NEW%20Real-time%20Anomalous%20Token%20Detection&amp;clzh29mrw002i5ivok37w2rwu</loc>
    <lastmod>2024-08-05T14:02:41.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NEW%20Microsoft%20Graph%20API%20Identity%20Protection%20KQL%20Detection&amp;clzh29gjd002h5ivo66yui8cq</loc>
    <lastmod>2024-08-05T14:02:33.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Entra%20Identity%20Attack%20Threat%20Detection&amp;clzh29ax6002g5ivodxz0djel</loc>
    <lastmod>2024-08-05T14:02:26.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20FIDO2%20Registration%20Threat%20Detection&amp;clzh295ss002f5ivoigt4pv13</loc>
    <lastmod>2024-08-05T14:02:19.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Leveraging%20Sentinel%20UEBA%20to%20safeguard%20against%20OpenSSH%20vulnerability%20exploits&amp;clzh2908g002e5ivo7936z0xz</loc>
    <lastmod>2024-08-05T14:02:12.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20to%20check%20Azure%20API%20spray%20attacks&amp;clzh28tpa002d5ivodpvs5rbx</loc>
    <lastmod>2024-08-05T14:02:03.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20for%20detecting%20potential%20hashtag%23RegreSSHion%20abuse&amp;clzh28iz5002c5ivo6h6rsrt6</loc>
    <lastmod>2024-08-05T14:01:49.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20URL%20Protection%20Report&amp;clzh28c6b002b5ivo9nnkw2xi</loc>
    <lastmod>2024-08-05T14:01:41.016Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20Sniper%20for%20Compromised%20Account%20(Sentinel%20UEBA)%20&amp;clzh27z2l002a5ivo5czwdonh</loc>
    <lastmod>2024-08-05T14:01:24.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Insider%20Threat%20-%20Monitor%20sensitive%20bulk%20download%20data%20email%20to%20external%20&amp;clzh27tbv00295ivo6xowcq5v</loc>
    <lastmod>2024-08-05T14:01:16.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity%20Blast%20Radius%202&amp;clzh27jpl00285ivoejcfv8zh</loc>
    <lastmod>2024-08-05T14:01:04.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphRunner%20Recon%20Detection%20%26%20Response&amp;clzh27eme00275ivox9verar6</loc>
    <lastmod>2024-08-05T14:00:57.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Risk%20Events%20%26%20MITRE%20ATT%26CK%20Analysis&amp;clzh275n400265ivovgknqk2o</loc>
    <lastmod>2024-08-05T14:00:45.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Passkey%20Addition%20Threat%20Detection&amp;clzh26pe000255ivov27qu13b</loc>
    <lastmod>2024-08-05T14:00:24.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20TeamsPhisher%20attack%20with%20Azure%20Sentinel&amp;clzh26gum00245ivogk7moqwj</loc>
    <lastmod>2024-08-05T14:00:13.773Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20Nation%20State%20Actors%20%40%20Near%20Realtime&amp;clzh267lp00235ivo1xgmmzxz</loc>
    <lastmod>2024-08-05T14:00:01.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20High%20Risk%20Passkey%20Users&amp;clzh264oh00225ivoryy3cs1j</loc>
    <lastmod>2024-08-05T13:59:58.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20privilege%20escalation%20to%20Global%20Admin%20role%20via%20compromised%20service%20principal&amp;clzh25z0h00215ivo4lauy57v</loc>
    <lastmod>2024-08-05T13:59:50.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defending%20malicious%20MS%20graph%20activity%20with%20MS%20Sentinel%20Threat%20Intelligence&amp;clzh25trl00205ivo7auu61bm</loc>
    <lastmod>2024-08-05T13:59:43.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defending%20Cyber%20Threats%20Leveraging%20Microsoft%20Graph%20API%20&amp;clzh25nsa001z5ivof06hrds6</loc>
    <lastmod>2024-08-05T13:59:36.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DISCOVERY%3A%20Obsolete%20device%20connecting%20to%20Entra&amp;clzh25hrt001y5ivo019z6bme</loc>
    <lastmod>2024-08-05T13:59:28.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Custom%20DefenderXDR%20KQL%20detection%20for%20fake%20CrowdStrike%20email%20domain%20using%20Regex&amp;clzh25cso001x5ivoqo8m8r0x</loc>
    <lastmod>2024-08-05T13:59:21.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Conditional%20Access%20Report&amp;clzh257bs001w5ivo12hn7ugb</loc>
    <lastmod>2024-08-05T13:59:14.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20cloud%20account%20takeover&amp;clzh252gu001v5ivo6j1njhqz</loc>
    <lastmod>2024-08-05T13:59:08.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20cloud%20account%20takeover%20(ATO)%20Reconnaissance%20Detection&amp;clzh24xgg001u5ivodz1v7gkc</loc>
    <lastmod>2024-08-05T13:59:01.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20CLI%20Spray%20-%20ASN%2053667&amp;clzh24qiw001t5ivoa5oc0wzn</loc>
    <lastmod>2024-08-05T13:58:52.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analyzing%20Malicious%20Microsoft%20Graph%20API%20Rate%20Limit%20Count&amp;clzh24li8001s5ivo6e8f6up7</loc>
    <lastmod>2024-08-05T13:58:46.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Add%20Passkey%20device-bound%20MS%20Authenticator%20Windows%20Hello%20detection&amp;clzh24d33001r5ivowd2kswjq</loc>
    <lastmod>2024-08-05T13:58:35.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vulnerability%20Profile%3A%20CVE-2024-30040%20(Zero-day)&amp;clzh2477s001q5ivo2e4garfg</loc>
    <lastmod>2024-08-05T13:58:27.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UNIT42%20-%20Abuse%20Microsoft%20OneNote%20files%20on%20the%20rise&amp;clzh240lu001p5ivomjmme5s4</loc>
    <lastmod>2024-08-05T13:58:19.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Tracking%20The%20Most%20Dangerous%20Entra%20Admin%20Role&amp;clzh23v1l001o5ivo9kdbvlyz</loc>
    <lastmod>2024-08-05T13:58:12.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Threat%20hunting%20voice%20phishing%20for%20Teams&amp;clzh23pfa001n5ivoy8f3uckt</loc>
    <lastmod>2024-08-05T13:58:04.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/The%20Hunt%20for%20QR%20Phisher&amp;clzh23hat001m5ivoi762zhhz</loc>
    <lastmod>2024-08-05T13:57:54.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Seashell%20Blizzard%20(IRIDIUM)%20-%20PWS%3AWin64-HighCount&amp;clzh236q4001l5ivoqn5t4xa8</loc>
    <lastmod>2024-08-05T13:57:40.683Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Remote%20code%20execution%20exploit%20chain%20in%20OpenVPN&amp;clzh231mc001k5ivo8kfqfr5n</loc>
    <lastmod>2024-08-05T13:57:34.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Perimeter%20Defense%20-%20Attack%20Surface%20Reduction&amp;clzh22wk1001j5ivokba02jl7</loc>
    <lastmod>2024-08-05T13:57:27.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/New%20Information%20Stealer%20-%20SamsStealer%20(By%20CYFIRMA)&amp;clzh22jbz001i5ivobdzcovqp</loc>
    <lastmod>2024-08-05T13:57:10.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Near%20real-time%20(NRT)%20custom%20DefenderXDR%20detection%20%26%20isolation%20for%20Windows%20Whatsapp%20security%20risk&amp;clzh22emp001h5ivo7c8kfz24</loc>
    <lastmod>2024-08-05T13:57:04.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multi-Cloud%20DefenderXDR%20KQL%20Threat%20Detection&amp;clzh229rp001g5ivo5gxy7sov</loc>
    <lastmod>2024-08-05T13:56:57.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monthly%20Report%20Entra%20Eligible%20Role%20Activation&amp;clzh2212d001f5ivoj9meqkvd</loc>
    <lastmod>2024-08-05T13:56:46.690Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Defender%20Advanced%20Hunting%20Copilot%20Activities&amp;clzh21w0r001e5ivo1ajxg49n</loc>
    <lastmod>2024-08-05T13:56:40.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MailItemsAccessed%20Defense&amp;clzh21mae001d5ivozoqhorwt</loc>
    <lastmod>2024-08-05T13:56:27.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MS%20Teams%20DLP%20Playbook&amp;clzh21ike001c5ivot40ab9wn</loc>
    <lastmod>2024-08-05T13:56:22.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%3A%20Detecting%20Quick%20Assist%20Usage&amp;clzh21f3c001b5ivo0i3o5gqx</loc>
    <lastmod>2024-08-05T13:56:18.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20KQL%20to%20detect%20UAC%20bypass%20of%20Fickle%20Stealer&amp;clzh210oq001a5ivolpb5k4dd</loc>
    <lastmod>2024-08-05T13:55:59.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20KQL%20to%20detect%20TA571%20socialengineering%20abuse&amp;clzh20v9p00195ivonh8cbj4x</loc>
    <lastmod>2024-08-05T13:55:52.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LockBit%20Black%20Ransomware&amp;clzh20r2y00185ivousn3v7su</loc>
    <lastmod>2024-08-05T13:55:47.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20to%20detect%20new%20chromium%20browser%20extension%20installation%20on%20MDE%20endpoints%20by%20Emerald%20Sleet%20(APT43)&amp;clzh20m5400175ivothr8esrt</loc>
    <lastmod>2024-08-05T13:55:40.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20to%20detect%20if%20Polyfill%20malicious%20payload%20was%20loaded&amp;clzh20dl300165ivoyc6jnknd</loc>
    <lastmod>2024-08-05T13:55:29.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQL%20query%20to%20oversee%20the%20privileged%20OAuth%20grants%20allocated%20to%20the%20Microsoft%20Graph%20Command%20Line%20Tools%20OAuth%20App&amp;clzh208lz00155ivoz04xxdiz</loc>
    <lastmod>2024-08-05T13:55:23.158Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Insider%20Threat%20Monitoring%20-%20Exfiltrate%20data%20via%20Link%20to%20Windows%20app&amp;clzh200nc00145ivobu89860c</loc>
    <lastmod>2024-08-05T13:55:12.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity%20Blast%20Radius&amp;clzh1zsif00135ivoo1vra5dg</loc>
    <lastmod>2024-08-05T13:55:02.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Hunting%20AI%20Recall%20on%20Windows%2011%2024H2&amp;clzh1zm4000125ivoieusx69q</loc>
    <lastmod>2024-08-05T13:54:54.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/High%20Precision%20KQL%20to%20detect%20MuddyWater%20BugSleep%20Backdoor&amp;clzh1zhfq00115ivo1bapr7vb</loc>
    <lastmod>2024-08-05T13:54:47.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Git%20Critical%20Vulnerability%20CVE-2024-32002&amp;clzh1z41100105ivojv3fit3d</loc>
    <lastmod>2024-08-05T13:54:30.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exposure%20Management%20-%20Slim&apos;s%20Metric%20(MaxCVSS-DAW)&amp;clzh1yyiq000z5ivo12arbt4l</loc>
    <lastmod>2024-08-05T13:54:23.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Exposure%20Management%20%2B%20Defender%20for%20Office%20365&amp;clzh1ytfl000y5ivok6wj9y2i</loc>
    <lastmod>2024-08-05T13:54:16.831Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Entra%20Admin%20Roles%20Query&amp;clzh1ylpo000x5ivoluiqd8mr</loc>
    <lastmod>2024-08-05T13:54:06.817Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EchoSpoofing&amp;clzh1y878000w5ivocowcgwe6</loc>
    <lastmod>2024-08-05T13:53:49.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20or%20VM%20with%20critical%20CVSS%20and%20ExploitIsVerified&amp;clzh1y2jn000v5ivofbl6ogz5</loc>
    <lastmod>2024-08-05T13:53:41.975Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detecting%20GOLDEN%20SAML%20Attack&amp;clzh1xvv1000u5ivoznl7ohed</loc>
    <lastmod>2024-08-05T13:53:33.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20threat%20actor%20abuse%20CloudFlare%20tunnels%20to%20deliver%20RATS&amp;clzh1xqyh000t5ivos20q61vk</loc>
    <lastmod>2024-08-05T13:53:26.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20privilege%20escalation%20to%20The%20Most%20Dangerous%20Entra%20Admin%20Role%20via%20compromised%20service%20principal&amp;clzh1xl92000s5ivooji95ce1</loc>
    <lastmod>2024-08-05T13:53:19.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Copilot%20Plugin%20Installation&amp;clzh1xeqz000r5ivo2bn1wg3l</loc>
    <lastmod>2024-08-05T13:53:11.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Copilot%20Exfiltration%20arises%20from%20AiTM%20Token%20Theft&amp;clzh1x9wh000q5ivo3t1bddt0</loc>
    <lastmod>2024-08-05T13:53:04.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20CVE-2024-31497&amp;clzh1x21q000p5ivofg4ewo2j</loc>
    <lastmod>2024-08-05T13:52:54.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20%26%20mitigate%20potential%20Specula%20Exploitation&amp;clzh1wxrp000o5ivobqo19ck8</loc>
    <lastmod>2024-08-05T13:52:49.106Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defending%20against%20dot%20zip%20domain%20phishing%20attack&amp;clzh1wo95000n5ivoi14poixr</loc>
    <lastmod>2024-08-05T13:52:36.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defending%20against%20Windows%20Internet%20Shortcut%20Files%20Security%20Feature%20Bypass%20Vulnerability%20(CVE-2024-21412)&amp;clzh1wfbg000m5ivo1cvv8k6u</loc>
    <lastmod>2024-08-05T13:52:25.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Defending%20against%20CVE-2024-21413%20Outlook%20MonikerLink%20Bug%20Abuse&amp;clzh1w963000l5ivojokknhtp</loc>
    <lastmod>2024-08-05T13:52:17.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20exposure%20management%20for%20CVE-2024-38021&amp;clzh1w040000k5ivoqc0mzbse</loc>
    <lastmod>2024-08-05T13:52:05.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Exposure%20Management%20for%20hashtag%23RegreSSHion&amp;clzh1vp67000j5ivono8q06tr</loc>
    <lastmod>2024-08-05T13:51:51.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Exposure%20Management%20for%20CVE-2024-3094&amp;clzh1vkfu000i5ivo8umd2y87</loc>
    <lastmod>2024-08-05T13:51:45.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Advanced%20Hunting%20All-In-One%20UPN%20Search&amp;clzh1vec2000h5ivocvc32kjz</loc>
    <lastmod>2024-08-05T13:51:37.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderXDR%20Advanced%20Hunting%20All-In-One%20IP%20Search&amp;clzh1v5v1000g5ivonp1fy39x</loc>
    <lastmod>2024-08-05T13:51:26.307Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data%20Exfiltration%20via%20Microsoft%20Teams&amp;clzh1uw91000f5ivo9dgmc7wc</loc>
    <lastmod>2024-08-05T13:51:13.861Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20Monitor%20for%20Critical%20Assets&amp;clzh1up9i000e5ivoyn3igvva</loc>
    <lastmod>2024-08-05T13:51:04.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20Identities%20Privilege%20Escalation%20on%20Entra%20Service%20Principal&amp;clzh1uisu000d5ivofccuvm1a</loc>
    <lastmod>2024-08-05T13:50:56.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Critical%20Identities%20OAuth%20Grant&amp;clzh1ubee000c5ivo4ofb8sla</loc>
    <lastmod>2024-08-05T13:50:46.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cobalt%20Strike%20HTTPS%20beaconing%20over%20Microsoft%20Graph%20API&amp;clzh1u4ej000b5ivogt74a955</loc>
    <lastmod>2024-08-05T13:50:37.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudApp%20Privilege%20OAuth%20Grant&amp;clzh1tya9000a5ivoo9v2n9vc</loc>
    <lastmod>2024-08-05T13:50:29.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-38112%20ZERO-DAY%20TRICKS%20IN%20dot%20URL%20TO%20LURE%20VICTIMS&amp;clzh1ttg200095ivobz4ezo7i</loc>
    <lastmod>2024-08-05T13:50:23.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-3094%20with%20CVSS%20Score%2010&amp;clzh1tnzc00085ivoirhj38vb</loc>
    <lastmod>2024-08-05T13:50:16.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-29510%20Ghostscript%20library%20RCE%20bug%20Exploited&amp;clzh1ticx00075ivonuoqcfgb</loc>
    <lastmod>2024-08-05T13:50:09.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-26234%20and%20CVE-2024-29988&amp;clzh1tcr800065ivo40vs1n3b</loc>
    <lastmod>2024-08-05T13:50:01.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ATP%20Detection%20for%20Critical%20Identities&amp;clzh1t4s700055ivovjvlfyr6</loc>
    <lastmod>2024-08-05T13:49:51.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/regreSSHion%20-%20Remote%20Unauthenticated%20Code%20Execution%20Vulnerability%20in%20OpenSSH%20server&amp;clzh1syur00045ivo1phiy5ys</loc>
    <lastmod>2024-08-05T13:49:43.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Azure%20API%20Secrets%20Extraction&amp;clzh1spa100035ivomhptj9kd</loc>
    <lastmod>2024-08-05T13:49:31.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Storage%20Blob%20-%20Misconfiguration%20Check&amp;clzh1sitc00025ivocekk50x7</loc>
    <lastmod>2024-08-05T13:49:23.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20Graph%20Explorer%20-%20KQL%20Change%20Analysis&amp;clzh1sd8800015ivoehin96tp</loc>
    <lastmod>2024-08-05T13:49:15.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Cloud%20Security%20Monitoring&amp;clzh1s6kt00005ivorlovkc3s</loc>
    <lastmod>2024-08-05T13:49:07.274Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Unauthorized%20actor%20has%20been%20added%20Federated%20Credential%20on%20User-Assigned%20Managed%20Identity&amp;clzcl6e3u004tmc0qgjgkbj1z</loc>
    <lastmod>2024-08-02T10:53:11.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MS_Copilots&amp;clzbi621w0044mc0q4ixoi886</loc>
    <lastmod>2024-08-01T16:41:11.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/exposure-management-browser-cookies-with-credentials-of-privileged-users&amp;clzb5mybx003vmc0qqjpq16d1</loc>
    <lastmod>2024-08-01T10:50:24.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DirectoryRolesWithDetails&amp;clz8nqwsj002amc0qu2p0dzkh</loc>
    <lastmod>2024-07-30T16:54:03.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-37085-suspicious-creation-of-esx-admins-group&amp;clz8npo1j0029mc0q2eew9vnq</loc>
    <lastmod>2024-07-30T16:53:05.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-37085-suspicious-creation-of-esx-admins-group-through-securityevent&amp;clz8npghq0028mc0qc4m0l2r4</loc>
    <lastmod>2024-07-30T16:52:56.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/non-familiar%20DHCPDomains%20configured%20in%20our%20devices&amp;clz5f9c5500025ie89yr29fqj</loc>
    <lastmod>2024-07-28T10:33:08.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sign-in%20Attempts%20from%20multiple%20countries&amp;clz5f98a800015ie8y9fn342z</loc>
    <lastmod>2024-07-28T10:33:03.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20ISP&apos;s&amp;clz5f91ny00005ie8t0sti8ck</loc>
    <lastmod>2024-07-28T10:32:54.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/same%20infected%20files%20detected%20in%20multiple%20devices&amp;clz5f8nsz00015iogr9nvjxnp</loc>
    <lastmod>2024-07-28T10:32:36.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices%20with%20external%20RDP%20connections&amp;clz5f8l8700005iogeybcfwfw</loc>
    <lastmod>2024-07-28T10:32:33.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SetThreadContextRemoteApiCallQuery&amp;clz5eye3z00055ii0e5oyzcfi</loc>
    <lastmod>2024-07-28T10:24:37.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/QueueUserApcRemoteApiCallDetectionRule&amp;clz5eyagb00045ii05jwg9m8a</loc>
    <lastmod>2024-07-28T10:24:33.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NtMapViewOfSectionDetectionRule&amp;clz5ey5nq00035ii0903ws6tf</loc>
    <lastmod>2024-07-28T10:24:26.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GetAsyncKeyStateApiCallQuery&amp;clz5ey3bp00025ii0oxua1hdv</loc>
    <lastmod>2024-07-28T10:24:23.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ectprofilesuspiciousscripts&amp;clz5exwaw00015ii0z2ittqcc</loc>
    <lastmod>2024-07-28T10:24:14.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TripleCrosseBPFRootkit&amp;clz5exsh700005ii0dx0b5y5n</loc>
    <lastmod>2024-07-28T10:24:09.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SudoersFileEnumeration&amp;clz5evrun00185it4b75904wj</loc>
    <lastmod>2024-07-28T10:22:35.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sudoers.dFileCreation&amp;clz5evo7y00165it4q20ey2yh</loc>
    <lastmod>2024-07-28T10:22:30.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ShadowPasswdcopytosuspiciouslocation&amp;clz5evj0o00145it491w6n7mw</loc>
    <lastmod>2024-07-28T10:22:24.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ShadowFileModified&amp;clz5eveic00125it4lvz9r8mk</loc>
    <lastmod>2024-07-28T10:22:18.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PtraceDetected&amp;clz5evand00105it4kc3xhbu6</loc>
    <lastmod>2024-07-28T10:22:13.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linuxwebshell&amp;clz5ev756000y5it4ctr629xy</loc>
    <lastmod>2024-07-28T10:22:08.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Getcapdetection&amp;clz5ev25k000w5it4n3ijvx2y</loc>
    <lastmod>2024-07-28T10:22:02.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DoasConfFileCreation&amp;clz5euzec000u5it4oydk1vde</loc>
    <lastmod>2024-07-28T10:21:58.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ChattrImmutableRemoval&amp;clz5euvth000s5it4gzip5b00</loc>
    <lastmod>2024-07-28T10:21:54.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Base64Shebang&amp;clz5eus84000q5it4d6ewk6lg</loc>
    <lastmod>2024-07-28T10:21:49.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BPFKprobe&amp;clz5eunfu000o5it4n8kmrv1b</loc>
    <lastmod>2024-07-28T10:21:43.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/rnpkeysDllHijack&amp;clz5eufee000m5it4gv68kzto</loc>
    <lastmod>2024-07-28T10:21:32.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrWebShellOnServerAuditedQuery&amp;clz5eu7s3000k5it4rmdvyymc</loc>
    <lastmod>2024-07-28T10:21:23.041Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrVulnerableSignedDriverAuditedQuery&amp;clz5eu47l000i5it4xvr2w7vm</loc>
    <lastmod>2024-07-28T10:21:18.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrUntrustedUsbProcessAuditedDetectionRule&amp;clz5eu0ib000g5it4pk8cgb7p</loc>
    <lastmod>2024-07-28T10:21:13.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrUntrustedExecutableAuditedQuery&amp;clz5etxrs000e5it4ag9dz94x</loc>
    <lastmod>2024-07-28T10:21:10.071Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrPsexecWmiChildProcessAuditedQuery&amp;clz5etsiy000c5it4mr96phss</loc>
    <lastmod>2024-07-28T10:21:03.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrOfficeProcessInjectionAuditedQuery&amp;clz5etobd000a5it4c10t6fcv</loc>
    <lastmod>2024-07-28T10:20:57.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrOfficeMacroWin32ApiCallsAuditedDetecitonRule&amp;clz5etknm00085it4vsva8ej7</loc>
    <lastmod>2024-07-28T10:20:53.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrOfficeChildProcessAuditedQuery&amp;clz5ethrp00065it4n48hcteo</loc>
    <lastmod>2024-07-28T10:20:49.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrLsassCredentialTheftAuditedQuery&amp;clz5etdw100045it4g4u4glw9</loc>
    <lastmod>2024-07-28T10:20:44.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrExecutableEmailContentAuditedDetectionRule&amp;clz5et8xx00025it4uro8xica</loc>
    <lastmod>2024-07-28T10:20:37.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrAdobeReaderChildProcessAuditedDetectionRule&amp;clz5et5p000005it46mp6r3i6</loc>
    <lastmod>2024-07-28T10:20:33.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RegSamDumping&amp;clz1cl43t000pmc0pm5ig0m0i</loc>
    <lastmod>2024-07-25T14:07:14.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TIMapQueryGenerator&amp;clz0z80dw000gmc0pp2k7kv6t</loc>
    <lastmod>2024-07-25T07:53:08.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WscriptInternetConnection&amp;clz0ybmsa002c5iog6u15tj0p</loc>
    <lastmod>2024-07-25T07:27:57.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SmashjackerAppinitDLLmodifcation&amp;clz0ybj7y002a5iogwzfe62m2</loc>
    <lastmod>2024-07-25T07:27:52.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecretsdumpExecution&amp;clz0ybg6g00285iogp9fpwjlu</loc>
    <lastmod>2024-07-25T07:27:48.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WMIEventConsumer&amp;clz0ybb1c00265iogu3uihqwo</loc>
    <lastmod>2024-07-25T07:27:42.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServiceCreationRATools&amp;clz0yb6dz00245iog5lu9omnn</loc>
    <lastmod>2024-07-25T07:27:36.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServiceCreationIDE&amp;clz0yb1lq00225iog7k2bvmey</loc>
    <lastmod>2024-07-25T07:27:30.013Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServiceCreation&amp;clz0yay7n00205iogal3zro2m</loc>
    <lastmod>2024-07-25T07:27:25.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/InternetFacingDevices&amp;clz0yatxq001y5iogmp1gn9bs</loc>
    <lastmod>2024-07-25T07:27:20.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SQlite3TCC&amp;clz0yape6001w5iogjivqdkvk</loc>
    <lastmod>2024-07-25T07:27:14.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PasswordStores&amp;clz0yam7y001u5iogtihryepp</loc>
    <lastmod>2024-07-25T07:27:10.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NetworkSetupProxy&amp;clz0yahjh001s5iogug0kjblx</loc>
    <lastmod>2024-07-25T07:27:04.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CredentialAccessBuiltin&amp;clz0yadl3001q5iog3vm93mt7</loc>
    <lastmod>2024-07-25T07:26:58.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousSQLChildren&amp;clz0yaagu001o5iogr65j4qh6</loc>
    <lastmod>2024-07-25T07:26:54.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ISOIMGMount&amp;clz0ya4uy001m5iogj9fkchec</loc>
    <lastmod>2024-07-25T07:26:47.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousMSIExecRRobin&amp;clz0ya29l001k5iogytleoerx</loc>
    <lastmod>2024-07-25T07:26:44.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SimonThatamC2Putty&amp;clz0y9yhk001i5iogqqc1lz3f</loc>
    <lastmod>2024-07-25T07:26:39.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RemoteAdminCerts&amp;clz0y9ubd001g5iogycgmk3kq</loc>
    <lastmod>2024-07-25T07:26:33.912Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FreeSSLProviders&amp;clz0y9opc001e5iogp9teyhlw</loc>
    <lastmod>2024-07-25T07:26:26.640Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExportMailbox&amp;clz0y9k5b001c5iogyhbscoxm</loc>
    <lastmod>2024-07-25T07:26:20.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ServinceInstall&amp;clz0y9glu001a5iogqznnvdff</loc>
    <lastmod>2024-07-25T07:26:16.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NamedPipeDetection&amp;clz0y9cro00185iogvgl9ik40</loc>
    <lastmod>2024-07-25T07:26:11.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WebDavTempFiles&amp;clz0y989300165iog01e9jsdr</loc>
    <lastmod>2024-07-25T07:26:05.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WMISBMExec&amp;clz0y93pg00145iog05dnqbqe</loc>
    <lastmod>2024-07-25T07:25:59.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousPDQDeployRunnerChild&amp;clz0y90od00125iog3k97n2kx</loc>
    <lastmod>2024-07-25T07:25:55.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousMSC&amp;clz0y8vgp00105ioghrxnuvzb</loc>
    <lastmod>2024-07-25T07:25:48.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowershellV2Downgrade&amp;clz0y8q3d000y5iog99aht5ka</loc>
    <lastmod>2024-07-25T07:25:41.785Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowershellDLLexecutions&amp;clz0y8l41000w5iogo7m1vgo5</loc>
    <lastmod>2024-07-25T07:25:35.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PSexecNamedPipe&amp;clz0y8ho2000u5iogstmlk6hk</loc>
    <lastmod>2024-07-25T07:25:30.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeSmartScreen&amp;clz0y8czb000s5iogh3xc7mby</loc>
    <lastmod>2024-07-25T07:25:24.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MusciFolderExecution&amp;clz0y871t000q5iogheb5abjj</loc>
    <lastmod>2024-07-25T07:25:17.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MaliciousNamedPipes&amp;clz0y829o000o5iogxzimanmt</loc>
    <lastmod>2024-07-25T07:25:10.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MSHTAExecutions&amp;clz0y7x6z000m5iogcg50ziqq</loc>
    <lastmod>2024-07-25T07:25:04.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DismLinuxSubsystem&amp;clz0y7t9p000k5iog43431kdl</loc>
    <lastmod>2024-07-25T07:24:59.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DiscordDriveby&amp;clz0y7qdv000j5iogc8hl1x1y</loc>
    <lastmod>2024-07-25T07:24:55.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RundllSuspicious&amp;clz0y7mbn000h5ioghcqgvcnv</loc>
    <lastmod>2024-07-25T07:24:50.233Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rundllwithoutcommandline&amp;clz0y7i05000f5iogrcnogsyq</loc>
    <lastmod>2024-07-25T07:24:44.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderExclusion&amp;clz0y7ebt000e5iogt7lqmsft</loc>
    <lastmod>2024-07-25T07:24:39.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CoralRaiderMSHTAPowershell&amp;clz0y75qi000c5ioge9mixsrx</loc>
    <lastmod>2024-07-25T07:24:28.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GoSimpleTunnel&amp;clz0y6xry000a5iog1rqi7ofz</loc>
    <lastmod>2024-07-25T07:24:18.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FreeSSL&amp;clz0y6t4200085iogmp3vkicp</loc>
    <lastmod>2024-07-25T07:24:12.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CertReq&amp;clz0y6p3h00065iogmlo1lltf</loc>
    <lastmod>2024-07-25T07:24:07.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CSSacricialProcesses&amp;clz0y6m4m00045iogo0bhuoj6</loc>
    <lastmod>2024-07-25T07:24:03.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/C2IntelFeedsdomain&amp;clz0y6hoy00025iog80k8i0mk</loc>
    <lastmod>2024-07-25T07:23:57.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/C2IntelFeedsIPs&amp;clz0y6d1200005iogcyfxyis5</loc>
    <lastmod>2024-07-25T07:23:51.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ClientIP%20malfunction&amp;clyyi8nc301agmc0q8un82tiy</loc>
    <lastmod>2024-07-23T14:22:12.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/crowdstrike-suspicious-domains&amp;clytv61js017jmc0qez0vovmr</loc>
    <lastmod>2024-07-20T08:25:14.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20Kerberos%20authentication%20ticket%20(TGT)&amp;clyqabast015amc0q5khgb48j</loc>
    <lastmod>2024-07-17T20:18:09.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ManagedIdentityAssignmentsToResource&amp;clyov5czj014dmc0qg8a0dx3q</loc>
    <lastmod>2024-07-16T20:25:51.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20Email%20-%20PostDeliveryEvents&amp;clyov0r9s014cmc0qbc9ovqa5</loc>
    <lastmod>2024-07-16T20:22:17.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/alerts-related-to-deception-in-microsoft-defender-xdr&amp;clyjv5g910117mc0qwwx9szrx</loc>
    <lastmod>2024-07-13T08:27:05.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CryptoMiningDetection&amp;clyfkv3xv00yimc0qpggs4hdy</loc>
    <lastmod>2024-07-10T08:28:01.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XclipExecutions&amp;clyeibsfd00xtmc0qfeai96bj</loc>
    <lastmod>2024-07-09T14:29:15.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ShadowFileModified&amp;clybagffv00vsmc0q2zx1d7bl</loc>
    <lastmod>2024-07-07T08:25:36.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-6387-regresshion-identify-affected-internet-facing-endpoints&amp;cly7cybs800tbmc0qp5y3tqzt</loc>
    <lastmod>2024-07-04T14:24:25.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-6387-regresshion-identify-affected-endpoints&amp;cly7cy8cu00tamc0qpywghyau</loc>
    <lastmod>2024-07-04T14:24:21.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Multiple%20device%20names%20from%20IP%20address&amp;cly6a74bj00slmc0q6avhak2e</loc>
    <lastmod>2024-07-03T20:19:30.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20network%20share%20access&amp;cly4hvmta00rgmc0qe0njdadf</loc>
    <lastmod>2024-07-02T14:18:59.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unusual%20IPC%20share%20access&amp;cly4hvhih00rfmc0qblwa6x6b</loc>
    <lastmod>2024-07-02T14:18:52.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Activity_Increase_by_date&amp;cly32cos000qimc0qqtgcs0b0</loc>
    <lastmod>2024-07-01T14:16:35.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20JA3Blacklist&amp;clxzuugv400ohmc0q0fpsnjs8</loc>
    <lastmod>2024-06-29T08:23:09.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MailItemsAccessed&amp;clxxpnt3900n6mc0qyows3iz0</loc>
    <lastmod>2024-06-27T20:22:28.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceRegistryEvents-Unexpected%20Network%20Provider&amp;clxxcojv000mxmc0qw6mifcqf</loc>
    <lastmod>2024-06-27T14:19:07.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExposureManagement%20-%20LateralMovementPaths&amp;clxwzwxlt00momc0qmsgk2a00</loc>
    <lastmod>2024-06-27T08:21:43.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExposureManagement%20-%20DeviceActivities&amp;clxvkjq8w00lrmc0qw898ejaj</loc>
    <lastmod>2024-06-26T08:23:47.359Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExposureManagement%20-%20CloudPermissionsUser&amp;clxuurfpg00lamc0qfzmk6que</loc>
    <lastmod>2024-06-25T20:21:56.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WSL&amp;clxui0l4o00l1mc0qjh04illp</loc>
    <lastmod>2024-06-25T14:25:08.855Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-SSL%20connection%20with%20suspicious%20JA3%20fingerprint&amp;clxuhuja300l0mc0qd38s09ea</loc>
    <lastmod>2024-06-25T14:20:26.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MaliciousJA3Fingerprint&amp;clxu59ft400krmc0qmwgegigu</loc>
    <lastmod>2024-06-25T08:28:06.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-QRCode&amp;clxtsbsti00kimc0q0frr67he</loc>
    <lastmod>2024-06-25T02:26:02.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WDAC&amp;clxtsbm5g00khmc0q0sje4hat</loc>
    <lastmod>2024-06-25T02:25:53.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows%2011%20-%20Missing%20Security%20Updates&amp;clxtsbixq00kgmc0q5kculuc7</loc>
    <lastmod>2024-06-25T02:25:49.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DFC-CloudAuditEvents&amp;clxts9vac00kfmc0qkp642kp0</loc>
    <lastmod>2024-06-25T02:24:31.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-FailedLogons&amp;clxts9nbq00kemc0q0fenhkik</loc>
    <lastmod>2024-06-25T02:24:21.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/suspicious-reconnaissance-activity-through-wsl&amp;clxtfgloh00k5mc0q9z0q891r</loc>
    <lastmod>2024-06-24T20:25:50.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/suspicious-execution-using-wsl&amp;clxtfgio600k4mc0qaxtdwwbu</loc>
    <lastmod>2024-06-24T20:25:47.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/suspicious-creation-of-files-in-etc-for-persistance-in-wsl&amp;clxtfgg3f00k3mc0qd8uj5dli</loc>
    <lastmod>2024-06-24T20:25:43.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-E5SecurityBenefit&amp;clxtfexnu00k2mc0qx1ph7hlm</loc>
    <lastmod>2024-06-24T20:24:33.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-EntraSyntheticDevice&amp;clxtfek4e00k1mc0qiyzlbfkd</loc>
    <lastmod>2024-06-24T20:24:15.709Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceIsolationstate&amp;clxtfecc000k0mc0qx1979e04</loc>
    <lastmod>2024-06-24T20:24:05.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudResourceDeletion&amp;clxof9zrf00gvmc0q25gn4mhi</loc>
    <lastmod>2024-06-21T08:21:51.818Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MostPermissiveEntities&amp;clxmzw5t800fymc0q3xiv8vey</loc>
    <lastmod>2024-06-20T08:23:26.059Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RBACChanges&amp;clxlkh10u00f1mc0qossccdn6</loc>
    <lastmod>2024-06-19T08:23:59.597Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Audit&amp;clxjfbhav00domc0qbpeyn2b5</loc>
    <lastmod>2024-06-17T20:24:10.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AutomationAccount-RunbookStatus&amp;clxjfb6dh00dnmc0q6b37mo31</loc>
    <lastmod>2024-06-17T20:23:56.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-running-wsl-without-mde-plug-in&amp;clxha5h5600camc0q7zot8xjr</loc>
    <lastmod>2024-06-16T08:23:59.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-running-wsl&amp;clxfuqwhs00bdmc0q6k6lxrsp</loc>
    <lastmod>2024-06-15T08:24:59.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Malformed%20security%20descriptor&amp;clx925u0e0074mc0q7ywgysyi</loc>
    <lastmod>2024-06-10T14:18:10.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailCountbyCountry&amp;clx921opy0073mc0q41hj4xkx</loc>
    <lastmod>2024-06-10T14:14:56.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Ransomware%20-%20LeaksiteMontitoring&amp;clx8pgmjm006umc0qtdkkyuqs</loc>
    <lastmod>2024-06-10T08:22:38.485Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ransomware_leaksite_monitoring&amp;clx6x4i1w005pmc0qr07yv8h4</loc>
    <lastmod>2024-06-09T02:21:37.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Weekly%20Security%20Incident%20Comparison&amp;clx4vmx2q000j5inoqmy8lp7p</loc>
    <lastmod>2024-06-07T16:04:25.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Users%20affected%20by%20MFA%20enforcement&amp;clx4vmu3s000h5inobop1vkmu</loc>
    <lastmod>2024-06-07T16:04:21.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Threatviewio%20Feed%20in%20EmailUrlInfo&amp;clx4vmr3z000f5inopoyp26ft</loc>
    <lastmod>2024-06-07T16:04:17.470Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20OpenPhish%20Free%20Feed%20Hits%20in%20EmailUrlInfo&amp;clx4vmoj7000d5inom3zsizkw</loc>
    <lastmod>2024-06-07T16:04:14.121Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Successful%20Foreign%20Login%20Attempts%20Analysis&amp;clx4vmmki000c5ino2m70y2gu</loc>
    <lastmod>2024-06-07T16:04:11.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Search%20for%20Webmail%20Users&amp;clx4vmiya000a5ino5sm6ltcu</loc>
    <lastmod>2024-06-07T16:04:06.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RDP%20connections%20from%20devices%20to%20RemoteIP%20classified%20by%20country&amp;clx4vmggd00085inowavlkxii</loc>
    <lastmod>2024-06-07T16:04:03.660Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Malicious%20QR%20Code%20File%20Attachment%20Found&amp;clx4vmcwy00065inoubrg4gx7</loc>
    <lastmod>2024-06-07T16:03:59.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ChatGPT%20Usage%20Detection%20in%20Network%20Traffic&amp;clx4vm9cf00045inodww6y8xh</loc>
    <lastmod>2024-06-07T16:03:54.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CIDRASN%20details%20for%20the%20RemoteIPs%20connections%20attempts&amp;clx4vm6aq00025inom5tisfuk</loc>
    <lastmod>2024-06-07T16:03:50.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AiTM%20Phishing%20Compromised%20account%20validation&amp;clx4vm43f00005inotq9kksle</loc>
    <lastmod>2024-06-07T16:03:47.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20RDP%20Logon%20Sessions&amp;clx4u5hjj000m5iiomtzf5xio</loc>
    <lastmod>2024-06-07T15:22:52.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Weekly%20Email%20Security%20Analysis&amp;clx4u5drt000k5iiokrl9e0k5</loc>
    <lastmod>2024-06-07T15:22:47.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Signin_AfterUrlClick&amp;clx4u57kw000i5iioztyoice8</loc>
    <lastmod>2024-06-07T15:22:39.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Outlook%20monikerlink%20zeroday&amp;clx4u548s000g5iion9h4hok2</loc>
    <lastmod>2024-06-07T15:22:35.067Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OpenPhish%20Urls%20in%20Emails&amp;clx4u51hz000e5iiovfv7tpco</loc>
    <lastmod>2024-06-07T15:22:31.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Microsoft%20Entra%20ID%20User%20Removal&amp;clx4u4yu2000c5iiovhzcpdb0</loc>
    <lastmod>2024-06-07T15:22:28.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MCAS%20Low%20Score%20App%20Usage%20Report&amp;clx4u4wdh000a5iio71bp5sfk</loc>
    <lastmod>2024-06-07T15:22:24.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intune%20Device%20Enrollment%20Information&amp;clx4u4tph00085iioevbkxrrc</loc>
    <lastmod>2024-06-07T15:22:21.412Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Consumer%20VPN%20Logins&amp;clx4u4q3800065iio1udg95wl</loc>
    <lastmod>2024-06-07T15:22:16.724Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Communication%20to%20threatintel.co.nz%20Feed%20IP&amp;clx4u4n3600045iiofm5z7v1e</loc>
    <lastmod>2024-06-07T15:22:12.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Communication%20to%20greensnow.co%20IP%20Blacklist&amp;clx4u4klv00025iio8gk2ac2z</loc>
    <lastmod>2024-06-07T15:22:09.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20IAM%20access%20delgation&amp;clx4u2vtk00005iiodgzpt6nq</loc>
    <lastmod>2024-06-07T15:20:50.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TheArtOfKnowingYourData&amp;clx0ukbs3001wmc0qcw4n7x5o</loc>
    <lastmod>2024-06-04T20:23:19.828Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ManualAntivirusScans&amp;clx0ujyqq001vmc0qt944t3r7</loc>
    <lastmod>2024-06-04T20:23:03.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-TenantRestrictionFailedSignin&amp;clwz2bcuh000qmc0q0l9o0sh6</loc>
    <lastmod>2024-06-03T14:24:46.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-Honeytoken%20was%20queried%20via%20SAM-R&amp;clwyphhn9000gmc0qy4d1gdh7</loc>
    <lastmod>2024-06-03T08:25:37.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-Audit-HealthIssue&amp;clwv3qimk02zxmc0p3cki5n6g</loc>
    <lastmod>2024-05-31T19:53:28.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LiveResponseUnsignedPowerShellChanges&amp;clwto9qs502z0mc0pwr4qgifn</loc>
    <lastmod>2024-05-30T19:52:45.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20named%20pipes%20on%20multiple%20devices&amp;clwtbdtfh02yrmc0pqf24r1jk</loc>
    <lastmod>2024-05-30T13:52:00.316Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OffboardingPackageDownloaded&amp;clwpdyvqj02wamc0pl6nx2mwb</loc>
    <lastmod>2024-05-27T19:53:17.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceRemovedFromIsolation&amp;clwnygjix02vdmc0p2tukehdx</loc>
    <lastmod>2024-05-26T19:51:21.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LiveResponseFileCollection&amp;clwm667iy02u8mc0puq2khybq</loc>
    <lastmod>2024-05-25T13:51:44.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Suspicious%20device%20name&amp;clwkqud0k02tbmc0p8khjbvoe</loc>
    <lastmod>2024-05-24T13:54:50.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityLogonEvents-Unusual%20delegated%20resource%20access&amp;clwkqu98i02tamc0py9uqtk5u</loc>
    <lastmod>2024-05-24T13:54:45.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AlertSupressionAdded&amp;clwkdx00d02t1mc0pwldk2zre</loc>
    <lastmod>2024-05-24T07:52:58.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceIsolation&amp;clwjo6k1702skmc0ph24c1d1o</loc>
    <lastmod>2024-05-23T19:52:34.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rcloneconfigfile&amp;clwjbg2i002sbmc0pxrpzfzam</loc>
    <lastmod>2024-05-23T13:56:03.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RcloneFileProperties&amp;clwjbfz4m02samc0pnbzbuz95</loc>
    <lastmod>2024-05-23T13:55:59.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/rclone-use-detection&amp;clwiyiryf02s1mc0p159aziax</loc>
    <lastmod>2024-05-23T07:54:14.918Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CustomDetectionDeletion&amp;clwhj18s302r4mc0p5c2onv6w</loc>
    <lastmod>2024-05-22T07:52:56.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrintspoolerElevation&amp;clwf15itu02pjmc0pqo8frbr9</loc>
    <lastmod>2024-05-20T13:56:50.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ForestBlizzardCustomProtocolHandler&amp;clwf15ffq02pimc0p48sos41a</loc>
    <lastmod>2024-05-20T13:56:46.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MonitorCloudBreakGlassAccount&amp;clwb3iqnh02n1mc0p129wiw73</loc>
    <lastmod>2024-05-17T19:52:01.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousMMC&amp;clw9o9fja02m4mc0pk2iteoce</loc>
    <lastmod>2024-05-16T19:57:07.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ADSrootDirectoryFileCreation&amp;clw9o7j6h02m3mc0ptsm2gw4b</loc>
    <lastmod>2024-05-16T19:55:38.585Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ADSRootProcessCreation&amp;clw9o7gxi02m2mc0pnaedl4ek</loc>
    <lastmod>2024-05-16T19:55:35.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SliverPSexec&amp;clw9o7cq902m1mc0pjzsj5615</loc>
    <lastmod>2024-05-16T19:55:30.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20ThreatviewioDomain-High-Confidence-Feed&amp;clw4o4jqn02iwmc0pzzydo2wj</loc>
    <lastmod>2024-05-13T07:54:28.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20ThreatviewioIP-High-Confidence-Feed&amp;clw13izsu02gnmc0pdry66jpp</loc>
    <lastmod>2024-05-10T19:54:31.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousAmountofURLClickEvents&amp;clvy8jnju02eumc0pta0ar1sc</loc>
    <lastmod>2024-05-08T19:51:42.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/weird%20SessionId&amp;clvwt2mgx02dxmc0pcd6up3cy</loc>
    <lastmod>2024-05-07T19:50:47.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphURIAPIRequestStats&amp;clvvdp0jv02d0mc0pv57kzj7m</loc>
    <lastmod>2024-05-06T19:52:31.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IPEnrichment&amp;clvty8em202c3mc0pvfr4ndwh</loc>
    <lastmod>2024-05-05T19:51:56.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppEnrichmentAADNonInteractiveUserSignInLogs&amp;clvqdn8d9029umc0p4bt6k4m0</loc>
    <lastmod>2024-05-03T07:52:17.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppEnrichmentExternalData&amp;clvoy9a4s028xmc0pbg9r1xnk</loc>
    <lastmod>2024-05-02T07:53:46.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphResourceAPIRequestStats&amp;clvo8i6j1028gmc0paba2e7yr</loc>
    <lastmod>2024-05-01T19:52:51.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MITRE_ATLAS_csv_parser&amp;clvnvf90f0287mc0pakv8ufk6</loc>
    <lastmod>2024-05-01T13:46:40.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureHound&amp;clvnipsq5027ymc0p630j4oc2</loc>
    <lastmod>2024-05-01T07:50:57.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MITRE_JSON_Parser&amp;clvmsvznh027hmc0pis31v48p</loc>
    <lastmod>2024-04-30T19:47:56.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MITRE_ATLAS_parser&amp;clvmsvupj027gmc0p7mycaadm</loc>
    <lastmod>2024-04-30T19:47:49.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/rdp-default-listening-port-modification&amp;clviismzg024rmc0po29df6a0</loc>
    <lastmod>2024-04-27T19:54:18.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-where-mitigationstatus-is-isolated&amp;clvht45i7024amc0pp1zn39xs</loc>
    <lastmod>2024-04-27T07:55:26.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/rdp-enable-by-modifying-registry-key&amp;clvhg6i3y0241mc0ppcsye5pu</loc>
    <lastmod>2024-04-27T01:53:20.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/netsh-command-for-firewall-to-allow-incoming-rdp-connections&amp;clvhg6d6z0240mc0pwlr96pwv</loc>
    <lastmod>2024-04-27T01:53:14.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID-MDEDeviceRegistrations&amp;clvh3b88a023rmc0pd1p9x7gy</loc>
    <lastmod>2024-04-26T19:53:06.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID%20-%20GroupMembershipchanges-Dynamic&amp;clvh3b35j023qmc0pier94vzm</loc>
    <lastmod>2024-04-26T19:52:59.574Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs%20-%20UserActivities&amp;clvfntlqm022vmc0peo240uln</loc>
    <lastmod>2024-04-25T19:51:43.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CountryInfoExternal&amp;clvfnls5a022umc0p0cxbn6jt</loc>
    <lastmod>2024-04-25T19:45:38.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureServiceIPs&amp;clvel0bpy0225mc0px12yxiax</loc>
    <lastmod>2024-04-25T01:45:12.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelAnalyticsRuleNewCISAKnowExploitedVulnerabilityAdded&amp;clvcszdt40210mc0pheysjbwl</loc>
    <lastmod>2024-04-23T19:52:52.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppTraces-App%20Service%20failures&amp;clvbdfzy00203mc0prx5gt4eb</loc>
    <lastmod>2024-04-22T19:50:07.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/D4IOT-MaliciousNameQueriesDetection&amp;clv9l88b001yymc0pbg49xbqh</loc>
    <lastmod>2024-04-21T13:52:29.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/D4IOT-IoT_PLCOperatingMode&amp;clv9l85ju01yxmc0p0ma9iv8h</loc>
    <lastmod>2024-04-21T13:52:26.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/D4IOT-IoT_MalwareDetected&amp;clv9l82tb01ywmc0pp9zgz5ia</loc>
    <lastmod>2024-04-21T13:52:22.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/D4IOT-FTP%20Authentication%20failure&amp;clv9l800u01yvmc0pnbcm9fga</loc>
    <lastmod>2024-04-21T13:52:19.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-AIPClient&amp;clv9l7kx701yumc0p3uuuz7ln</loc>
    <lastmod>2024-04-21T13:51:59.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphAPI%20-%20SuspiciousUserRequests&amp;clv9l546n01ytmc0pb9rf43jh</loc>
    <lastmod>2024-04-21T13:50:04.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UserEnrichment&amp;clv85r0mb01xwmc0pcthxu6ul</loc>
    <lastmod>2024-04-20T13:51:26.290Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CollectIncidentStatistics&amp;clv6qb4ee01wzmc0p4bhufpkq</loc>
    <lastmod>2024-04-19T13:51:24.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/minimum-characters-for-pim-activation-justification&amp;cluxsvfap01remc0p58wmag8z</loc>
    <lastmod>2024-04-13T07:53:15.312Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-WizIssues&amp;cluvnlyj201q3mc0puw5qhffd</loc>
    <lastmod>2024-04-11T19:50:23.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListADDelegations&amp;clupxyqum01momc0pve9fivbz</loc>
    <lastmod>2024-04-07T19:53:38.925Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-DepreicatedPowerShellModule&amp;clung06ug01l3mc0p3xturzsv</loc>
    <lastmod>2024-04-06T01:55:20.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-ExtractPhoneNumber&amp;clum033dn01jymc0pvaw1wgso</loc>
    <lastmod>2024-04-05T01:41:56.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TableData&amp;clulnffcz01jxmc0p05dthvm1</loc>
    <lastmod>2024-04-04T19:47:36.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataPerComputer&amp;clulne05001jwmc0pc6mna3qm</loc>
    <lastmod>2024-04-04T19:46:30.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/parse_ipv4%20malfunction&amp;clujv9k3n01irmc0pnxq3nap9</loc>
    <lastmod>2024-04-03T13:51:27.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DnsEvents-DNS%20query%20resolved%20to%20Palo%20Alto%20Networks%20sinkhole&amp;cluispr0b01i2mc0pmrdmjv7o</loc>
    <lastmod>2024-04-02T19:52:17.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20S3%20object%20encrypted%20with%20external%20key&amp;cluhd9l3w01h5mc0pkjifth6b</loc>
    <lastmod>2024-04-01T19:52:03.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/InboundSSHConnectionToVulnerableXZMachine&amp;clue5kqqs01f4mc0p1gkbe7h5</loc>
    <lastmod>2024-03-30T13:53:28.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2024-3094-internet-facing-devices&amp;cludstmqp01evmc0ptjq53m1k</loc>
    <lastmod>2024-03-30T07:56:27.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LogAnalyticsQueryStatistics&amp;clucq7m0u01e6mc0pe9sid2r9</loc>
    <lastmod>2024-03-29T13:55:35.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Watchlist_Item_Delete&amp;clubaih6601d9mc0pe8cva20c</loc>
    <lastmod>2024-03-28T13:48:22.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-StorageAccounts&amp;clu8spfbh01bomc0p3888zqyu</loc>
    <lastmod>2024-03-26T19:54:21.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-MaliciousLink&amp;clu8spax101bnmc0pepi3skvo</loc>
    <lastmod>2024-03-26T19:54:15.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-CriticalAssets&amp;clu8sp67r01bmmc0pvxxz50zw</loc>
    <lastmod>2024-03-26T19:54:09.059Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-AzureVirtualMachines&amp;clu8sp3ac01blmc0po4r3qdwb</loc>
    <lastmod>2024-03-26T19:54:05.411Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ResourceContainerChanges-Azure%20subscription%20modified&amp;clu8fr1js01bcmc0psoh6cwwk</loc>
    <lastmod>2024-03-26T13:51:41.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-SoftwareUninstall&amp;clu7q29m201avmc0p8hkvjpog</loc>
    <lastmod>2024-03-26T01:52:34.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-ParseNetsh&amp;clu7q20um01aumc0pxfd29y2r</loc>
    <lastmod>2024-03-26T01:52:23.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-SensitiveGroupChanges&amp;clu7q1qmr01atmc0pvqr3ioww</loc>
    <lastmod>2024-03-26T01:52:10.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-GPOCreation&amp;clu7q1lxy01asmc0pybevugd7</loc>
    <lastmod>2024-03-26T01:52:04.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SummaryOfPrivilegedOperationsByDirectoryRoleMember&amp;clu5l02b9019fmc0pwj0jg3e0</loc>
    <lastmod>2024-03-24T13:55:21.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureResourceCount&amp;clu32vogx017umc0prtl3u4h8</loc>
    <lastmod>2024-03-22T19:52:31.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NTDSDitFileModifications&amp;clu1nfak5016xmc0po6e3z2cz</loc>
    <lastmod>2024-03-21T19:52:06.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SensitiveMicrosoftGraphDelegatedPermissionAccess&amp;clu1ap6u0016omc0p13nkauye</loc>
    <lastmod>2024-03-21T13:55:53.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Tarfilexecutions&amp;cltzigr6k015jmc0pw8s6hcc0</loc>
    <lastmod>2024-03-20T07:57:44.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PossibleMaliciousBrowserExtensionLoaded&amp;cltzigp1p015imc0p33ln4xbg</loc>
    <lastmod>2024-03-20T07:57:41.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ChromeloaderRegistryValueLargeSizeGeneric&amp;cltzigmpy015hmc0p1g4vp41c</loc>
    <lastmod>2024-03-20T07:57:38.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-AdminActionsfromRiskyUsers&amp;cltzhtsxk0158mc0p8dfsfvq6</loc>
    <lastmod>2024-03-20T07:39:53.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity%20Protection%20latency%20issues&amp;cltyfo4vj014rmc0pl8lbze9z</loc>
    <lastmod>2024-03-19T13:51:44.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_PowerPlatformConnectorActivity&amp;cltyfmxbv014qmc0p20msszo2</loc>
    <lastmod>2024-03-19T13:50:47.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_PowerAppsActivity&amp;cltyfmqhn014pmc0phjfvbixl</loc>
    <lastmod>2024-03-19T13:50:38.746Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Account%20created%20by%20unexpected%20account&amp;cltyflhta014omc0pp0wx9tty</loc>
    <lastmod>2024-03-19T13:49:40.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Suspicious%20process%20connection%20to%20cloudfront%20domain&amp;cltx042sk013rmc0pu2vnp2mm</loc>
    <lastmod>2024-03-18T13:48:27.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20NetActivities&amp;cltt2rfsw011amc0pldnw3cgb</loc>
    <lastmod>2024-03-15T19:51:32.145Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Suspicious%20connection%20by%20WerFault&amp;cltt2ou5p0119mc0pi6t03xia</loc>
    <lastmod>2024-03-15T19:49:30.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Suspicious%20connection%20by%20COM%20Surrogate&amp;cltt2oqn00118mc0prkfb1xk9</loc>
    <lastmod>2024-03-15T19:49:26.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-RDP&amp;cltqks07w00znmc0pogdh2my3</loc>
    <lastmod>2024-03-14T01:52:33.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EEG-ManagedIdentity&amp;cltqkrwqj00zmmc0pzuaeb7vx</loc>
    <lastmod>2024-03-14T01:52:28.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-SuspiciousAWSCLICommandExecution&amp;cltncvnbw00xlmc0pa7th9owt</loc>
    <lastmod>2024-03-11T19:48:07.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommandlineGroupAddition&amp;cltn044wo00xcmc0ppu9wn62c</loc>
    <lastmod>2024-03-11T13:50:48.791Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MidnightBlizzard&amp;cltj2gio100uvmc0pga8k70ay</loc>
    <lastmod>2024-03-08T19:45:21.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DirectAgent&amp;cltj2fppg00uumc0pjqm6x704</loc>
    <lastmod>2024-03-08T19:44:43.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-NSGChanges&amp;cltj2f4kb00utmc0p4zueqt49</loc>
    <lastmod>2024-03-08T19:44:15.945Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-CloudShellExecution&amp;cltj2f1b900usmc0pp5jd6k7b</loc>
    <lastmod>2024-03-08T19:44:11.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-BruteForce&amp;cltj2ewnu00urmc0p7a2jek8l</loc>
    <lastmod>2024-03-08T19:44:05.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-BreakGlassAccount&amp;cltj2eups00uqmc0p9h5ftsac</loc>
    <lastmod>2024-03-08T19:44:03.327Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AMAAgent&amp;cltj2esmp00upmc0pdi7sa9v4</loc>
    <lastmod>2024-03-08T19:44:00.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceNetworkEvents-Suspicious%20process%20connection%20to%20cloudfrount%20domain&amp;clthn7zv600tsmc0pbn7etuic</loc>
    <lastmod>2024-03-07T19:51:02.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_detect_sts_get_session_token_abuse&amp;cltes9a5300rzmc0pyijqw54p</loc>
    <lastmod>2024-03-05T19:48:42.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20S3%20bucket%20publicly%20exposed&amp;cltes7clg00rymc0pi5ghf19o</loc>
    <lastmod>2024-03-05T19:47:12.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20Graph%20-%20VMs%20%26%20HybridCompute&amp;clteffjva00rpmc0p87uoi2ar</loc>
    <lastmod>2024-03-05T13:49:40.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DnsEvents-DNS%20query%20resolved%20to%20Palo%20Alto%20Networks%20skinhole&amp;cltca9mpo00qcmc0p531asi9b</loc>
    <lastmod>2024-03-04T01:49:33.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-isolated-endpoints&amp;clt7ah1gs00n9mc0po580bcdg</loc>
    <lastmod>2024-02-29T13:56:28.061Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-removed-from-isolation&amp;clt7agxmk00n8mc0pkd90iakg</loc>
    <lastmod>2024-02-29T13:56:23.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommandlineUserAddition&amp;clt67q1u300mlmc0ploaxz5ye</loc>
    <lastmod>2024-02-28T19:51:43.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MultipleSentitiveGroupAdditions&amp;clt4s93jk00lomc0p77wagu05</loc>
    <lastmod>2024-02-27T19:50:52.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Defender%20for%20Cloud%20incident&amp;clt3ctj1100krmc0partw4uqs</loc>
    <lastmod>2024-02-26T19:51:05.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Apt29&amp;clt305wp800kimc0poj4qz7s5</loc>
    <lastmod>2024-02-26T13:56:47.804Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-DataUsage&amp;clt2mrx1z00k1mc0pgrsw0x3t</loc>
    <lastmod>2024-02-26T07:42:00.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellInvokeWebrequest&amp;clt1kj9h800jkmc0p22l8gs18</loc>
    <lastmod>2024-02-25T13:51:31.003Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CertutilRemoteDownload&amp;clt053rk700inmc0p3rz9tafq</loc>
    <lastmod>2024-02-24T13:51:47.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-endpoints-removed-from-containment&amp;clszsd6cl00iemc0prwg9nwj5</loc>
    <lastmod>2024-02-24T07:55:11.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-contained-endpoints&amp;clszsd2r200idmc0pbjf0vjue</loc>
    <lastmod>2024-02-24T07:55:06.926Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ThreatIntelligenceThreatTypes&amp;clsy09qu800h8mc0ppvd5f4i2</loc>
    <lastmod>2024-02-23T02:00:56.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CreateAndQuery&amp;clsx9ybnx00gtmc0pcoaxa0kb</loc>
    <lastmod>2024-02-22T13:44:13.195Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Teams%20phishing%20campaign&amp;clsw7jaet00g4mc0pgxgpbju8</loc>
    <lastmod>2024-02-21T19:48:46.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SBMNTLM&amp;clsufho8c00ezmc0p77q4i1nk</loc>
    <lastmod>2024-02-20T13:55:55.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppServiceHTTPLogs-PHP%20file%20request%20in%20App%20Service&amp;clstcrapn00eamc0pv8z2aru0</loc>
    <lastmod>2024-02-19T19:51:39.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-PaloAltoPrismaCloudAlertLogs&amp;clstcpuak00e9mc0p5vup7vv4</loc>
    <lastmod>2024-02-19T19:50:31.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-AzurePortalSigninfromanotherAzureTenant&amp;clsszrqjz00e0mc0p3yghpi63</loc>
    <lastmod>2024-02-19T13:48:04.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vssadmindelete&amp;clsr7sptt00cvmc0p94exvec4</loc>
    <lastmod>2024-02-18T07:57:15.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellKeyLogging&amp;clsr7smq000cumc0p1kjrjnpj</loc>
    <lastmod>2024-02-18T07:57:11.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BloodHoundGeneratedfiles&amp;clsr7sk8700ctmc0pcsk2zvyw</loc>
    <lastmod>2024-02-18T07:57:08.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-SlowPasswordSpray&amp;clsps32b300bymc0pooh3ybnx</loc>
    <lastmod>2024-02-17T07:49:37.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-PotentialMFASpam&amp;clsps2wd600bxmc0plmnrm9tv</loc>
    <lastmod>2024-02-17T07:49:30.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AzureRBACRoleAssignments&amp;clsps2qgb00bwmc0pg8jxaeoc</loc>
    <lastmod>2024-02-17T07:49:22.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SysmonParser&amp;clsprz2n300bvmc0pmop40man</loc>
    <lastmod>2024-02-17T07:46:31.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-CiscoASAParser&amp;clsprsdkh00bmmc0psndz2fi1</loc>
    <lastmod>2024-02-17T07:41:19.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphActivityFromFirstPartyApps&amp;clsp2jg0u00bdmc0pfjd9ri1o</loc>
    <lastmod>2024-02-16T19:54:32.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AadAuditEventFromFirstPartyApps&amp;clsp2jb6j00bcmc0p0kptqjka</loc>
    <lastmod>2024-02-16T19:54:26.010Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_setdefaultpolicyversion&amp;clsnmx5du00afmc0p5kambq2p</loc>
    <lastmod>2024-02-15T19:49:31.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_network_access_control_list_deleted&amp;clsnmx23x00aemc0pp784lcjb</loc>
    <lastmod>2024-02-15T19:49:27.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_iam_assume_role_policy_brute_force&amp;clsnmwyig00admc0p2wppd3et</loc>
    <lastmod>2024-02-15T19:49:22.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20user%20MFA%20modified&amp;clsnmuxs100acmc0pn1enpj8u</loc>
    <lastmod>2024-02-15T19:47:48.480Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20FileTypes&amp;clsm7jfp4009fmc0p9rtobonu</loc>
    <lastmod>2024-02-14T19:51:11.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_iam_accessdenied_discovery_events&amp;clsm7gve7009emc0ptxiy84be</loc>
    <lastmod>2024-02-14T19:49:11.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_exfiltration_via_datasync_task&amp;clslulw480095mc0p66q8lqpf</loc>
    <lastmod>2024-02-14T13:49:10.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_exfiltration_via_bucket_replication&amp;clslulran0094mc0pwdgxj45t</loc>
    <lastmod>2024-02-14T13:49:04.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-Incidents%20with%20automation%20rule%20failure%20events%20from%20SentinelHealth&amp;clslulkq90093mc0p9y9lgske</loc>
    <lastmod>2024-02-14T13:48:56.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_ecr_container_upload_unknown_user&amp;clsks0g8a008emc0pabq0sxzf</loc>
    <lastmod>2024-02-13T19:48:45.082Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_disable_bucket_versioning&amp;clsks0d6b008dmc0pe3hghh9l</loc>
    <lastmod>2024-02-13T19:48:41.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_password_policy_changes&amp;clskf6vpr0084mc0pnmsrxsym</loc>
    <lastmod>2024-02-13T13:49:50.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_multi_factor_authentication_disabled&amp;clskf6pin0083mc0pjlz7p5ur</loc>
    <lastmod>2024-02-13T13:49:42.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_defense_evasion_putbucketlifecycle&amp;clskf6mr90082mc0pgoyae144</loc>
    <lastmod>2024-02-13T13:49:38.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_credential_access_rds_password_reset&amp;clskf6dtp0081mc0pyizra4vs</loc>
    <lastmod>2024-02-13T13:49:27.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_credential_access_getpassworddata&amp;clskf68tg0080mc0pdcn4v32v</loc>
    <lastmod>2024-02-13T13:49:20.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_credential_access_failed_login&amp;clskf64if007zmc0pp3p3edya</loc>
    <lastmod>2024-02-13T13:49:14.966Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_createaccesskey&amp;clskf61bn007ymc0pqvr1n5b0</loc>
    <lastmod>2024-02-13T13:49:10.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-aws_concurrent_sessions_from_different_ips&amp;clskf5wca007xmc0p8p4fsrh6</loc>
    <lastmod>2024-02-13T13:49:04.232Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-asl_aws_password_policy_changes&amp;clsjcltqj0078mc0p25lzae8t</loc>
    <lastmod>2024-02-12T19:49:42.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20IAM%20user%20password%20modified&amp;clsjcjuve0077mc0pcxiqj4aq</loc>
    <lastmod>2024-02-12T19:48:10.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20EBS%20snapshot%20publicly%20exposed&amp;clsjcjqsp0076mc0payf6rpw2</loc>
    <lastmod>2024-02-12T19:48:05.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20DB%20snapshot%20publicly%20exposed&amp;clsjcjlpb0075mc0pcdg4109e</loc>
    <lastmod>2024-02-12T19:47:58.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20AMI%20publicly%20exposed&amp;clsjcjfcn0074mc0pue1xf9ek</loc>
    <lastmod>2024-02-12T19:47:50.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-asl_aws_multi_factor_authentication_disabled&amp;clsizpmuu006vmc0p5ocismfz</loc>
    <lastmod>2024-02-12T13:48:45.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EpmUnusuedServicePrincipalsAzADSPI&amp;clsgi37j9005amc0p83z2ghjk</loc>
    <lastmod>2024-02-10T19:59:53.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-asl_aws_createaccesskey&amp;clsdmu7d3003hmc0ptjifrwed</loc>
    <lastmod>2024-02-08T19:49:32.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-asl_aws_concurrent_sessions_from_different_ips&amp;clsd9y5u50038mc0pw50g6pbk</loc>
    <lastmod>2024-02-08T13:48:42.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/USB_Copy_7_days&amp;clsck3myn002rmc0p3hvk0ct3</loc>
    <lastmod>2024-02-08T01:45:07.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MultipleAccountsLocked&amp;clsaryoe0001mmc0p6xtaptsg</loc>
    <lastmod>2024-02-06T19:49:40.727Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADUserRiskEvents-Leaked%20credentials&amp;cls8zoc7j000gmc0poz7itxe6</loc>
    <lastmod>2024-02-05T13:50:02.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20Quick%20Fix%20Engineering%20Hot%20Fixes&amp;cls8z1ppd00255iv8bno5er1r</loc>
    <lastmod>2024-02-05T13:32:27.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20Update%20Installations&amp;cls8z1nng00235iv8fro2ksi2</loc>
    <lastmod>2024-02-05T13:32:24.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20Right%20Assigned&amp;cls8z1lo200215iv8tk97ao9k</loc>
    <lastmod>2024-02-05T13:32:22.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20Added%20to%20Privileged%20Group&amp;cls8z1jpi001z5iv8t1q57jgt</loc>
    <lastmod>2024-02-05T13:32:19.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/System%20Time%20Changed&amp;cls8z1hjf001x5iv8cvy6zcic</loc>
    <lastmod>2024-02-05T13:32:16.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Successful%20User%20Account%20Login&amp;cls8z1fj4001v5iv8vg6c5wo6</loc>
    <lastmod>2024-02-05T13:32:14.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Services%20That%20Have%20Stopped&amp;cls8z1d6f001t5iv85en9dfqv</loc>
    <lastmod>2024-02-05T13:32:11.126Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Services%20That%20Have%20Started&amp;cls8z1ai8001r5iv8hzcnzrln</loc>
    <lastmod>2024-02-05T13:32:07.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Latest%20Application%20Installations&amp;cls8z18ff001p5iv8hgi7sb51</loc>
    <lastmod>2024-02-05T13:32:04.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Failed%20Licence%20Activations&amp;cls8z16ni001o5iv8p0ihkfbm</loc>
    <lastmod>2024-02-05T13:32:02.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Application%20Hangs&amp;cls8z13y6001m5iv8et7lk32c</loc>
    <lastmod>2024-02-05T13:31:59.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Application%20Crashes&amp;cls8z11jt001k5iv8vltbp1vc</loc>
    <lastmod>2024-02-05T13:31:56.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Application%20Events&amp;cls8z0zar001i5iv839mmxq79</loc>
    <lastmod>2024-02-05T13:31:53.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Service%20Start%20Failure&amp;cls8z0x6a001g5iv8mxb9i0fz</loc>
    <lastmod>2024-02-05T13:31:50.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Query%20Recent%20Windows%20System%20Event%20Logs&amp;cls8z0uzq001e5iv8s8hbul1a</loc>
    <lastmod>2024-02-05T13:31:47.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Overview%20Event%20Level%20Types%20for%20Windows%20Applications%20Events&amp;cls8z0sfg001c5iv8gscbmnjk</loc>
    <lastmod>2024-02-05T13:31:44.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Number%20of%20Events%20per%20Provider&amp;cls8z0q45001a5iv8lw5zrtp1</loc>
    <lastmod>2024-02-05T13:31:41.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Failed%20User%20Account%20Login&amp;cls8z0o1b00185iv8w9tiyae8</loc>
    <lastmod>2024-02-05T13:31:38.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Event%20Log%20was%20Cleared&amp;cls8z0lr700165iv8iqjw1i17</loc>
    <lastmod>2024-02-05T13:31:35.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check%20if%20Device%20Restart%20Is%20Required&amp;cls8z0jtw00145iv8h3vqurg3</loc>
    <lastmod>2024-02-05T13:31:33.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Blue%20Screen%20of%20Death&amp;cls8z0gve00125iv8enbe5036</loc>
    <lastmod>2024-02-05T13:31:29.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Assigned%20Primary%20Tokens&amp;cls8z0eiu00105iv8zjt2px58</loc>
    <lastmod>2024-02-05T13:31:26.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Drivers%20That%20Are%20Not%20Signed&amp;cls8z0btr000y5iv80qtb21mk</loc>
    <lastmod>2024-02-05T13:31:22.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Number%20of%20Signed%20and%20Unsigned%20Drivers&amp;cls8z09to000w5iv858q0s20i</loc>
    <lastmod>2024-02-05T13:31:20.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Group%20Drivers%20by%20Their%20Provider%20Name&amp;cls8z07eh000u5iv8hkx5rzjx</loc>
    <lastmod>2024-02-05T13:31:16.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Drivers%20That%20Don%E2%80%99t%20Have%20Associated%20Inf%20Files&amp;cls8z05lf000s5iv8qc6d9q2y</loc>
    <lastmod>2024-02-05T13:31:14.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows%20App%20Crash%20Events%20Grouped%20by%20the%20App%20and%20Its%20Version&amp;cls8z03lk000q5iv8zkn7kkks</loc>
    <lastmod>2024-02-05T13:31:12.056Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/List%20of%20Applications%20Crashes&amp;cls8z01co000o5iv8t3ncali4</loc>
    <lastmod>2024-02-05T13:31:09.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Lookup%20Registry%20Keys%20Wildcard&amp;cls8yzz06000m5iv8bmi2a0bo</loc>
    <lastmod>2024-02-05T13:31:06.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Windows%2011%20Compatible%20Tpms&amp;cls8yzwfn000l5iv8n6thnc3k</loc>
    <lastmod>2024-02-05T13:31:02.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Track%20the%20Working%20Directories%20of%20Processes&amp;cls8yzukg000k5iv8cmry0mag</loc>
    <lastmod>2024-02-05T13:31:00.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Track%20the%20Usage%20of%20Specific%20Applications%20and%20How%20Often%20They%20Are%20Started&amp;cls8yzryu000j5iv8bvtly6wd</loc>
    <lastmod>2024-02-05T13:30:56.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Most%20frequently%20running%20Processes&amp;cls8yzp2e000i5iv8y9od2qpa</loc>
    <lastmod>2024-02-05T13:30:53.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/List%20All%20Process%20That%20Running%20Under%20NT%20Authority&amp;cls8yzmzf000h5iv8szqrzx28</loc>
    <lastmod>2024-02-05T13:30:50.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Impact%20of%20Processes%20Over%20Time%20by%20Looking%20at%20How%20Long%20They%20Run&amp;cls8yzkrg000g5iv842j4orin</loc>
    <lastmod>2024-02-05T13:30:47.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20Unexpected%20or%20Unknown%20Processes%20Running%20From%20Unusual%20Paths&amp;cls8yzhdk000f5iv8mf9qtppa</loc>
    <lastmod>2024-02-05T13:30:43.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20Processes%20That%20Are%20Heavily%20Using%20Disk%20Space&amp;cls8yzeli000e5iv8vx3w1yud</loc>
    <lastmod>2024-02-05T13:30:39.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Processes%20With%20High%20Memory%20Usage&amp;cls8yzbsc000d5iv8fnqnesbj</loc>
    <lastmod>2024-02-05T13:30:36.011Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20All%20System%20Processes%20Related%20to%20Defender%2C%20Sense%20or%20Security&amp;cls8yz96l000c5iv8b6vwasl0</loc>
    <lastmod>2024-02-05T13:30:32.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Determine%20Which%20Users%20Are%20Running%20Which%20Processes&amp;cls8yz4hy000b5iv8lkbb85vp</loc>
    <lastmod>2024-02-05T13:30:26.557Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Processes%20That%20Are%20Reading%20or%20Writing%20Significantly%20to%20Disk&amp;cls8yz1vx000a5iv89omz4uhp</loc>
    <lastmod>2024-02-05T13:30:23.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Command%20Lines%20Used%20to%20Start%20Processes&amp;cls8yyyzj00095iv8k52szp1n</loc>
    <lastmod>2024-02-05T13:30:19.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analyze%20Start%20Times%20and%20Run%20Durations%20of%20Processes&amp;cls8yyw4f00085iv8l30og0as</loc>
    <lastmod>2024-02-05T13:30:15.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Local%20Drives&amp;cls8yyta400075iv82adjm62w</loc>
    <lastmod>2024-02-05T13:30:12.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20all%20Local%20Groups%20on%20Device&amp;cls8yyr3700065iv8pnwi6m4b</loc>
    <lastmod>2024-02-05T13:30:09.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Search%20Recently%20Created%20Files%20at%20a%20Location&amp;cls8yy9un00045iv8l5kcjzah</loc>
    <lastmod>2024-02-05T13:29:46.846Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20Hosts%20File&amp;cls8yy7wd00025iv817ulzv1w</loc>
    <lastmod>2024-02-05T13:29:44.316Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Find%20Disk%20Information&amp;cls8yy5v100005iv810tluk57</loc>
    <lastmod>2024-02-05T13:29:41.666Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Valid%20Certificates%20on%20Device&amp;cls8yur70000n5icktg69sqda</loc>
    <lastmod>2024-02-05T13:27:02.700Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20Expired%20Certificates%20on%20Device&amp;cls8yuowg000l5icktofxb2i6</loc>
    <lastmod>2024-02-05T13:26:59.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Self-Signed%20Certificates&amp;cls8yumo2000j5ickv3zulue3</loc>
    <lastmod>2024-02-05T13:26:56.833Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Insecure%20Certificates&amp;cls8yujy2000h5ick8ss2cb8e</loc>
    <lastmod>2024-02-05T13:26:53.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Show%20All%20Certificates%20That%20Are%20Not%20Stored%20in%20Localmachine&amp;cls8yuhea000f5icknzk4m80o</loc>
    <lastmod>2024-02-05T13:26:50.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/List%20All%20CA%20Certificates&amp;cls8yufhy000d5ickhewok92e</loc>
    <lastmod>2024-02-05T13:26:47.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intune%20MDM%20Device%20Certificate&amp;cls8yudcz000b5ick6ytkzfut</loc>
    <lastmod>2024-02-05T13:26:44.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Certificates%20That%20Will%20Expire%20in%20the%20Next%2090%20days&amp;cls8yubpj000a5ickdkleo000</loc>
    <lastmod>2024-02-05T13:26:42.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Monitor%20CPU%20Performance%20and%20Health&amp;cls8yu8it00085ickujb288x4</loc>
    <lastmod>2024-02-05T13:26:38.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identify%20CPU%20Configuration&amp;cls8yu6aj00065ick08z9lnjo</loc>
    <lastmod>2024-02-05T13:26:35.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20CPU%20Overclocking&amp;cls8yu4al00045ickm0gjvvt0</loc>
    <lastmod>2024-02-05T13:26:33.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Assess%20CPU%20Physical%20Characteristics&amp;cls8yu29300025ickob8r5mlj</loc>
    <lastmod>2024-02-05T13:26:30.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BIOS%20Details&amp;cls8yu07400005ickxnooigjx</loc>
    <lastmod>2024-02-05T13:26:27.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WindowsBuiltInGroupMemberChanges&amp;cls8bgb6j001nmc0qx3huigb8</loc>
    <lastmod>2024-02-05T02:31:57.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ttp_smoke-sandstorm_unusual_coreuicomponent.dll-behaviour&amp;cls7yjj6s001emc0qx74eacl5</loc>
    <lastmod>2024-02-04T20:30:32.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ttp_generic_kerberos_attacks&amp;cls7yje2y001dmc0qt9nu2agi</loc>
    <lastmod>2024-02-04T20:30:26.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-TaxiiConnectorFailures&amp;cls6j65gg000gmc0qmkjecyia</loc>
    <lastmod>2024-02-03T20:32:28.047Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Unprotected%20secrets%20assessments&amp;cls62yk8z000w5izcta2i252k</loc>
    <lastmod>2024-02-03T12:58:40.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-System%20updates%20assessments&amp;cls62ygcg000u5izclcgzwt3u</loc>
    <lastmod>2024-02-03T12:58:35.199Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-System%20updates%20Update%20Center%20assessments&amp;cls62ydka000s5izcaz1k4563</loc>
    <lastmod>2024-02-03T12:58:31.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Security%20configuration%20assessments&amp;cls62yal1000q5izc2jlrmyml</loc>
    <lastmod>2024-02-03T12:58:27.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Security%20configuration%20Guest%20Configuration%20assessments&amp;cls62y8am000o5izc9lg4b6t4</loc>
    <lastmod>2024-02-03T12:58:24.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-SQL%20databases%20assessments&amp;cls62y5lc000m5izczitjlbgw</loc>
    <lastmod>2024-02-03T12:58:21.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Running%20container%20images%20MDVM%20vulnerability%20assessments&amp;cls62y2gc000k5izc63gtqrr4</loc>
    <lastmod>2024-02-03T12:58:17.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Linux%20virtual%20machines%20SecureBoot%20assessments&amp;cls62xy57000i5izcg7qz0rkl</loc>
    <lastmod>2024-02-03T12:58:11.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Endpoint%20protection%20assessments&amp;cls62xvbc000g5izcqbty0ecu</loc>
    <lastmod>2024-02-03T12:58:07.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/binaries-using-anydesk-compromised-certificate&amp;cls5sut2300005i0swhhks607</loc>
    <lastmod>2024-02-03T08:15:48.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ttp_t1543_peach-sandstorm_azure_arc_persistence&amp;cls2bbgja00lvmc0q0fjzk1h9</loc>
    <lastmod>2024-01-31T21:41:34.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TotalEventsByTable&amp;cls0vvveq00kymc0qcecww2m5</loc>
    <lastmod>2024-01-30T21:41:46.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20ipfs_phishing&amp;clrzggbim00k1mc0qcvx35xdo</loc>
    <lastmod>2024-01-29T21:42:00.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ttp_t1543_scattered-spider_azure_arc_persistence&amp;clrzgfm4i00k0mc0qgd8xebd3</loc>
    <lastmod>2024-01-29T21:41:27.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/nf_ttp_t1562.001_scattered-spider_abuse%20conditional_access_trusted_locations&amp;clrzgeply00jzmc0qgw3bu4g7</loc>
    <lastmod>2024-01-29T21:40:45.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-InboxForwarding&amp;clrxo6bsb00iumc0qjkg7hb3x</loc>
    <lastmod>2024-01-28T15:42:38.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/possible-soaphound-tool-execution-using-specific-arguments&amp;clrvvwt5p00hpmc0q6yuor0jq</loc>
    <lastmod>2024-01-27T09:43:39.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-CAPoliciesNotinUse&amp;clrry0na200f0mc0q5nz7gmxi</loc>
    <lastmod>2024-01-24T15:31:32.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unsynchronized%20Defender%20for%20Cloud%20alert&amp;clrqvqm1e00ejmc0qsfkx0u3w</loc>
    <lastmod>2024-01-23T21:39:59.377Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TokenReplayOfWorkloadIdentityFromOutsideOfAzureNetworkRange&amp;clrq66nuf00e2mc0q96eic5w0</loc>
    <lastmod>2024-01-23T09:44:38.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MacroTrustrecords&amp;clrp3ojth00ddmc0qns4auqtq</loc>
    <lastmod>2024-01-22T15:46:47.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/applicationshimming&amp;clroqsxs000d4mc0qso0p6ys6</loc>
    <lastmod>2024-01-22T09:46:17.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Spamhaus-10-most-abused-tlds&amp;clrnbaxpx00c7mc0q9g920md0</loc>
    <lastmod>2024-01-21T09:44:37.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behaviour%20-%20APT28ExternalWebdav&amp;clrkt7usq00ammc0qat88c815</loc>
    <lastmod>2024-01-19T15:42:47.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ttp_t1562-001_disabledefender&amp;clrjqmmv4009xmc0qkhmydsjy</loc>
    <lastmod>2024-01-18T21:42:32.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ttp_t1219_netsupportrat_fin7&amp;clrjqmj4l009wmc0qwkymc8qr</loc>
    <lastmod>2024-01-18T21:42:27.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ttp_t1127-001_suspNetworkConnMSBuild&amp;clrjqmej0009vmc0qi9qxxz68</loc>
    <lastmod>2024-01-18T21:42:21.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ttp_t1059-001_powershell_windowsappsdir_fin7&amp;clrjqma71009umc0qz953ow7t</loc>
    <lastmod>2024-01-18T21:42:16.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ttp_t1027-010_powershellEncodedCommand&amp;clrjqm7g5009tmc0q9qf04kox</loc>
    <lastmod>2024-01-18T21:42:12.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-ConnectivityType&amp;clrfgbkqn0076mc0qnbbf0y93</loc>
    <lastmod>2024-01-15T21:42:55.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behaviour%20-%20APT28Commands&amp;clrag9br50041mc0qny29f3lx</loc>
    <lastmod>2024-01-12T09:42:19.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Virtual%20machines%20MDVM%20vulnerability%20assessments&amp;clr9dljzd003cmc0qpi0487a7</loc>
    <lastmod>2024-01-11T15:40:05.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ipv4_is_private%20malfunction&amp;clr7y6lb0002fmc0q3v1zr0b9</loc>
    <lastmod>2024-01-10T15:40:46.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-iOSDevicesWithoutLatestOSVersion&amp;clr7xrhu50026mc0qrxg6f3ti</loc>
    <lastmod>2024-01-10T15:29:02.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-StaleDevice&amp;clr7xrcd90025mc0qbhvg4549</loc>
    <lastmod>2024-01-10T15:28:55.388Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NumberOfDeviceWipesAndDeletions&amp;clr7xr1cu0024mc0q248z4dg4</loc>
    <lastmod>2024-01-10T15:28:41.117Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellNoProfile&amp;clr7ldku90023mc0qpni9ciql</loc>
    <lastmod>2024-01-10T09:42:17.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDXDR-ThreatProtectionReport&amp;clr6vowiu001mmc0q7v2xeqde</loc>
    <lastmod>2024-01-09T21:43:16.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect_Known_RAT_RMM_Process_Patterns&amp;clr6isyqv001dmc0qfz2p08jz</loc>
    <lastmod>2024-01-09T15:42:30.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WebshellDetection&amp;clr5g7czw000omc0q5ejnelm1</loc>
    <lastmod>2024-01-08T21:41:57.259Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XdrAlertsRelatedCiemAssessment&amp;clr4247a500g1mc0p50bydsu9</loc>
    <lastmod>2024-01-07T22:19:48.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AttackPathsRelatedSecurityAlerts&amp;clr42410t00g0mc0p5vx1zafk</loc>
    <lastmod>2024-01-07T22:19:40.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialAiTMPhishing&amp;clr41yt5w00fzmc0p26bon8bc</loc>
    <lastmod>2024-01-07T22:15:37.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/weird%20CorrelationId&amp;clqzerecg00d2mc0pvxnck3km</loc>
    <lastmod>2024-01-04T16:14:55.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Container%20registries%20MDVM%20vulnerability%20assessments&amp;clqxzb3ba00c5mc0pipavvo7e</loc>
    <lastmod>2024-01-03T16:14:34.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommandlineWithClearTextPassword&amp;clqwwsdd200bgmc0plbakqf9t</loc>
    <lastmod>2024-01-02T22:16:15.781Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQLQueryVisits&amp;clqrwqpk0008bmc0p42gbjugc</loc>
    <lastmod>2023-12-30T10:16:07.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KQLSearchVisits&amp;clqqu6cvf007mmc0pi31zmmp2</loc>
    <lastmod>2023-12-29T16:16:32.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityNestedRecommendation-Running%20container%20image%20MDVM%20vulnerability%20assessments&amp;clqqu38f4007lmc0p3am58a8c</loc>
    <lastmod>2023-12-29T16:14:06.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsEmojiReactionsByDepartment&amp;clqp1vjb1006gmc0pebzz1x5b</loc>
    <lastmod>2023-12-28T10:16:32.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/applicaitonshimming&amp;clqnzetpg005rmc0pb3vhqc8o</loc>
    <lastmod>2023-12-27T16:19:47.043Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsEmojiReactions&amp;clqnzaac0005qmc0p1wbzx4z3</loc>
    <lastmod>2023-12-27T16:16:15.311Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Logon%20activity%20from%20a%20potentially%20harmful%20application&amp;clqmjrdc8004tmc0p0fb6wqpe</loc>
    <lastmod>2023-12-26T16:13:52.187Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/changing-powershell-execution-policy-to-insecure-level&amp;clqjc6g3q002smc0pxzlh8tja</loc>
    <lastmod>2023-12-24T10:18:20.294Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ExposureLevels&amp;clqjc40p3002rmc0ps7dbadjv</loc>
    <lastmod>2023-12-24T10:16:27.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevicesCanBeOnboarded&amp;clqi9ik5t0022mc0pt0r7utet</loc>
    <lastmod>2023-12-23T16:16:00.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance%20-%20Intune%20devices%20that%20are%20compliant%20with%20OS%2C%20OS%20Version&amp;clqi920p9001tmc0p2u2uyexh</loc>
    <lastmod>2023-12-23T16:03:08.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OnboardedDeviceByOS&amp;clqi79xr300005izk7jnijn1t</loc>
    <lastmod>2023-12-23T15:13:18.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/sdcltUAC&amp;clqfqsjc3001k5i48etc8vd02</loc>
    <lastmod>2023-12-21T21:56:20.835Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DLLhostUAC&amp;clqfqshkk001i5i48jli88ooo</loc>
    <lastmod>2023-12-21T21:56:18.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Clipup&amp;clqfqsfdq001g5i4815gkubob</loc>
    <lastmod>2023-12-21T21:56:15.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ChangePKSLUITampering&amp;clqfqsdtf001e5i48hhme65tn</loc>
    <lastmod>2023-12-21T21:56:13.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Getsystem&amp;clqfqsb9k001c5i48vvd4j8cr</loc>
    <lastmod>2023-12-21T21:56:10.376Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/tempexecutions&amp;clqfqs98g001a5i482r7ufc04</loc>
    <lastmod>2023-12-21T21:56:07.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/osascriptpassword&amp;clqfqs72e00185i48ds3tohzp</loc>
    <lastmod>2023-12-21T21:56:04.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/libraryexecutions&amp;clqfqs5ne00165i48arsvyfoq</loc>
    <lastmod>2023-12-21T21:56:03.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/copytmptousers&amp;clqfqs2w800145i48xvdxuos3</loc>
    <lastmod>2023-12-21T21:55:59.520Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/chainbreaker&amp;clqfqs0qd00125i482e7bvdpf</loc>
    <lastmod>2023-12-21T21:55:56.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/configfile&amp;clqfqrypk00105i480tfk1ezm</loc>
    <lastmod>2023-12-21T21:55:54.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RcloneMSThreatReport&amp;clqfqrw86000y5i48xm7qccuy</loc>
    <lastmod>2023-12-21T21:55:50.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FileProperties&amp;clqfqrsp5000w5i48rc087ubl</loc>
    <lastmod>2023-12-21T21:55:46.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/gpresult&amp;clqfqrr3s000u5i48dfypcxoy</loc>
    <lastmod>2023-12-21T21:55:44.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WebdavExecution&amp;clqfqrnpb000s5i488oo0buxz</loc>
    <lastmod>2023-12-21T21:55:39.839Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccesfullExploitationofPDFreaders&amp;clqfqrld4000q5i48lwn2fr3k</loc>
    <lastmod>2023-12-21T21:55:36.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowershellSuspiciousStrings&amp;clqfqrdkv000o5i48rlv4ynno</loc>
    <lastmod>2023-12-21T21:55:26.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OneNoteZeroday&amp;clqfqra1s000m5i484jqfaqku</loc>
    <lastmod>2023-12-21T21:55:22.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MicrosoftWorkflowCompiler&amp;clqfqr6b2000k5i48j1vxdamp</loc>
    <lastmod>2023-12-21T21:55:17.293Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailAttachmentExecuted&amp;clqfqr49c000i5i48stqndcpl</loc>
    <lastmod>2023-12-21T21:55:14.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CSCSuspiciousExecutions&amp;clqfqr0hw000g5i4877sswm8h</loc>
    <lastmod>2023-12-21T21:55:09.756Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EnumerationShortperiod&amp;clqfqqx9i000e5i48k4pngc2o</loc>
    <lastmod>2023-12-21T21:55:05.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderLocalOverride&amp;clqfqqu1c000c5i48q7rul9ns</loc>
    <lastmod>2023-12-21T21:55:01.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NTDSDump&amp;clqfqqrnv000a5i48c3kt07uk</loc>
    <lastmod>2023-12-21T21:54:58.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Msbuild&amp;clqfqqo9300085i488fm2y4ue</loc>
    <lastmod>2023-12-21T21:54:53.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WinrarEncryption&amp;clqfqqlsu00065i48gs186hbs</loc>
    <lastmod>2023-12-21T21:54:50.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Telegraminfostealers&amp;clqfqqjbc00045i48wx04is7j</loc>
    <lastmod>2023-12-21T21:54:47.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousNSLookup&amp;clqfqqfv900025i48hvlnq3jv</loc>
    <lastmod>2023-12-21T21:54:43.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PlinkTunnelingForwarding&amp;clqfqqdnl00005i48kvvqt2eu</loc>
    <lastmod>2023-12-21T21:54:40.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-Automatically%20forwarded%20emails&amp;clqflxxsj022gmc0o34c6aatp</loc>
    <lastmod>2023-12-21T19:40:34.629Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/STORM-0539%20URLPathsEmail&amp;clqcr5om0020nmc0ohjr7ajia</loc>
    <lastmod>2023-12-19T19:43:15.671Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Usage-CloudAppEvents&amp;clqbolptj01zymc0okzw5se7t</loc>
    <lastmod>2023-12-19T01:43:58.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDRAutomaticallyClosedIncidents&amp;clqbbq2et01zpmc0oborjqsc7</loc>
    <lastmod>2023-12-18T19:43:26.502Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Added%20Credential%20to%20privileged%20workload%20by%20lower%20or%20non-privileged%20user%20(WorkloadIdentityInfo)&amp;clqayz8h501zgmc0owd3ycq9p</loc>
    <lastmod>2023-12-18T13:46:39.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-how-quick-a-confirmed-compromised-account-changed-password&amp;clq6ommko01wrmc0odc27mq47</loc>
    <lastmod>2023-12-15T13:45:50.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identification-of-risky-users-risk-dismissal-or-account-compromised-confirmation&amp;clq59ie1601vumc0oxe5mtq5v</loc>
    <lastmod>2023-12-14T13:54:52.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_UrlClickEvents&amp;clq59bloy01vtmc0obyuep6tk</loc>
    <lastmod>2023-12-14T13:49:35.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_UrlClickEvents&amp;clq59b85001vsmc0osrq3evop</loc>
    <lastmod>2023-12-14T13:49:17.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AppServiceIPSecAuditLogs&amp;clq59asap01vrmc0ob3e3misn</loc>
    <lastmod>2023-12-14T13:48:57.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AppServiceAuditLogs&amp;clq59air901vqmc0ojgo3035g</loc>
    <lastmod>2023-12-14T13:48:44.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_UrlClickEvents&amp;clq59a42m01vpmc0o2bn04o6s</loc>
    <lastmod>2023-12-14T13:48:25.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Kubernetes_legacy&amp;clq4w6ztq01vgmc0ov1mcbirh</loc>
    <lastmod>2023-12-14T07:42:05.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Key_Vault_legacy&amp;clq4w6o4501vfmc0oh2ek8rye</loc>
    <lastmod>2023-12-14T07:41:50.215Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Firewall_legacy&amp;clq4w54w701vemc0osx41jweo</loc>
    <lastmod>2023-12-14T07:40:38.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NetQueryStatistics&amp;clq21c0lb01tlmc0ojbuc8g3q</loc>
    <lastmod>2023-12-12T07:42:39.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NetDiscoveryActivitiesDetected&amp;clq1bmge701t4mc0o8my35ghf</loc>
    <lastmod>2023-12-11T19:42:56.380Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RareNetParamaterExecutions&amp;clpzjau4b01rzmc0ozgmo3ug6</loc>
    <lastmod>2023-12-10T13:42:18.874Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20Threat%20detection%20policy%20for%20OAuth%20Apps%20with%20Enriched%20Information%20(WorkloadIdentityInfo)&amp;clpy3z2sy01r2mc0oqx64biry</loc>
    <lastmod>2023-12-09T13:45:29.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalGroupDiscovery&amp;clpxe51ud01qlmc0obn48v8l2</loc>
    <lastmod>2023-12-09T01:42:18.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NetDiscoveryActivities&amp;clpvlvu7o01pgmc0otyqtmo9d</loc>
    <lastmod>2023-12-07T19:43:33.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS_SuspiciousCommandEC2&amp;clpvlsd9r01pfmc0o3x9pn7zz</loc>
    <lastmod>2023-12-07T19:40:51.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS_SAMLUpdateIdentity&amp;clpvls6q801pemc0o4836wt6d</loc>
    <lastmod>2023-12-07T19:40:42.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20DigitalSideDomains&amp;clpu6g5oa01ohmc0o7gcjq1we</loc>
    <lastmod>2023-12-06T19:43:41.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20DigitalSideIPs&amp;clpt3v30201nsmc0o97wmbnw5</loc>
    <lastmod>2023-12-06T01:43:32.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Strcat&amp;clpsr5qax01njmc0ojgv3v1h1</loc>
    <lastmod>2023-12-05T19:47:54.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IncidentURL&amp;clpsqrpc501nimc0oyauqy6gj</loc>
    <lastmod>2023-12-05T19:36:59.766Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DueDatePassedCISAKnownExploitedVulnerability&amp;clprbkule01mlmc0oa8ceotvm</loc>
    <lastmod>2023-12-04T19:43:59.712Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LatestAntivirusScanStatus&amp;clpne209f01k4mc0ouq2fhapm</loc>
    <lastmod>2023-12-02T01:42:14.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS_RDSInstancePubliclyExposed&amp;clpmo9sn301jnmc0ouria8w3h</loc>
    <lastmod>2023-12-01T13:40:28.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS_NetworkACLOpenToAllPorts&amp;clpmo9ois01jmmc0ok6jfe178</loc>
    <lastmod>2023-12-01T13:40:22.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Suspicious%20AD%20attributes%20accessed%20from%20unexpected%20source&amp;clpllofiw01ixmc0o8itx2ygb</loc>
    <lastmod>2023-11-30T19:40:05.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListCISAExploitedVulnerabilites&amp;clpkw21sa01igmc0o485tj0ym</loc>
    <lastmod>2023-11-30T07:42:51.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewActiveCISAKnownExploitedVulnerabilityDetected&amp;clpk6daeb01hzmc0opappa8gu</loc>
    <lastmod>2023-11-29T19:43:45.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behaviour%20-%20KillSQLProcesses&amp;clphobp2w01gemc0oso41l1mm</loc>
    <lastmod>2023-11-28T01:43:05.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/detecting-rmm-tools-using-processversioninfocompanymame-table&amp;clpgyq6nv01fzmc0ob927u28v</loc>
    <lastmod>2023-11-27T13:46:31.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WevtutilClearLogs&amp;clpblomfu01cmmc0oprt2qgzp</loc>
    <lastmod>2023-11-23T19:42:32.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-ReleaseQuarantine&amp;clpb8wxqk01cdmc0ofrbc2nw6</loc>
    <lastmod>2023-11-23T13:45:05.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-Email%20Attachment%20File%20Extensions&amp;clpb8wse301ccmc0o0knv9qwo</loc>
    <lastmod>2023-11-23T13:44:58.924Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-AuthenticationDetails&amp;clpb8wa9001cbmc0o33e1bp0b</loc>
    <lastmod>2023-11-23T13:44:35.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20TVM%20-%20eIOT&amp;clpb8w0nf01camc0o7phkv3ic</loc>
    <lastmod>2023-11-23T13:44:23.114Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphMailPermissions&amp;clpa68m5501blmc0on2ppvedk</loc>
    <lastmod>2023-11-22T19:42:25.816Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TotalAllGraphPermissionsAdded&amp;clp8qsvz001aomc0o535y4f9w</loc>
    <lastmod>2023-11-21T19:42:31.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Token%20Replay%20from%20workload%20identity%20with%20privileges%20in%20Microsoft%20Azure%20(WorkloadIdentityInfo)&amp;clp7bj9uz019tmc0o16gwgy4z</loc>
    <lastmod>2023-11-20T19:47:22.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Token%20Replay%20from%20workload%20identity%20with%20privileges%20in%20Microsoft%20365%20(WorkloadIdentityInfo)&amp;clp7bj08t019smc0otbmj9k0n</loc>
    <lastmod>2023-11-20T19:47:10.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20Threat%20detection%20policy%20with%20Enriched%20Information%20(WorkloadIdentityInfo)&amp;clp7biutt019rmc0opdi3gq3s</loc>
    <lastmod>2023-11-20T19:47:03.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AllGraphPermissionsAdded&amp;clp7bd7vw019qmc0oz7ky3uur</loc>
    <lastmod>2023-11-20T19:42:40.170Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RecentAddedPrivileges&amp;clp5w3b15018tmc0ojvrha3o1</loc>
    <lastmod>2023-11-19T19:47:17.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Added%20Ownership%20to%20workload%20identity%20(WorkloadIdentityInfo)&amp;clp5w2y8a018smc0o8yxa112h</loc>
    <lastmod>2023-11-19T19:47:00.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Added%20Credential%20to%20privileged%20workload%20by%20lower%20or%20non-privileged%20user%20(WorkloadIdentityInfo&amp;clp5w2pu2018rmc0ong3qfveq</loc>
    <lastmod>2023-11-19T19:46:49.659Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnifiedIdentityInfo&amp;clp4gm5ks017umc0orofdez6f</loc>
    <lastmod>2023-11-18T19:46:16.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrivilegedWorkloadIdentityInfo&amp;clp4glzbs017tmc0o93d12mb4</loc>
    <lastmod>2023-11-18T19:46:08.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrivilegedIdentityInfo&amp;clp4glscf017smc0ocaqpk7id</loc>
    <lastmod>2023-11-18T19:45:59.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/detect-inbound-email-domains-from-text-list&amp;clp3e1inq0173mc0o2028tmti</loc>
    <lastmod>2023-11-18T01:46:28.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInsByBrowser&amp;clp1lls0b015ymc0o03e3e8tu</loc>
    <lastmod>2023-11-16T19:42:38.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderDiscoveryActivities&amp;clp06744s0151mc0ogrrxq51o</loc>
    <lastmod>2023-11-15T19:43:33.918Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/replace_strings%20malfunction&amp;clp064va30150mc0ougflhd3x</loc>
    <lastmod>2023-11-15T19:41:49.132Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20user%20agent%20in%20Microsoft%20Graph&amp;clp06388y014zmc0owb7hcinh</loc>
    <lastmod>2023-11-15T19:40:32.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20enumeration%20in%20Microsoft%20Graph&amp;clp0633ku014ymc0oatpob9qv</loc>
    <lastmod>2023-11-15T19:40:26.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LOLBinRemoteIPCommandLine&amp;cloyqqq3d0141mc0od5yuzhws</loc>
    <lastmod>2023-11-14T19:43:08.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TooManyRecipients&amp;cloxb3lbo0134mc0orerdcn7m</loc>
    <lastmod>2023-11-13T19:37:29.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Workload%20ID%20Protection%20Alerts%20with%20Enriched%20Information&amp;clovj30y70121mc0o49iogdmf</loc>
    <lastmod>2023-11-12T13:45:27.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UEBA%20Behavior%20anomaly%20on%20Application%20Management&amp;clovj2tva0120mc0oxu3fc7qr</loc>
    <lastmod>2023-11-12T13:45:18.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDA%20App%20Governance%20Alerts%20with%20Enriched%20Information&amp;clovj2lwh011zmc0o2hbkevhn</loc>
    <lastmod>2023-11-12T13:45:07.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ComparisonIntuneandMDEDevices&amp;clougdty1011amc0ostragepu</loc>
    <lastmod>2023-11-11T19:42:06.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkloadIdentityInfo_EnrichedByEntraOps&amp;clou3n3er0111mc0of8x5e9uo</loc>
    <lastmod>2023-11-11T13:45:23.571Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzADSPI_EnrichedByEntraOps&amp;clou3mwqx0110mc0o9pgety8v</loc>
    <lastmod>2023-11-11T13:45:15.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzADSPI&amp;clou3mrho010zmc0ojuiu6hk4</loc>
    <lastmod>2023-11-11T13:45:08.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AllPrivilegedIdentityInfo&amp;clou3mm38010ymc0o65ls07yz</loc>
    <lastmod>2023-11-11T13:45:01.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20DailyTableEvents&amp;cloq6358h00yhmc0o6zm3aguy</loc>
    <lastmod>2023-11-08T19:42:47.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20Email%20-%20PhishDetectionReasons&amp;clono1wrd00wymc0o4ekp9ddt</loc>
    <lastmod>2023-11-07T01:42:23.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20Email%20-%20MalwareDetectionReasons&amp;clono1qp800wxmc0ote536s0o</loc>
    <lastmod>2023-11-07T01:42:16.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KerberosUnusualProcess&amp;clonbmvvk00womc0oykz3lpq9</loc>
    <lastmod>2023-11-06T19:54:47.647Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rare_Outgoing_IPv4_Connections&amp;clolivh0a00vnmc0ovb7ser0t</loc>
    <lastmod>2023-11-05T13:41:53.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OutboundConhostConnection&amp;clokgai4n00uymc0obivfuo2h</loc>
    <lastmod>2023-11-04T19:41:49.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20PotentialPhishingCampaign&amp;cloj0vr7l00u1mc0o6utrk61s</loc>
    <lastmod>2023-11-03T19:42:41.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Networkaddresses-Parser&amp;clohyczoz00temc0oke5zr3mz</loc>
    <lastmod>2023-11-03T01:44:20.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mail%20Sending%20Limit%20exceeded&amp;clohycs8d00tdmc0o2jgara63</loc>
    <lastmod>2023-11-03T01:44:10.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO%20-%20AuthenticationDetails&amp;clohyciyj00tcmc0oy633fqmx</loc>
    <lastmod>2023-11-03T01:43:58.458Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-FirewallConfiguration&amp;clohyc1fp00tbmc0oclflc11x</loc>
    <lastmod>2023-11-03T01:43:35.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-UserRiskOnPremisePasswordChange&amp;clohybu9800tamc0o7zpaltyf</loc>
    <lastmod>2023-11-03T01:43:26.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-AccessReviews&amp;clohybn9500t9mc0oh3b11aow</loc>
    <lastmod>2023-11-03T01:43:17.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO-%20FindRelatedMails&amp;clohy9lwy00t8mc0obqh2ez5u</loc>
    <lastmod>2023-11-03T01:41:42.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalAdminAdditions&amp;clodb3ugc00qdmc0ocmvh74jt</loc>
    <lastmod>2023-10-30T19:42:17.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/suspicious-commands-hunting-to-remove-files&amp;clob60axy00p6mc0oyo19k4u2</loc>
    <lastmod>2023-10-29T07:44:01.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrivilegedIdentities&amp;cloago08x00opmc0o2nepjqyi</loc>
    <lastmod>2023-10-28T19:54:37.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzADSPI&amp;cloa3giji00oimc0oir8tnqoz</loc>
    <lastmod>2023-10-28T13:44:53.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalGroupCreation&amp;clo9qh6o600o9mc0o7lac61cw</loc>
    <lastmod>2023-10-28T07:41:29.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/USBConnectors&amp;clo8nxm7x00nmmc0ojepcacak</loc>
    <lastmod>2023-10-27T13:42:31.100Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulSignInFromNewCountry&amp;clo6j34yl00m9mc0o9nu9tw5r</loc>
    <lastmod>2023-10-26T01:51:18.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS_OverlyPermessiveKMS&amp;clo65tpel00m2mc0obdwxach1</loc>
    <lastmod>2023-10-25T19:40:03.164Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-Overly%20permissive%20AWS%20IAM%20policy&amp;clo65t5ff00m1mc0o1d4d1glt</loc>
    <lastmod>2023-10-25T19:39:37.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20disabled%20Python%20Excel%20warning%20for%20executing%20untrusted%20code&amp;clo63tmk500025i6wq3qv3rh3</loc>
    <lastmod>2023-10-25T18:44:00.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindDuplicateGuestAccount&amp;clo63thu200005i6w5z1zqfr1</loc>
    <lastmod>2023-10-25T18:43:54.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/What%20Users%20Downloaded%20From%20The%20Internet&amp;clo63cjpi00025iwwdmgzb067</loc>
    <lastmod>2023-10-25T18:30:43.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cloud%20Discovery%20Performed%20by%20User%20at%20Risk&amp;clo63cf6200005iwwt3b84xyk</loc>
    <lastmod>2023-10-25T18:30:37.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Curl-CVE-2023-38545%20-%20Devices%20not%20updated%20Yet&amp;clo60cy8800025ijo5nxxf15l</loc>
    <lastmod>2023-10-25T17:07:03.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CobaltStrike%20C2&amp;clo60cue900005ijoivj3c6at</loc>
    <lastmod>2023-10-25T17:06:58.400Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatHunt-SuspiciousUserAgents&amp;clo5zt8dg00005ick9qtnug2p</loc>
    <lastmod>2023-10-25T16:51:43.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20logging%20modified&amp;clo5syeqk00lsmc0o3yovuyfa</loc>
    <lastmod>2023-10-25T13:39:47.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20GuardDuty%20configuration%20modified&amp;clo5sy9nq00lrmc0oq825suyq</loc>
    <lastmod>2023-10-25T13:39:41.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConnectedPnPTypes&amp;clo4qh6kl00l2mc0ozjn211kc</loc>
    <lastmod>2023-10-24T19:42:38.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccess%20-%20ChangePolicy&amp;clo3b0q3z00k5mc0o141mzmjl</loc>
    <lastmod>2023-10-23T19:42:10.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccess%20-%20AddPolicy&amp;clo3b0kwb00k4mc0o44e1z3y1</loc>
    <lastmod>2023-10-23T19:42:03.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccess%20-%20UserFailures&amp;clo1ioku100izmc0o2084vmfr</loc>
    <lastmod>2023-10-22T13:41:08.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccess%20-%20ApplicationFailures&amp;clnz0op4h00hemc0ovvf7a4b2</loc>
    <lastmod>2023-10-20T19:41:48.208Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphRunnerReconnaissanceDetected&amp;clnyb1rw100gxmc0oyxjl4rq8</loc>
    <lastmod>2023-10-20T07:44:08.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccess%20-%20DeletePolicy&amp;clnxl94hi00gomc0o2z7pjgmk</loc>
    <lastmod>2023-10-19T19:42:01.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ConditionalAccess%20-%20SignInFailures&amp;clnw5t5sm00frmc0o0mg8zrbl</loc>
    <lastmod>2023-10-18T19:41:55.989Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-KnownRansomwareVuln&amp;clnvsn28r00famc0o9i2f4ljk</loc>
    <lastmod>2023-10-18T13:33:16.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MostExploitedVulnerabilities2022&amp;clntaz56f00dxmc0oh6k8jpoe</loc>
    <lastmod>2023-10-16T19:43:14.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GraphActivityFromOtherIpAddress&amp;clnriqmpo00csmc0obfrubsko</loc>
    <lastmod>2023-10-15T13:45:01.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureActivityFromOtherIpAddress&amp;clnriqgxr00crmc0oubrdcj4h</loc>
    <lastmod>2023-10-15T13:44:54.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IndicatorOfTokenReplay_SignInActivityOutsideOfMdeDeviceIPAddresses&amp;clnriq9rv00cqmc0o3yl1sbv5</loc>
    <lastmod>2023-10-15T13:44:45.165Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DirectoryRoleMemberWithClassification&amp;clnriq3zs00cpmc0o60np8in1</loc>
    <lastmod>2023-10-15T13:44:37.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureActivityOutsideOfClassifiedPrivileges&amp;clnripzsr00comc0oh6d5359l</loc>
    <lastmod>2023-10-15T13:44:32.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddedAppRolesWithClassification&amp;clnripwb700cnmc0o7jqk436r</loc>
    <lastmod>2023-10-15T13:44:27.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PurpleKnightReconnaissanceDetected&amp;clnq38o9a00bqmc0o7v8xx1sm</loc>
    <lastmod>2023-10-14T13:43:23.712Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureHoundReconnaissanceDetected&amp;clnq38g3h00bpmc0ox2m3uaw7</loc>
    <lastmod>2023-10-14T13:43:13.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureHoundActivityDetected&amp;clnq38bfp00bomc0ooweontz8</loc>
    <lastmod>2023-10-14T13:43:07.236Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-AzureAADPowerShellAnomaly&amp;clnkddrqq0083mc0orbvmeny4</loc>
    <lastmod>2023-10-10T13:40:40.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectInvalidCertificates&amp;clnk08pak007mmc0oo7ep19lo</loc>
    <lastmod>2023-10-10T07:32:49.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Curl-CVE-2023-38545&amp;clnjavp0d007dmc0o4ohwap7q</loc>
    <lastmod>2023-10-09T19:42:51.848Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EntraID%20-%20SignInsByCompromisedAccount&amp;clnjaua1z007cmc0o1pp5pv8m</loc>
    <lastmod>2023-10-09T19:41:45.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SingleFactorAuthenticationSignInUsingPasswordDetected&amp;clngg0x16005lmc0og7a6ucwy</loc>
    <lastmod>2023-10-07T19:43:35.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-SensitiveIdentityLogins&amp;clndlj7ah003smc0o9262jnce</loc>
    <lastmod>2023-10-05T19:54:27.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI-AttackDisruption&amp;clndlj27v003rmc0ota78e9h4</loc>
    <lastmod>2023-10-05T19:54:21.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Inactive-ADActive&amp;clndlip0n003qmc0osfthgxke</loc>
    <lastmod>2023-10-05T19:54:04.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Detection-Removal%20and%20Quarantine%20actions&amp;clndlii94003pmc0oc0veu6kb</loc>
    <lastmod>2023-10-05T19:53:55.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceControl&amp;clndlibaz003omc0oe6a8j5u8</loc>
    <lastmod>2023-10-05T19:53:46.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Activity%20from%20a%20Tor%20IP%20address&amp;clndle2p1003nmc0ortz42egt</loc>
    <lastmod>2023-10-05T19:50:28.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Running%20container%20image%20MDVM%20vulnerability%20assessments&amp;clnd874kk003gmc0oetl14jsr</loc>
    <lastmod>2023-10-05T13:41:09.474Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectionTemplate&amp;clnc5o7mc002rmc0o7r4waudd</loc>
    <lastmod>2023-10-04T19:42:41.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Running%20container%20image%20Qualys%20vulnerability%20assessments&amp;clnc5lcic002qmc0o714kragd</loc>
    <lastmod>2023-10-04T19:40:27.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/recently-received-emails-with-phishing-related-subject-keywords&amp;clnbsyq3v002hmc0o0zbz7eas</loc>
    <lastmod>2023-10-04T13:46:57.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Virtual%20machines%20MDVM%20vulnerability%20assessments&amp;clnbsrz65002gmc0o58746wr5</loc>
    <lastmod>2023-10-04T13:41:42.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Container%20registry%20image%20MDVM%20vulnerability%20assessments&amp;clnbsrsg2002fmc0o5q8759vd</loc>
    <lastmod>2023-10-04T13:41:33.357Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/review-recent-urlclick-events&amp;clnadib3i001imc0ozrd682z9</loc>
    <lastmod>2023-10-03T13:46:30.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/recently-received-emails-with-attachments&amp;clnadi2kl001hmc0osg0nmqou</loc>
    <lastmod>2023-10-03T13:46:19.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/delivered-emails-identified-as-suspicious&amp;clnadhwsn001gmc0oc0zjpg2g</loc>
    <lastmod>2023-10-03T13:46:12.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListEntraIDSignIns&amp;clna0i2tr0017mc0o95l3izbl</loc>
    <lastmod>2023-10-03T07:42:24.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ImageFiles&amp;cln9nf0ex000ymc0o581jj5oj</loc>
    <lastmod>2023-10-03T01:36:06.872Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MontySecurity%20C2%20Tracker%20All%20IPs&amp;cln9asbt6000pmc0ov4f6lxyb</loc>
    <lastmod>2023-10-02T19:42:33.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MultipleTablesNoIngest&amp;cln9akn3m000omc0o5rkrl9yh</loc>
    <lastmod>2023-10-02T19:36:34.397Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/User%20elevated%20to%20User%20Access%20Administrator&amp;cln8x70d300025id06mmgu41w</loc>
    <lastmod>2023-10-02T13:22:03.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Detect%20Inbound%20Phish%20With%20Base64%20Encoded%20Receipient&amp;cln8x6vxv00005id03aajvx80</loc>
    <lastmod>2023-10-02T13:21:57.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/find_new_usb_mount&amp;cln674755009mmc0ohkhlv3uw</loc>
    <lastmod>2023-09-30T15:36:29.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IncidentsOfEntitiesInMDCAttackPaths&amp;cln4hqpdx001k5i0o2ckhkzkv</loc>
    <lastmod>2023-09-29T10:58:23.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzRbacAssignmentsOfRiskyUser&amp;cln4hqdu5001j5i0ovg1x41e8</loc>
    <lastmod>2023-09-29T10:58:08.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SensitiveServicePrincipalsAzADSPI&amp;cln4hq33b001i5i0o6ox8jye5</loc>
    <lastmod>2023-09-29T10:57:54.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewCredentialAddedToSensitiveSP&amp;cln4hpxla001h5i0oj1tdis63</loc>
    <lastmod>2023-09-29T10:57:47.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuthenticationLibraries&amp;cln4hoxqh001g5i0onhpzn87s</loc>
    <lastmod>2023-09-29T10:57:01.384Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddedSensitiveApiPermissions&amp;cln4hor4n001f5i0osz15jgoz</loc>
    <lastmod>2023-09-29T10:56:52.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddedOwnerToApplicationForUnprivileged&amp;cln4hockn001e5i0ol6t8j7jr</loc>
    <lastmod>2023-09-29T10:56:33.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddedOwnerToApplicationByUnprivileged&amp;cln4ho1fu001d5i0ob9l6l9xr</loc>
    <lastmod>2023-09-29T10:56:19.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Indicator%20of%20Token%20Replay%20-%20Sign-in%20Activity%20outside%20of%20MDE%20Device%20IP%20Addresses&amp;cln4hntqa001c5i0ot1shwakf</loc>
    <lastmod>2023-09-29T10:56:09.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Activity%20outside%20of%20Classified%20Privileges&amp;cln4hnkc2001b5i0oi67dhy4a</loc>
    <lastmod>2023-09-29T10:55:57.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuthTokenIssuer&amp;cln4hnb5o001a5i0oromfooh6</loc>
    <lastmod>2023-09-29T10:55:45.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuthMethods-Windows-Signin&amp;cln4hn4v400195i0o1ijp8te1</loc>
    <lastmod>2023-09-29T10:55:37.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RepoVisibilityChangeToPublic&amp;cln4hmxkv00185i0osnvg75gf</loc>
    <lastmod>2023-09-29T10:55:27.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PullRequestPolicyByPass&amp;cln4hka4x00175i0ow9q0b6hm</loc>
    <lastmod>2023-09-29T10:53:24.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewWorkflowUsingSecrets&amp;cln4hjz3n00165i0o25cwxkqf</loc>
    <lastmod>2023-09-29T10:53:09.875Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/InvitedOutsideCollabsAsOwner&amp;cln4h9rcs00155i0ovdufns7z</loc>
    <lastmod>2023-09-29T10:45:13.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GitHubOrgSensitiveChangeActions&amp;cln4h9l7e00145i0opuu9ldoy</loc>
    <lastmod>2023-09-29T10:45:05.297Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GitHubAppAddedToOrg&amp;cln4h9cc000135i0ol6nmcssc</loc>
    <lastmod>2023-09-29T10:44:53.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FedCredIssuedRepoSensitiveAction&amp;cln4h94lz00125i0olzoqmhj8</loc>
    <lastmod>2023-09-29T10:44:43.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FedCredCreatedForUnknownEntity&amp;cln4h8sp100115i0omf7f71kb</loc>
    <lastmod>2023-09-29T10:44:28.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FedCredAzActivityWithoutSignInWorkflow&amp;cln4h8jpx00105i0opr1fdsv5</loc>
    <lastmod>2023-09-29T10:44:16.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FedCredAuthFromNewWorkflow&amp;cln4h875f000z5i0oce7cyh35</loc>
    <lastmod>2023-09-29T10:44:00.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Update%20of%20Authentication%20Methods%20Policy&amp;cln4h7v1b000y5i0oafsbdgqm</loc>
    <lastmod>2023-09-29T10:43:44.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Registration%20of%20TAP%20by%20admin%20after%20successful%20strong%20authentication%20from%20user&amp;cln4h7mw9000x5i0o7f97t1b7</loc>
    <lastmod>2023-09-29T10:43:34.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Blocked%20sign-in%20by%20User%20Credential%20Policy%20with%20TAP%20outside%20of%20the%20Authentication%20Methods%20Policy&amp;cln4h7crw000w5i0oxkmxwb7f</loc>
    <lastmod>2023-09-29T10:43:21.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousSSPRActivity&amp;cln4h71zs000v5i0oz3nfmvba</loc>
    <lastmod>2023-09-29T10:43:07.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BlockingSSPRAttempts&amp;cln4h6peg000t5i0ozz6uca5i</loc>
    <lastmod>2023-09-29T10:42:50.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WriteClassicAdministratorsOfAzSubscription&amp;cln4h6hkv000r5i0o6zw0hr26</loc>
    <lastmod>2023-09-29T10:42:40.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInFromExternalPrivilegedUserWithoutMFAClaim&amp;cln4h69to000p5i0oxb4qbhe4</loc>
    <lastmod>2023-09-29T10:42:30.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RiskySignInToAzurePortal&amp;cln4h61mk000o5i0oh5n2h4op</loc>
    <lastmod>2023-09-29T10:42:19.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ResetMFAAuthCredByAdmin&amp;cln4h5qy6000m5i0o7ueq6npe</loc>
    <lastmod>2023-09-29T10:42:06.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NonePasswordlessAuthenticationFromPrivilegedIdentities&amp;cln4h5h0m000k5i0ojeweri8r</loc>
    <lastmod>2023-09-29T10:41:53.246Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ElevatedGAforAzureManagement&amp;cln4h56ht000i5i0oxbo7h5o1</loc>
    <lastmod>2023-09-29T10:41:39.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureRbacAssignmentManagementGroup&amp;cln4h4ytx000g5i0o6wh8ii6k</loc>
    <lastmod>2023-09-29T10:41:29.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnusualAADConditionalAccessFailuresAfterPolicyChange&amp;cln4h4p47000e5i0oic94sufp</loc>
    <lastmod>2023-09-29T10:41:17.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnusualAADConditionalAccessFailures&amp;cln4h4en8000c5i0oygow5olj</loc>
    <lastmod>2023-09-29T10:41:03.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADConnectorAccount-OutsideOfWatchList&amp;cln4h42zx000a5i0oyzaa5kdx</loc>
    <lastmod>2023-09-29T10:40:48.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADConnectorAccount-AddedTAPorChangedPassword&amp;cln4h3qve00085i0ovl69dx4h</loc>
    <lastmod>2023-09-29T10:40:32.706Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADConnectorAccount-AADActivitiesWithEnrichedInformation&amp;cln4h3imu00065i0oy8q9ueiy</loc>
    <lastmod>2023-09-29T10:40:22.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADConnect-SignInsOutsideServerIP&amp;cln4h387100045i0oj65gzqhx</loc>
    <lastmod>2023-09-29T10:40:08.500Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADConnect-ChangedDirSyncSettings&amp;cln4h2v8200025i0od4t066ts</loc>
    <lastmod>2023-09-29T10:39:51.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ModifyAzDevOpsServiceConnectionRBAC&amp;cln4h2mlj00005i0opu33xphs</loc>
    <lastmod>2023-09-29T10:39:40.517Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ARG-LogStatusOfWindowsDevices&amp;cln2m57ka0079mc0ookhl8cj6</loc>
    <lastmod>2023-09-28T03:26:06.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20AccountsLongestPeriodWithoutPasswordReset&amp;cln29mhyj0078mc0o4db5v0om</loc>
    <lastmod>2023-09-27T21:35:38.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TopNAccountsLongestPeriodWithoutPasswordReset&amp;cln0u69zb006bmc0owqma056q</loc>
    <lastmod>2023-09-26T21:35:21.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/lumma-stealer-using-tesla-browser-useragent&amp;cln0h8lz60062mc0orjw72x21</loc>
    <lastmod>2023-09-26T15:33:14.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Container%20registry%20image%20Azure%20vulnerability%20assessments&amp;clmzehngj005dmc0olo08zp5c</loc>
    <lastmod>2023-09-25T21:28:31.602Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-UnifySignInLogs&amp;clmz1sukm0054mc0o4sbprpmm</loc>
    <lastmod>2023-09-25T15:33:19.033Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSGuardDutyAlert&amp;clmwjwgsp003jmc0ovu1d1xfq</loc>
    <lastmod>2023-09-23T21:36:42.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-LocalAccountCreated&amp;clmvu6amd0032mc0od89ah0dj</loc>
    <lastmod>2023-09-23T09:36:31.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DefenderAntivirusExclusions&amp;clmvu61mg0031mc0ooo623379</loc>
    <lastmod>2023-09-23T09:36:19.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-Groups&amp;clmvu5ouz0030mc0o8bpmbusk</loc>
    <lastmod>2023-09-23T09:36:02.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-BasicAuth&amp;clmvu5hdc002zmc0ob4vymqzn</loc>
    <lastmod>2023-09-23T09:35:53.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/QRPhishVictim&amp;clmv4i6i3002imc0owxc78klx</loc>
    <lastmod>2023-09-22T21:37:55.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListPublicIPs&amp;clmv4ei8t002hmc0ommq6646f</loc>
    <lastmod>2023-09-22T21:35:04.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureTagSearch&amp;clmtoy5jw001kmc0o2zens0je</loc>
    <lastmod>2023-09-21T21:34:40.795Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Playbook%20run%20failed&amp;clmtc3br7001bmc0ov26z4h7k</loc>
    <lastmod>2023-09-21T15:34:46.961Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/savingperworkbook&amp;clms9ql56000mmc0oh7s95lrw</loc>
    <lastmod>2023-09-20T21:41:07.337Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/threat-hunting-template&amp;clmrvyx2t00155inwopon7yn2</loc>
    <lastmod>2023-09-20T15:15:41.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/identify-mitreattack-techniques&amp;clmrvys7d00145inww9ayn38v</loc>
    <lastmod>2023-09-20T15:15:35.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/endpoints-associated-with-multiple-deviceids&amp;clmrvyltv00125inwkfwj1rl8</loc>
    <lastmod>2023-09-20T15:15:26.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/device-last-seen&amp;clmrvyh2s00105inw4ewo0n47</loc>
    <lastmod>2023-09-20T15:15:20.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/count-devices-based-on-osversion&amp;clmrvycdv000y5inwtjjcdwja</loc>
    <lastmod>2023-09-20T15:15:14.611Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/completed-av-scan&amp;clmrvy7ur000w5inwkm85yhg2</loc>
    <lastmod>2023-09-20T15:15:08.738Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ssl-inspection-for-malware-cnc&amp;clmrvy2pw000u5inwjtivkind</loc>
    <lastmod>2023-09-20T15:15:02.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/raspberry-robin-malware-cmd-invoking-msiexec&amp;clmrvxx0y000s5inwgoze42c3</loc>
    <lastmod>2023-09-20T15:14:54.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/onenote-invoking-browser-with-smartscreen-alert&amp;clmrvxsgl000q5inw6yshihg3</loc>
    <lastmod>2023-09-20T15:14:48.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/wscript-vbs-spawning-suspicious-processes&amp;clmrvxl0w000o5inwhfacapbr</loc>
    <lastmod>2023-09-20T15:14:39.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/screensaver-file-invoking-suspicious-processes&amp;clmrvxdqx000m5inwwv74nzf6</loc>
    <lastmod>2023-09-20T15:14:29.712Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/screensaver-file-invoking-internet-access&amp;clmrvx4si000k5inwynjkgo90</loc>
    <lastmod>2023-09-20T15:14:18.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/remcos-rat-checking-for-geolocation&amp;clmrvwyaa000i5inw3bu1c3nw</loc>
    <lastmod>2023-09-20T15:14:09.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/powershell-spawning-mshta-initiating-connection&amp;clmrvw7yx000g5inw7w4v39hl</loc>
    <lastmod>2023-09-20T15:13:35.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/powershell-base64-encoding&amp;clmrvw1id000e5inwpfu708rl</loc>
    <lastmod>2023-09-20T15:13:27.196Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/onenote-spawning-suspicious-processes&amp;clmrvvu2w000c5inwqzu1jmum</loc>
    <lastmod>2023-09-20T15:13:17.575Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/network-zipandmov-access&amp;clmrvvp7w000a5inwlvli3va6</loc>
    <lastmod>2023-09-20T15:13:11.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/dns-requests-to-suspicious-tlds&amp;clmrvvi7d00085inwm9bhuplb</loc>
    <lastmod>2023-09-20T15:13:02.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MOVEit-exploit-hunting&amp;clmrvvbn100065inwsqvi6unn</loc>
    <lastmod>2023-09-20T15:12:53.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2023-38831-winrar-spawning-cmd&amp;clmrvv3hl00045inwqvh3d7b5</loc>
    <lastmod>2023-09-20T15:12:43.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2023-36884-url-marker&amp;clmrvuwue00025inwnoc1fh49</loc>
    <lastmod>2023-09-20T15:12:34.493Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2023-36884-dropped-file&amp;clmrvupuz00005inw0xmr8xrs</loc>
    <lastmod>2023-09-20T15:12:25.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Container%20registry%20image%20Qualys%20Trivy%20vulnerability%20assessments&amp;clmqpya9k00v1mc0kczcmpa13</loc>
    <lastmod>2023-09-19T19:39:27.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/substitute%20json%20characters&amp;clmqd5kjv00usmc0kstyyk4z3</loc>
    <lastmod>2023-09-19T13:41:12.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20logins%20to%20user%20account&amp;clmqd54kk00urmc0kgagb1sdi</loc>
    <lastmod>2023-09-19T13:40:52.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-Activity%20with%20AWS%20break%20glass%20user&amp;clmqd3h3f00uqmc0koeb53lde</loc>
    <lastmod>2023-09-19T13:39:34.971Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_SmartScreen&amp;clmq0ewvq00uhmc0k6q6jtyni</loc>
    <lastmod>2023-09-19T07:44:33.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_Firewall&amp;clmq0enx300ugmc0kvyjf7f8p</loc>
    <lastmod>2023-09-19T07:44:22.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_ExploitGuard&amp;clmq0egf400ufmc0kid0zkqm9</loc>
    <lastmod>2023-09-19T07:44:12.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_Credential%20Guard&amp;clmq0e5pj00uemc0k0zx6otq0</loc>
    <lastmod>2023-09-19T07:43:58.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_BitLocker&amp;clmq0dwan00udmc0kkra48uj3</loc>
    <lastmod>2023-09-19T07:43:46.222Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_AppLicationGuard&amp;clmq0dmma00ucmc0km7rhh3lg</loc>
    <lastmod>2023-09-19T07:43:33.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_Antivirus_edr&amp;clmq0dgar00ubmc0kzav103zs</loc>
    <lastmod>2023-09-19T07:43:25.490Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-SecurityControls_ASR&amp;clmq0cedq00uamc0kns8aqh61</loc>
    <lastmod>2023-09-19T07:42:36.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-Network_NetworkProtection&amp;clmq0c56900u9mc0k1lgfcrkn</loc>
    <lastmod>2023-09-19T07:42:24.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-Accounts_LAPS&amp;clmq0bxhb00u8mc0kcrd8opxg</loc>
    <lastmod>2023-09-19T07:42:14.447Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-IngestionQuota&amp;clmpnh9h200tzmc0kem8regio</loc>
    <lastmod>2023-09-19T01:42:28.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-DataConnectorHealth&amp;clmpnh1s800tymc0kjn5lm1dy</loc>
    <lastmod>2023-09-19T01:42:18.295Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-AzureActivityDataConnectorCoverage&amp;clmpngskp00txmc0kn3kvkm4w</loc>
    <lastmod>2023-09-19T01:42:06.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-AutomationRulesPlaybooks&amp;clmpngnyb00twmc0k0g4en5n1</loc>
    <lastmod>2023-09-19T01:42:00.514Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-AnalyticRuleUpdates&amp;clmpngi1900tvmc0kmo1tvpcc</loc>
    <lastmod>2023-09-19T01:41:52.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/serversenrolledinWDATP&amp;clmp1vsmu00temc0ktarqywx5</loc>
    <lastmod>2023-09-18T15:37:54.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/scalarexpression&amp;clmp1vpb300tdmc0kdcoz3iil</loc>
    <lastmod>2023-09-18T15:37:50.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/qualys&amp;clmp1vlnq00tcmc0kwphdkb7n</loc>
    <lastmod>2023-09-18T15:37:45.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/multipleLAworkspaces&amp;clmp1vics00tbmc0knyu50wci</loc>
    <lastmod>2023-09-18T15:37:41.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/meraki_GROK&amp;clmp1vdpm00tamc0ktli6ubvl</loc>
    <lastmod>2023-09-18T15:37:35.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/maxoutputcolumns&amp;clmp1v8wc00t9mc0ka9zgbmh1</loc>
    <lastmod>2023-09-18T15:37:29.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/isempty&amp;clmp1v4xz00t8mc0k1zriky7c</loc>
    <lastmod>2023-09-18T15:37:24.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/heartbeatforscomagent&amp;clmp1v1bf00t7mc0k56p5576z</loc>
    <lastmod>2023-09-18T15:37:19.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/excessivefailedlogins&amp;clmp1uxcz00t6mc0key7ka1js</loc>
    <lastmod>2023-09-18T15:37:14.338Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/devices&amp;clmp1urtb00t5mc0kizvvjm0u</loc>
    <lastmod>2023-09-18T15:37:07.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/dataproviders&amp;clmp1uju000t4mc0k1y9b3c6c</loc>
    <lastmod>2023-09-18T15:36:56.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/dataparser&amp;clmp1ugi700t3mc0krgks0e3j</loc>
    <lastmod>2023-09-18T15:36:52.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/dataingestionthresholdlimits&amp;clmp1ubap00t2mc0kejsfmt2j</loc>
    <lastmod>2023-09-18T15:36:45.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/computersunhealthystate&amp;clmp1u5fj00t1mc0kajkqr98w</loc>
    <lastmod>2023-09-18T15:36:38.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/computersendingmostsecurityalerts&amp;clmp1u0k300t0mc0kwc4szoz6</loc>
    <lastmod>2023-09-18T15:36:31.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/allreportingcomputers&amp;clmp1twl200szmc0kirzk4lv5</loc>
    <lastmod>2023-09-18T15:36:26.536Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/adminskql&amp;clmp1tskh00symc0kuattffph</loc>
    <lastmod>2023-09-18T15:36:21.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/acrossworkspaceforFunction&amp;clmp1tngf00sxmc0k0cfuyemc</loc>
    <lastmod>2023-09-18T15:36:14.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ZeroLogon_Ports&amp;clmp1tj8u00swmc0kn2i1ilid</loc>
    <lastmod>2023-09-18T15:36:09.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkspacesAndTables&amp;clmp1tc5100svmc0kpbi0xe3b</loc>
    <lastmod>2023-09-18T15:36:00.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Workspaces90DaysRetention&amp;clmp1t6qv00sumc0k5i0m31af</loc>
    <lastmod>2023-09-18T15:35:53.191Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkspaceIDs&amp;clmp1t39k00stmc0kogmxyyu7</loc>
    <lastmod>2023-09-18T15:35:48.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkbookDeletion&amp;clmp1sz1p00ssmc0knxbbhbjm</loc>
    <lastmod>2023-09-18T15:35:43.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkbookCreation&amp;clmp1sv6g00srmc0ky9y4oc4n</loc>
    <lastmod>2023-09-18T15:35:38.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WorkWeek&amp;clmp1sqn800sqmc0k4w1fpbef</loc>
    <lastmod>2023-09-18T15:35:32.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WiresharkRSSTraffic&amp;clmp1sina00spmc0ktf0p1gql</loc>
    <lastmod>2023-09-18T15:35:21.958Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Windows10LoggedInLast7Days&amp;clmp1se1c00somc0k0bnvte0s</loc>
    <lastmod>2023-09-18T15:35:15.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhoModifiedAnalyticsRule&amp;clmp1s9hr00snmc0klcm34hje</loc>
    <lastmod>2023-09-18T15:35:10.093Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhoDeletedAlertRule&amp;clmp1s3ax00smmc0k7nc5ps19</loc>
    <lastmod>2023-09-18T15:35:02.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhoChangedTheirAADPassword&amp;clmp1rzfz00slmc0kwhbpvt7c</loc>
    <lastmod>2023-09-18T15:34:56.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhoChangedConditionalAccessPolicy&amp;clmp1ruh200skmc0k62m8i8fy</loc>
    <lastmod>2023-09-18T15:34:50.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhiteList-FindWhoAccessedAzureSentinelthatShouldNot&amp;clmp1rqry00sjmc0kp3mkqafv</loc>
    <lastmod>2023-09-18T15:34:45.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WhenUEBAwasEnabledByWho&amp;clmp1rkhd00simc0kzrwombq8</loc>
    <lastmod>2023-09-18T15:34:37.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WebshellPosts&amp;clmp1rgot00shmc0kv5k8c3d0</loc>
    <lastmod>2023-09-18T15:34:32.765Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WatchlistsCosts&amp;clmp1rbvr00sgmc0ktpne62o0</loc>
    <lastmod>2023-09-18T15:34:26.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WatchlistNOTin&amp;clmp1r6gp00sfmc0kupfao1lb</loc>
    <lastmod>2023-09-18T15:34:19.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WatchListDelete&amp;clmp1r0vz00semc0kn1o95rfc</loc>
    <lastmod>2023-09-18T15:34:12.286Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WatchListAudit&amp;clmp1qx7z00sdmc0kc1x4prj6</loc>
    <lastmod>2023-09-18T15:34:07.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UsersIPsPorts&amp;clmp1qs2t00scmc0kov1473a5</loc>
    <lastmod>2023-09-18T15:34:00.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UsersConnectFromMultipleCity&amp;clmp1qnxm00sbmc0khhgjizn4</loc>
    <lastmod>2023-09-18T15:33:55.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Usergrantedaccesstoanapp&amp;clmp1qi2o00samc0ke4cm9e6n</loc>
    <lastmod>2023-09-18T15:33:47.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UserAccountLockedAAD&amp;clmp1qewn00s9mc0kzox7glzx</loc>
    <lastmod>2023-09-18T15:33:43.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UpdateDataConnectors&amp;clmp1qatx00s8mc0ki95fj4mj</loc>
    <lastmod>2023-09-18T15:33:38.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UpdateComplianceBarChart&amp;clmp1q7bt00s7mc0kqs5w689k</loc>
    <lastmod>2023-09-18T15:33:33.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnsuccessfulRulesinLast24&amp;clmp1q0ru00s6mc0k79pmcn3f</loc>
    <lastmod>2023-09-18T15:33:25.340Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UEBA_IsDormant&amp;clmp1pvwz00s5mc0kydbf9ss9</loc>
    <lastmod>2023-09-18T15:33:19.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UEBAEstimate&amp;clmp1pr5s00s4mc0k2na7fcdu</loc>
    <lastmod>2023-09-18T15:33:13.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UEBACosts&amp;clmp1pl5q00s3mc0ktt9soanr</loc>
    <lastmod>2023-09-18T15:33:05.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TrialExpiration&amp;clmp1peov00s2mc0kz5cvij1i</loc>
    <lastmod>2023-09-18T15:32:56.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TrendofRequests&amp;clmp1p8dt00s1mc0kbsexhmbm</loc>
    <lastmod>2023-09-18T15:32:48.688Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Tracking%20Privileged%20Account%20Rare%20Activity%20without%20AWS&amp;clmp1p4rr00s0mc0k5tz633cv</loc>
    <lastmod>2023-09-18T15:32:43.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TotalIncidentsInLast6Months&amp;clmp1oxjp00rzmc0k0rf309zu</loc>
    <lastmod>2023-09-18T15:32:34.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top%20N%20by%20group%20example%20via%20LAG%20-%20option%201&amp;clmp1orgq00rymc0ku70fyjyc</loc>
    <lastmod>2023-09-18T15:32:26.621Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top%20N%20by%20Group%20example%20via%20top-nested%20-%20option%202&amp;clmp1oi8n00rxmc0kblmx3kdn</loc>
    <lastmod>2023-09-18T15:32:14.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TimeRangeExample&amp;clmp1ocuo00rwmc0kksg50kc4</loc>
    <lastmod>2023-09-18T15:32:07.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TimeBetweenDates&amp;clmp1o90b00rvmc0kpf7xy9pk</loc>
    <lastmod>2023-09-18T15:32:02.701Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TieFighter&amp;clmp1o5ud00rumc0ka79fx0yt</loc>
    <lastmod>2023-09-18T15:31:58.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatStatus&amp;clmp1o1fp00rtmc0kuwyzxjud</loc>
    <lastmod>2023-09-18T15:31:53.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatIntelligenceTableCosts&amp;clmp1nwhw00rsmc0kx2o0oso9</loc>
    <lastmod>2023-09-18T15:31:46.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatIntelBag&amp;clmp1nqh800rrmc0k7021q3av</loc>
    <lastmod>2023-09-18T15:31:38.827Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsWasUserRoleChanged&amp;clmp1nn2m00rqmc0kehpxyyui</loc>
    <lastmod>2023-09-18T15:31:34.414Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsUserAddedtoTeamsChannel&amp;clmp1nj3600rpmc0kisjphzfq</loc>
    <lastmod>2023-09-18T15:31:29.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsSuspiciousElevationofPrivileges&amp;clmp1neni00romc0k9uy6gacd</loc>
    <lastmod>2023-09-18T15:31:23.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsSingleUsersDeleteMultipleTeams&amp;clmp1n7dx00rnmc0kh171rpft</loc>
    <lastmod>2023-09-18T15:31:13.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsListFederatedUsers&amp;clmp1n1os00rmmc0kwycm3xgo</loc>
    <lastmod>2023-09-18T15:31:06.699Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsExternalSuspiciousAccountsRevokedAccess&amp;clmp1mvo100rlmc0kd4f237a1</loc>
    <lastmod>2023-09-18T15:30:58.755Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsExternalRareUserAccess&amp;clmp1mm7o00rkmc0k63fsdj10</loc>
    <lastmod>2023-09-18T15:30:46.643Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsChannelDeleted&amp;clmp1mghb00rjmc0kmi91qi11</loc>
    <lastmod>2023-09-18T15:30:39.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsBotsorAppsAdded&amp;clmp1md2k00rimc0kgs8845j9</loc>
    <lastmod>2023-09-18T15:30:34.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsAADSigninsSuccessUnsuccess&amp;clmp1m7kz00rhmc0k04r9iqrt</loc>
    <lastmod>2023-09-18T15:30:27.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TeamsAADSigninLogsRelatedtoTeamOwners&amp;clmp1lzem00rgmc0kmbar6tsu</loc>
    <lastmod>2023-09-18T15:30:16.943Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TablesNotIngestingDatain3Days&amp;clmp1lgvl00rfmc0kv2ckuva9</loc>
    <lastmod>2023-09-18T15:29:53.072Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TableUsageandCost&amp;clmp1lalq00remc0kcmmx4ryb</loc>
    <lastmod>2023-09-18T15:29:44.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TableExistence&amp;clmp1l4vy00rdmc0ku8pi281y</loc>
    <lastmod>2023-09-18T15:29:37.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TableData&amp;clmp1l14t00rcmc0koqujbnmt</loc>
    <lastmod>2023-09-18T15:29:32.668Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SystemthatHaveUpdatedintheLast4Hours&amp;clmp1kutp00rbmc0k5zgy012z</loc>
    <lastmod>2023-09-18T15:29:24.352Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SystemsReportingtoSentinel&amp;clmp1kotr00ramc0k28xbosxm</loc>
    <lastmod>2023-09-18T15:29:16.719Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SystemRestoreDisabled&amp;clmp1klc300r9mc0kd1u1gf0t</loc>
    <lastmod>2023-09-18T15:29:12.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SysmonEventsStorageSize&amp;clmp1k6yt00r7mc0kvbgri1d7</loc>
    <lastmod>2023-09-18T15:28:53.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SysmonAMA&amp;clmp1k31500r6mc0kuntz56be</loc>
    <lastmod>2023-09-18T15:28:48.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SysLogDaemon&amp;clmp1jydr00r5mc0kfvtgb5tg</loc>
    <lastmod>2023-09-18T15:28:42.446Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspicousARMActivites&amp;clmp1ju2100r4mc0kmxq1lscu</loc>
    <lastmod>2023-09-18T15:28:36.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuccessfulRoleAssignments&amp;clmp1jngh00r3mc0kwqclazz0</loc>
    <lastmod>2023-09-18T15:28:28.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SubsCreatedPerHour&amp;clmp1jhrt00r2mc0kg7s4nkh8</loc>
    <lastmod>2023-09-18T15:28:20.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/StoppedServices&amp;clmp1je4700r1mc0ky9trsupz</loc>
    <lastmod>2023-09-18T15:28:16.182Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/StopPLCIoTDevice&amp;clmp1jaoj00r0mc0kmhp0y8qv</loc>
    <lastmod>2023-09-18T15:28:11.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sparkles&amp;clmp1j6j700qzmc0koroh5yd7</loc>
    <lastmod>2023-09-18T15:28:06.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SophosDisabled&amp;clmp1iyrf00qymc0kl1hbfurh</loc>
    <lastmod>2023-09-18T15:27:56.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SolutionDataUsage&amp;clmp1is6i00qxmc0kxjzd5l2b</loc>
    <lastmod>2023-09-18T15:27:47.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Solarwinds_ServerU_Vuln&amp;clmp1im5600qwmc0k2o56ua1r</loc>
    <lastmod>2023-09-18T15:27:39.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogsNow&amp;clmp1ifnq00qvmc0kdwqa4c37</loc>
    <lastmod>2023-09-18T15:27:31.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogsByDay%20-%20parsing%20UTC&amp;clmp1i9sg00qumc0k81anjayr</loc>
    <lastmod>2023-09-18T15:27:23.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogsByBrowserandLocation&amp;clmp1i3rm00qtmc0kkw85onfw</loc>
    <lastmod>2023-09-18T15:27:16.113Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignatureVersionPie&amp;clmp1hyi100qsmc0khtae13ze</loc>
    <lastmod>2023-09-18T15:27:09.288Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInbyLocation&amp;clmp1hu8200qrmc0kyud9d2ym</loc>
    <lastmod>2023-09-18T15:27:03.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SharePointDownloads&amp;clmp1hm4b00qqmc0ka9uvpyeo</loc>
    <lastmod>2023-09-18T15:26:53.242Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelIncidentURLs-%20ALL&amp;clmp1hgwv00qpmc0k5bgzryi9</loc>
    <lastmod>2023-09-18T15:26:46.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelDataRetention&amp;clmp1hctb00qomc0kvn27lvrg</loc>
    <lastmod>2023-09-18T15:26:41.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityLogFileCleared&amp;clmp1h8d100qnmc0km78w2n6b</loc>
    <lastmod>2023-09-18T15:26:35.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIndicentsCreatedinLastDay&amp;clmp1h3xi00qmmc0kco09udhs</loc>
    <lastmod>2023-09-18T15:26:29.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityChangePasswordResets&amp;clmp1gzyt00qlmc0kzqea365o</loc>
    <lastmod>2023-09-18T15:26:24.532Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SQLServerAuditLogs&amp;clmp1gwzr00qkmc0k2lqofqp8</loc>
    <lastmod>2023-09-18T15:26:20.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMA%20and%20EMA%20examples&amp;clmp1gtj600qimc0khne6v1fx</loc>
    <lastmod>2023-09-18T15:26:16.194Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Running%20total%20aka%20cumulative%20sum&amp;clmp1gl0u00qgmc0khyzevby9</loc>
    <lastmod>2023-09-18T15:26:05.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RulesRuninLast30d&amp;clmp1gb2k00qemc0kduqe2n7b</loc>
    <lastmod>2023-09-18T15:25:52.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RetentionPerTable&amp;clmp1g7of00qcmc0kz14fvyjl</loc>
    <lastmod>2023-09-18T15:25:47.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RestartShutdownsLast7Days&amp;clmp1g33x00qamc0ks2oz84oh</loc>
    <lastmod>2023-09-18T15:25:41.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ReportNoData&amp;clmp1fyos00q8mc0kckziming</loc>
    <lastmod>2023-09-18T15:25:36.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RemoteWorkspaceQuery&amp;clmp1fush00q6mc0kcmhyga4r</loc>
    <lastmod>2023-09-18T15:25:31.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RemoteLogon&amp;clmp1fs4v00q4mc0k7w8t1z15</loc>
    <lastmod>2023-09-18T15:25:27.586Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RegistryCredentialTheft&amp;clmp1fmhh00q2mc0krh3aiavm</loc>
    <lastmod>2023-09-18T15:25:20.404Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/QueriesEachPersonRan&amp;clmp1fib700q0mc0k2f4ut2hi</loc>
    <lastmod>2023-09-18T15:25:14.995Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ProxyShellExchange&amp;clmp1fe2v00pymc0ksdnm5rfa</loc>
    <lastmod>2023-09-18T15:25:09.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ProxyShell&amp;clmp1f9d200pwmc0kzyo7i6oa</loc>
    <lastmod>2023-09-18T15:25:03.398Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PrintNightmare&amp;clmp1f5j400pvmc0kt0341hos</loc>
    <lastmod>2023-09-18T15:24:58.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellExecutionwithDownload&amp;clmp1eztu00ptmc0kr4cq6jyu</loc>
    <lastmod>2023-09-18T15:24:50.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellExecution&amp;clmp1et6t00prmc0kfyorlot8</loc>
    <lastmod>2023-09-18T15:24:42.436Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Potentialmaliciouseventsmap&amp;clmp1ennw00ppmc0kc8j0tdim</loc>
    <lastmod>2023-09-18T15:24:35.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PoorPerfQuery&amp;clmp1eel900pomc0kavuakw9n</loc>
    <lastmod>2023-09-18T15:24:23.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PolicyExemptions&amp;clmp1e9xm00pnmc0kmw1i2dt4</loc>
    <lastmod>2023-09-18T15:24:17.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PolicyCreation&amp;clmp1e4t900pmmc0k0fkzr8o0</loc>
    <lastmod>2023-09-18T15:24:10.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PlaybookActivity&amp;clmp1e03t00plmc0kyl6akquk</loc>
    <lastmod>2023-09-18T15:24:04.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ParseBetween&amp;clmp1du8o00pkmc0kyeozejei</loc>
    <lastmod>2023-09-18T15:23:57.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ParseAnomaliConfidenceScore&amp;clmp1dovv00pjmc0kilqa5ed8</loc>
    <lastmod>2023-09-18T15:23:50.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PaloAltoStops&amp;clmp1dl4z00pimc0kzmvhvjpu</loc>
    <lastmod>2023-09-18T15:23:45.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PackAllExample&amp;clmp1dg8w00phmc0ky8lv0swa</loc>
    <lastmod>2023-09-18T15:23:39.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PKEXEC&amp;clmp1dcqv00pgmc0kvxtr1rq1</loc>
    <lastmod>2023-09-18T15:23:34.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Overview_Queries&amp;clmp1d8hn00pfmc0k1xaf4ga9</loc>
    <lastmod>2023-09-18T15:23:28.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mean%20time%20to%20close&amp;clmp1d24000pemc0k4ry6s3p5</loc>
    <lastmod>2023-09-18T15:23:20.687Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mean%20time%20to%20acknowledge%20-%20last%2048%20hours&amp;clmp1curx00pdmc0kzjq0srta</loc>
    <lastmod>2023-09-18T15:23:11.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents%20status%20by%20creation%20time%20-%20last%2024%20hours&amp;clmp1cl2w00pcmc0k8cde3ykf</loc>
    <lastmod>2023-09-18T15:22:58.616Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents%20by%20status%20-%20last%2024%20hours&amp;clmp1cepm00pbmc0kvhh8snu3</loc>
    <lastmod>2023-09-18T15:22:50.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents%20by%20severity%20-%20last%2024%20hours&amp;clmp1cb6100pamc0ktaku4bgq</loc>
    <lastmod>2023-09-18T15:22:45.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents%20by%20closed%20classification%20-%20last%2024%20hours&amp;clmp1c6z200p9mc0k3xevvu6h</loc>
    <lastmod>2023-09-18T15:22:40.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Unhealthy%20connectors&amp;clmp1c2as00p8mc0khd63ktm7</loc>
    <lastmod>2023-09-18T15:22:34.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Total%20volume&amp;clmp1bwi900p7mc0kgvij9nra</loc>
    <lastmod>2023-09-18T15:22:26.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20by%20type&amp;clmp1bsd700p6mc0kxpf2wkzs</loc>
    <lastmod>2023-09-18T15:22:21.402Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies&amp;clmp1bls000p5mc0kab2u3jny</loc>
    <lastmod>2023-09-18T15:22:12.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Time%20saved&amp;clmp1bgt300p4mc0ks9wbcfpx</loc>
    <lastmod>2023-09-18T15:22:06.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Closed%20incidents&amp;clmp1babu00p3mc0kmjq8qbu4</loc>
    <lastmod>2023-09-18T15:21:57.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Actions%20performed&amp;clmp1b4gm00p2mc0k9c7dgokl</loc>
    <lastmod>2023-09-18T15:21:50.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OnlineOffline&amp;clmp1ayid00p1mc0kzr3cn7tt</loc>
    <lastmod>2023-09-18T15:21:42.568Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeUsertoAdminGroup&amp;clmp1as6100p0mc0kdun6x2wo</loc>
    <lastmod>2023-09-18T15:21:34.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeIngestDelay&amp;clmp1anom00ozmc0kxd5vygax</loc>
    <lastmod>2023-09-18T15:21:28.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NumberofEventsOveraSelectedTime&amp;clmp1akb400oymc0kpm8zp4if</loc>
    <lastmod>2023-09-18T15:21:24.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NotLoggedIn&amp;clmp1afyp00oxmc0kg5xjeol7</loc>
    <lastmod>2023-09-18T15:21:18.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NotEqual&amp;clmp1acwk00owmc0kl6hijtjj</loc>
    <lastmod>2023-09-18T15:21:14.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NoUnassignedIncidents&amp;clmp1a7qk00ovmc0k5clqreoy</loc>
    <lastmod>2023-09-18T15:21:07.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NoTotalOpenIncidentsin90&amp;clmp1a26m00oumc0k4c6dfm4f</loc>
    <lastmod>2023-09-18T15:21:00.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NoNewOpenIncidents24hrs&amp;clmp19wuo00otmc0kj6yp9990</loc>
    <lastmod>2023-09-18T15:20:53.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NoLogintoAADin90Days&amp;clmp19r8e00osmc0k1ct6y013</loc>
    <lastmod>2023-09-18T15:20:46.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NoIncidentsClosedin90&amp;clmp19kmo00ormc0k6ybbnb6t</loc>
    <lastmod>2023-09-18T15:20:38.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewYearChampagneGlass&amp;clmp19g3u00oqmc0koig7uu8u</loc>
    <lastmod>2023-09-18T15:20:32.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewBruteForceAttacks&amp;clmp19a5k00opmc0k3ayxfm4e</loc>
    <lastmod>2023-09-18T15:20:24.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewAdmins&amp;clmp193z100oomc0kedn8mp5y</loc>
    <lastmod>2023-09-18T15:20:16.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NetLogonPatchCompliance&amp;clmp18xhn00onmc0ktjdezvqm</loc>
    <lastmod>2023-09-18T15:20:07.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NSGChangesbyUserandResource&amp;clmp18stk00ommc0kexo55cwt</loc>
    <lastmod>2023-09-18T15:20:02.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NSGChangesByUser&amp;clmp18otq00olmc0kk3k1unvm</loc>
    <lastmod>2023-09-18T15:19:56.846Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NRTFailed&amp;clmp18ih700okmc0ka174dp8m</loc>
    <lastmod>2023-09-18T15:19:48.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MostGeneratedIncidents&amp;clmp18dve00ojmc0koprki6df</loc>
    <lastmod>2023-09-18T15:19:42.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MimiKatzDetection&amp;clmp188n600oimc0kymnae9s0</loc>
    <lastmod>2023-09-18T15:19:35.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiSIGRED&amp;clmp182xl00ohmc0kprq63l9a</loc>
    <lastmod>2023-09-18T15:19:28.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiParser&amp;clmp14ng500ogmc0k344rphcb</loc>
    <lastmod>2023-09-18T15:16:48.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiPKIActivity&amp;clmp14idl00ofmc0k9es4jen4</loc>
    <lastmod>2023-09-18T15:16:41.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiDeviceInformation&amp;clmp14eih00oemc0kbc5aido1</loc>
    <lastmod>2023-09-18T15:16:36.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiDeviceChanges&amp;clmp149x100odmc0kcxle5anj</loc>
    <lastmod>2023-09-18T15:16:30.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiDenialofService&amp;clmp145a900ocmc0kotcryxr2</loc>
    <lastmod>2023-09-18T15:16:24.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MerakiConf2&amp;clmp141pm00obmc0knojjtge3</loc>
    <lastmod>2023-09-18T15:16:20.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MalwareEngShutdown&amp;clmp13p9400oamc0kfb0lyi8g</loc>
    <lastmod>2023-09-18T15:16:03.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Make-series%20for%20gaps&amp;clmp13k9300o9mc0kjaohta5y</loc>
    <lastmod>2023-09-18T15:15:57.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Make%20series%20to%20fill%20in%20gaps%20with%20default%20for%20bin%20by%20bucket&amp;clmp13cht00o8mc0k7s8ruczj</loc>
    <lastmod>2023-09-18T15:15:47.444Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MV-EpandExample&amp;clmp1353b00o7mc0kqli6awp2</loc>
    <lastmod>2023-09-18T15:15:37.991Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MITRETacticIncident&amp;clmp12zga00o6mc0k6it2wj6f</loc>
    <lastmod>2023-09-18T15:15:30.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDTISourceTI&amp;clmp12w5f00o5mc0kvgmgz37o</loc>
    <lastmod>2023-09-18T15:15:26.262Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LookingforInstalledKBIDs&amp;clmp12ske00o4mc0ktnogn3gq</loc>
    <lastmod>2023-09-18T15:15:21.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LookbackQuery&amp;clmp12p2b00o3mc0knkdfm8lu</loc>
    <lastmod>2023-09-18T15:15:17.218Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LoginsByAccountPerLocation&amp;clmp12jo500o2mc0kbh7ndxlr</loc>
    <lastmod>2023-09-18T15:15:10.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LoginLocationNotInUS&amp;clmp12f6z00o1mc0klnnbrwn5</loc>
    <lastmod>2023-09-18T15:15:04.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LoginFailureUnknownUserNameorBadPassword&amp;clmp12bca00o0mc0kk7ulrwzy</loc>
    <lastmod>2023-09-18T15:14:59.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LoginFailureButPasswordChangeRequired&amp;clmp127k200nzmc0k19vxkahw</loc>
    <lastmod>2023-09-18T15:14:54.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LogSources&amp;clmp1248i00nymc0k6f4wafdq</loc>
    <lastmod>2023-09-18T15:14:50.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LockedUsers&amp;clmp11w6i00nxmc0kxkk1c7du</loc>
    <lastmod>2023-09-18T15:14:39.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListofDomains&amp;clmp11qpq00nwmc0krzjek4b5</loc>
    <lastmod>2023-09-18T15:14:32.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LinksinTeamsMessages&amp;clmp11moh00nvmc0kpq96vi2v</loc>
    <lastmod>2023-09-18T15:14:27.472Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LineNumbers-serialize&amp;clmp11j8g00numc0k4pn04iwd</loc>
    <lastmod>2023-09-18T15:14:22.867Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LegacyAuthSignin&amp;clmp11eas00ntmc0kywnckfvi</loc>
    <lastmod>2023-09-18T15:14:16.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Latency%20for%20a%20Log%20Analytics%20example%20with%20rolling%20percentiles&amp;clmp1195e00nrmc0kyxztn79a</loc>
    <lastmod>2023-09-18T15:14:09.938Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastTimeMessageReceived&amp;clmp114ln00npmc0ko1m42gfq</loc>
    <lastmod>2023-09-18T15:14:03.902Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastTimeDataReceived&amp;clmp10zgx00nnmc0k8h6e7j9e</loc>
    <lastmod>2023-09-18T15:13:57.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastLogin&amp;clmp10s6c00nlmc0kgkvxqvpl</loc>
    <lastmod>2023-09-18T15:13:47.798Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Language%20demo%20just%20for%20fun%20and%20demo%20pattern%20replace&amp;clmp10mff00njmc0katag0jjq</loc>
    <lastmod>2023-09-18T15:13:40.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LAG%20analysis%20example&amp;clmp10cw800nhmc0kgy70qyl9</loc>
    <lastmod>2023-09-18T15:13:27.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KaseyaREvil&amp;clmp0zvfq00nfmc0krwx3tbs0</loc>
    <lastmod>2023-09-18T15:13:05.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KDCforKRBTGTPassword&amp;clmp0zrqs00ndmc0kiltpigin</loc>
    <lastmod>2023-09-18T15:13:00.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneisCompliantByOSandOSVersion&amp;clmp0zm9300nbmc0kbyf47dbn</loc>
    <lastmod>2023-09-18T15:12:53.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intunecomputershutdowns&amp;clmp0zhek00n9mc0krq4kidv0</loc>
    <lastmod>2023-09-18T15:12:47.324Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneTopuserswithauditedactions&amp;clmp0zcg100n7mc0kswrhb0yj</loc>
    <lastmod>2023-09-18T15:12:40.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneSummarizebyOperation&amp;clmp0z8qx00n5mc0k0sg5olw2</loc>
    <lastmod>2023-09-18T15:12:36.103Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneSuccessfulSynchedDevice&amp;clmp0z5yy00n3mc0kekvi5iie</loc>
    <lastmod>2023-09-18T15:12:32.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneRemoteactionstopusers&amp;clmp0z37p00n2mc0kp2ezhz4c</loc>
    <lastmod>2023-09-18T15:12:28.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneRemoteactionsbyactiontype&amp;clmp0yzac00n0mc0kzoudjxaw</loc>
    <lastmod>2023-09-18T15:12:23.844Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneRecentEventsbyAccounts&amp;clmp0yvck00mymc0koic8n0ak</loc>
    <lastmod>2023-09-18T15:12:18.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneNotCompliant2&amp;clmp0ys0o00mwmc0k52xssvgc</loc>
    <lastmod>2023-09-18T15:12:14.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneNotCompliant&amp;clmp0ympc00mumc0kej629en5</loc>
    <lastmod>2023-09-18T15:12:07.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentSuccessbyEnrollmentType&amp;clmp0yi2k00msmc0k9g9aqxzp</loc>
    <lastmod>2023-09-18T15:12:01.391Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentStatistics&amp;clmp0ydbu00mqmc0kg5b0i45l</loc>
    <lastmod>2023-09-18T15:11:55.386Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentFailuresbyPlatform&amp;clmp0y9la00mpmc0kismzx77w</loc>
    <lastmod>2023-09-18T15:11:50.542Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentFailuresbyEnrollmentType&amp;clmp0y3rh00mnmc0k5ro5bpo3</loc>
    <lastmod>2023-09-18T15:11:42.848Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentFailurereasons&amp;clmp0xyzs00mlmc0kzhjbnmz6</loc>
    <lastmod>2023-09-18T15:11:36.808Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneEnrollmentEventsTrend&amp;clmp0xu7l00mjmc0koylf8fhm</loc>
    <lastmod>2023-09-18T15:11:30.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevicesNotinCompliance&amp;clmp0xpyk00mhmc0kyr7q9mxf</loc>
    <lastmod>2023-09-18T15:11:25.100Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevicesNotSupported&amp;clmp0xhrh00mfmc0kl2n8vdiv</loc>
    <lastmod>2023-09-18T15:11:14.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneCountofSuccessfulEnrollmentsbyOS&amp;clmp0xds300mdmc0kuzvrvnd9</loc>
    <lastmod>2023-09-18T15:11:09.314Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneComplianceFailuresbyReason&amp;clmp0xa7800mbmc0kavpgrab3</loc>
    <lastmod>2023-09-18T15:11:04.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneComplianceFailuresbyOperatingSystem&amp;clmp0x4i500m9mc0krxhxba9c</loc>
    <lastmod>2023-09-18T15:10:57.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneAuditEventsTrend&amp;clmp0wy6n00m7mc0k2xgf05cj</loc>
    <lastmod>2023-09-18T15:10:49.102Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneAuditEvents&amp;clmp0wv0j00m5mc0k65ohqwys</loc>
    <lastmod>2023-09-18T15:10:44.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneActivityTypes&amp;clmp0wrn800m3mc0kblgxu4gc</loc>
    <lastmod>2023-09-18T15:10:40.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intune-Enrollmentsabandonedbytheuser&amp;clmp0woe900m1mc0kri4on73w</loc>
    <lastmod>2023-09-18T15:10:36.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intune-DeviceThreatLevelnotSecured&amp;clmp0wgkd00lzmc0kspulb6z5</loc>
    <lastmod>2023-09-18T15:10:26.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Intune-AutoPilotFailedEnrollment1Day&amp;clmp0wcqg00lxmc0kgx47khaf</loc>
    <lastmod>2023-09-18T15:10:21.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IngestionDelaySnippet&amp;clmp0w8cv00lvmc0kcln4dict</loc>
    <lastmod>2023-09-18T15:10:15.487Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IngestionDelay&amp;clmp0w3p900ltmc0kn93rkw7t</loc>
    <lastmod>2023-09-18T15:10:09.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Incidents&amp;clmp0vyq800lrmc0k47hd7kvz</loc>
    <lastmod>2023-09-18T15:10:03.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IncidentOwnerChange&amp;clmp0vvm100lpmc0kkmmcqxxb</loc>
    <lastmod>2023-09-18T15:09:59.112Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IncidentID2RuleName&amp;clmp0vnwe00lnmc0k1jppckjd</loc>
    <lastmod>2023-09-18T15:09:48.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ImpossibleTravelMCAS&amp;clmp0vgoc00llmc0kh59yshst</loc>
    <lastmod>2023-09-18T15:09:39.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ImpossibleTravelKQL&amp;clmp0vbeu00ljmc0kac3kui02</loc>
    <lastmod>2023-09-18T15:09:32.933Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntingQueriesAzureActivitySuccessandFailures&amp;clmp0v6xr00lhmc0kgclbf4bp</loc>
    <lastmod>2023-09-18T15:09:27.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HuntingBookmarkHealth&amp;clmp0v19800lfmc0k1qwvsssq</loc>
    <lastmod>2023-09-18T15:09:19.771Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HowManyQueriesEachPersonRan&amp;clmp0uw5h00ldmc0kvksuqhai</loc>
    <lastmod>2023-09-18T15:09:13.156Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HowManyHostLogons&amp;clmp0up3v00lbmc0kx4kal7o1</loc>
    <lastmod>2023-09-18T15:09:04.026Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HowManyAlertsGeneratedByService&amp;clmp0ul5h00l9mc0kfdj9z2a4</loc>
    <lastmod>2023-09-18T15:08:58.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HourMinute&amp;clmp0ugeq00l7mc0kdkdrmk52</loc>
    <lastmod>2023-09-18T15:08:52.753Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HighRiskUserSigninResourceGroupCreation&amp;clmp0ud2000l5mc0ki67mwkax</loc>
    <lastmod>2023-09-18T15:08:48.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Heartbeatnotreceivedinlast30min&amp;clmp0u6h200l3mc0ks2v2y0us</loc>
    <lastmod>2023-09-18T15:08:39.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GuestsAddedtoRoles&amp;clmp0u1k100l1mc0k5zjgsf3x</loc>
    <lastmod>2023-09-18T15:08:33.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GuestAccountAdds&amp;clmp0toh200kzmc0krfy0vb1h</loc>
    <lastmod>2023-09-18T15:08:16.549Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GreaterThanOneCity&amp;clmp0ti0f00kxmc0k7bkvcu2y</loc>
    <lastmod>2023-09-18T15:08:08.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GetTags&amp;clmp0tdye00kvmc0k42cush14</loc>
    <lastmod>2023-09-18T15:08:02.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GEOIPLocation&amp;clmp0ta7w00ktmc0kkisqvyzz</loc>
    <lastmod>2023-09-18T15:07:58.075Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FileExecutionOver5Times&amp;clmp0t6dc00krmc0kjfiiaaom</loc>
    <lastmod>2023-09-18T15:07:53.087Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FailedLoginsPerAccount&amp;clmp0t0yu00kpmc0kegs19f9q</loc>
    <lastmod>2023-09-18T15:07:46.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalGEOforSecurityEvents&amp;clmp0sxoi00knmc0kceznayh8</loc>
    <lastmod>2023-09-18T15:07:41.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalAccess&amp;clmp0sts800klmc0k0dlyovz3</loc>
    <lastmod>2023-09-18T15:07:36.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExpiredPassword&amp;clmp0spj400kjmc0kkrkepzfm</loc>
    <lastmod>2023-09-18T15:07:31.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExistingConditionalAccessPolicies&amp;clmp0sm5j00khmc0kmcqhyo5u</loc>
    <lastmod>2023-09-18T15:07:26.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExecutedProcesses&amp;clmp0siip00kfmc0k2khdmk3q</loc>
    <lastmod>2023-09-18T15:07:22.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EventVolumePerTable&amp;clmp0se9k00kdmc0kewkw4q6f</loc>
    <lastmod>2023-09-18T15:07:16.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EventLogSources&amp;clmp0s8gx00kbmc0khybpp7hq</loc>
    <lastmod>2023-09-18T15:07:09.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EventIDsinLastDay&amp;clmp0s5xg00k9mc0krdno5qrm</loc>
    <lastmod>2023-09-18T15:07:05.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EventIDStorageinBytes&amp;clmp0s1us00k7mc0ko9kgdst2</loc>
    <lastmod>2023-09-18T15:07:00.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailForwarding&amp;clmp0rwyt00k5mc0k1kboclqw</loc>
    <lastmod>2023-09-18T15:06:54.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EPSperTable&amp;clmp0rrkp00k3mc0k8h0bryoa</loc>
    <lastmod>2023-09-18T15:06:47.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EPSforM365AdvancedTables&amp;clmp0rkza00k1mc0kpniquqc0</loc>
    <lastmod>2023-09-18T15:06:38.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Duration%20of%20session&amp;clmp0rfxy00jzmc0k4vwmolw9</loc>
    <lastmod>2023-09-18T15:06:32.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DormantAccounts&amp;clmp0r9nn00jxmc0k0avtqvq6</loc>
    <lastmod>2023-09-18T15:06:23.891Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DomainAdminsEnterpriseAdmins&amp;clmp0r33b00jvmc0k2y0m3d3a</loc>
    <lastmod>2023-09-18T15:06:15.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Does%20a%20table%20exist&amp;clmp0qxvy00jtmc0k681pt7dy</loc>
    <lastmod>2023-09-18T15:06:08.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DirectReport&amp;clmp0qtff00jrmc0kp1wx7vcz</loc>
    <lastmod>2023-09-18T15:06:03.002Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DirectAgent&amp;clmp0qpl300jpmc0k82anoc6g</loc>
    <lastmod>2023-09-18T15:05:58.022Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceStopsReporting&amp;clmp0qlf300jnmc0krqca7x2u</loc>
    <lastmod>2023-09-18T15:05:52.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderLiveResponse&amp;clmp0qfv000jlmc0kh8m5mqwx</loc>
    <lastmod>2023-09-18T15:05:45.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderExclusions&amp;clmp0qboe00jjmc0kusk365ba</loc>
    <lastmod>2023-09-18T15:05:39.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderAVNotSuccessful&amp;clmp0q7hy00jhmc0khd7ylfrl</loc>
    <lastmod>2023-09-18T15:05:34.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Debugging%20authentication%20sign-ins&amp;clmp0q1mb00jfmc0kakjvombe</loc>
    <lastmod>2023-09-18T15:05:26.962Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DayofWeek&amp;clmp0pt6w00jdmc0kmqiscved</loc>
    <lastmod>2023-09-18T15:05:15.898Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataTypeUsagePieChart&amp;clmp0pogx00jbmc0ko2g61ty7</loc>
    <lastmod>2023-09-18T15:05:09.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataRetentionChanges&amp;clmp0pkba00j9mc0ks6zm8lez</loc>
    <lastmod>2023-09-18T15:05:04.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataPerSyslogServer&amp;clmp0pgh400j8mc0kbbyhjmvn</loc>
    <lastmod>2023-09-18T15:04:59.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataPerComputer&amp;clmp0pbyt00j6mc0k4vtaiuue</loc>
    <lastmod>2023-09-18T15:04:53.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataIngestionNotHappening&amp;clmp0p4k400j4mc0k1p6ge81p</loc>
    <lastmod>2023-09-18T15:04:44.115Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataIngestEstimation&amp;clmp0ozjr00j2mc0kd6ovwogz</loc>
    <lastmod>2023-09-18T15:04:37.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataConnectorReqsFailedbyCallerIPOperation&amp;clmp0op2500j0mc0kico8q7nt</loc>
    <lastmod>2023-09-18T15:04:24.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataConnectorReqsFailed&amp;clmp0olmi00iymc0kw3f9rma5</loc>
    <lastmod>2023-09-18T15:04:19.577Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataConnectorOpened&amp;clmp0ohjd00iwmc0knajgt2ty</loc>
    <lastmod>2023-09-18T15:04:14.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DataByProvider&amp;clmp0odq400iumc0kng3awg2t</loc>
    <lastmod>2023-09-18T15:04:09.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DarkSideRansomware&amp;clmp0oa5v00ismc0k02rpg9ue</loc>
    <lastmod>2023-09-18T15:04:04.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DNSActivity_Attempts_Per_Device&amp;clmp0o51800iqmc0kztjtdurm</loc>
    <lastmod>2023-09-18T15:03:58.076Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cross%20resource%20query&amp;clmp0nyup00iomc0k26trdmz6</loc>
    <lastmod>2023-09-18T15:03:49.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CountriesWhereAgentedComputersReportFrom&amp;clmp0ntgs00immc0k2y2xmx7h</loc>
    <lastmod>2023-09-18T15:03:43.083Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CostperEventID&amp;clmp0no5700ikmc0kaselzkq6</loc>
    <lastmod>2023-09-18T15:03:36.186Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CostPerSubscription&amp;clmp0njy400iimc0k2ehpydar</loc>
    <lastmod>2023-09-18T15:03:30.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConnectorFailures&amp;clmp0nd7b00igmc0kotfpd6md</loc>
    <lastmod>2023-09-18T15:03:22.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Conditional%20access%20changes%20new%20value%20and%20old%20value&amp;clmp0n86j00iemc0ktmesdtu7</loc>
    <lastmod>2023-09-18T15:03:15.355Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CompareTotalRecordswithValuebyPercentage&amp;clmp0n26h00icmc0kfc61omag</loc>
    <lastmod>2023-09-18T15:03:07.720Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommonSecurityLogThroughput&amp;clmp0mxri00iamc0kwe2wt7t1</loc>
    <lastmod>2023-09-18T15:03:01.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommonSecurityLogCostsbyVendor&amp;clmp0ms8d00i8mc0kdl3gy6v5</loc>
    <lastmod>2023-09-18T15:02:54.829Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CommentDeleted&amp;clmp0mn4n00i6mc0krp52gsje</loc>
    <lastmod>2023-09-18T15:02:48.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cloudshell2&amp;clmp0mhde00i4mc0k5vwb5r0d</loc>
    <lastmod>2023-09-18T15:02:40.610Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudShellPart2&amp;clmp0mavr00i2mc0kan7h5clj</loc>
    <lastmod>2023-09-18T15:02:32.342Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudShell&amp;clmp0m4r400i0mc0kc837hi36</loc>
    <lastmod>2023-09-18T15:02:24.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CheckPointLogs&amp;clmp0m0g500hymc0kpczxdvlb</loc>
    <lastmod>2023-09-18T15:02:18.820Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Check4LockedoutUser&amp;clmp0lulm00hwmc0k835v201o</loc>
    <lastmod>2023-09-18T15:02:11.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CaseComments&amp;clmp0lq6b00humc0k4f38gx0u</loc>
    <lastmod>2023-09-18T15:02:04.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CalculateSumofColumn&amp;clmp0llmq00htmc0ki130x62b</loc>
    <lastmod>2023-09-18T15:01:59.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2023-23397-Detection&amp;clmp0lhus00hsmc0kprvv3vuh</loc>
    <lastmod>2023-09-18T15:01:54.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CEFDevices&amp;clmp0l8zi00hrmc0kmoysg8w2</loc>
    <lastmod>2023-09-18T15:01:43.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BuiltInFusionCreation&amp;clmp0l3rs00hqmc0kvphrz935</loc>
    <lastmod>2023-09-18T15:01:36.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BrowserActivitybyGEO&amp;clmp0kysv00hpmc0kfpv2hsj1</loc>
    <lastmod>2023-09-18T15:01:29.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BookmarksCreatedBy&amp;clmp0kse400homc0k4daekz22</loc>
    <lastmod>2023-09-18T15:01:21.723Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BookmarkUpdate&amp;clmp0kp7g00hnmc0kefn2r4kv</loc>
    <lastmod>2023-09-18T15:01:17.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BookMarkUpdatedBy&amp;clmp0klk000hmmc0kwgg6fouv</loc>
    <lastmod>2023-09-18T15:01:12.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BitLockerMaliciousEncrypt&amp;clmp0ki1y00hlmc0k183d8rii</loc>
    <lastmod>2023-09-18T15:01:08.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Billabledatavolumebysolution&amp;clmp0kc0500hkmc0k7w1jmido</loc>
    <lastmod>2023-09-18T15:01:00.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Billabledatavolumebydatatype&amp;clmp0k5zg00hjmc0k9a3ekl7l</loc>
    <lastmod>2023-09-18T15:00:52.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BillableDatabyDataType&amp;clmp0k08m00himc0k0wj9be33</loc>
    <lastmod>2023-09-18T15:00:45.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzurePortalLoginErrors&amp;clmp0juks00hhmc0k8wvkkgez</loc>
    <lastmod>2023-09-18T15:00:37.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Runbooks%20query%20with%20correlation&amp;clmp0jqpf00hgmc0kobstd2pm</loc>
    <lastmod>2023-09-18T15:00:32.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AutomationRuleHasRun&amp;clmp0jkvm00hfmc0kvfzbd4wr</loc>
    <lastmod>2023-09-18T15:00:25.329Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AutomationRuleDelete&amp;clmp0jfnb00hemc0kz16rc422</loc>
    <lastmod>2023-09-18T15:00:18.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousToken&amp;clmp0jbxw00hdmc0k0yzm3gy4</loc>
    <lastmod>2023-09-18T15:00:13.606Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousAADAccountCreation&amp;clmp0j38u00hcmc0kej5ep2f2</loc>
    <lastmod>2023-09-18T15:00:02.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRulesRunbyTimes&amp;clmp0iz1200hbmc0ke0zg49xo</loc>
    <lastmod>2023-09-18T14:59:56.873Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRuleLastRun&amp;clmp0iufh00hamc0kcus264eq</loc>
    <lastmod>2023-09-18T14:59:51.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRuleDeleted&amp;clmp0ir1o00h9mc0kuuf3yphb</loc>
    <lastmod>2023-09-18T14:59:46.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRuleCreatedorModifiedwithDisplayName&amp;clmp0ilk200h8mc0kbuh60t8d</loc>
    <lastmod>2023-09-18T14:59:39.413Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRuleCreatedorModified&amp;clmp0ie3t00h7mc0kn60sqmqu</loc>
    <lastmod>2023-09-18T14:59:29.896Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Allexes&amp;clmp0i99j00h6mc0kwovowit1</loc>
    <lastmod>2023-09-18T14:59:23.482Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AlertProviderCounts&amp;clmp0i2jq00h5mc0k6kp3eynn</loc>
    <lastmod>2023-09-18T14:59:14.917Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AlertIngestionTime&amp;clmp08q1w00gwmc0kcmrxf67v</loc>
    <lastmod>2023-09-18T14:51:58.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AlertContextParser&amp;clmp08ldz00gvmc0kogmbnilh</loc>
    <lastmod>2023-09-18T14:51:52.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AgentedDevicesnotADJoined&amp;clmp08h8x00gumc0ksweyz7dy</loc>
    <lastmod>2023-09-18T14:51:47.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AgentProblems&amp;clmp08d4h00gtmc0kf18897zl</loc>
    <lastmod>2023-09-18T14:51:42.064Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AgentInfowithLocation&amp;clmp088x200gsmc0k6adk90el</loc>
    <lastmod>2023-09-18T14:51:36.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AdminConsent&amp;clmp081p700grmc0kuhbkcnsu</loc>
    <lastmod>2023-09-18T14:51:27.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddedorAssignedGlobalAdministratorroleperms&amp;clmp07w9q00gqmc0k6m77va5t</loc>
    <lastmod>2023-09-18T14:51:20.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AddClientDataSource&amp;clmp07o8f00gpmc0kr381ryii</loc>
    <lastmod>2023-09-18T14:51:09.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ActivityFromInfrequentCountry&amp;clmp07j5q00gomc0k233h2xjx</loc>
    <lastmod>2023-09-18T14:51:03.229Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ActiveUsers&amp;clmp07fgu00gnmc0k81gw8dqj</loc>
    <lastmod>2023-09-18T14:50:58.445Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ActiveIncidents&amp;clmp07b5c00gmmc0kyxlwazfz</loc>
    <lastmod>2023-09-18T14:50:52.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Account-Created-Addedto-LocalAdministrator&amp;clmp078am00glmc0k9fsdzya7</loc>
    <lastmod>2023-09-18T14:50:49.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASCIncidentClosure&amp;clmp0744m00gkmc0k6xrnj26s</loc>
    <lastmod>2023-09-18T14:50:43.750Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ARPPoisoning&amp;clmp06ymv00gjmc0kv1gwn9ue</loc>
    <lastmod>2023-09-18T14:50:36.488Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-CloudShellExecution&amp;clmp06sq600gimc0kfxw3x78y</loc>
    <lastmod>2023-09-18T14:50:28.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-BruteForce&amp;clmp06mh000ghmc0k2sggm3fz</loc>
    <lastmod>2023-09-18T14:50:20.725Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AR-BreakGlassAccount&amp;clmp06idj00ggmc0kib1reeca</loc>
    <lastmod>2023-09-18T14:50:15.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AMAAgent&amp;clmp06e8s00gfmc0kozzrcbq0</loc>
    <lastmod>2023-09-18T14:50:10.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecEvents-SummarizeLogonEvents&amp;clmp03vjf00g6mc0kq7znkxw0</loc>
    <lastmod>2023-09-18T14:48:12.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecEvents-PotentialRDPRecon&amp;clmp03op100g5mc0key3j1o8x</loc>
    <lastmod>2023-09-18T14:48:03.781Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecEvents-FindLateralMovementUsers&amp;clmp03j5b00g4mc0knzxhf12n</loc>
    <lastmod>2023-09-18T14:47:56.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecEvents-FindDevicesNoLongerSendingLogs&amp;clmp03di500g3mc0klq9mt5s7</loc>
    <lastmod>2023-09-18T14:47:49.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-VisualizeBlastRadius&amp;clmp037pa00g2mc0kxpoz4mat</loc>
    <lastmod>2023-09-18T14:47:41.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindUserswithmanyGroups&amp;clmp032c600g1mc0ktk8s4ryn</loc>
    <lastmod>2023-09-18T14:47:34.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindPrivAccountsHighBlastRadius&amp;clmp02vsg00g0mc0kj17tts5d</loc>
    <lastmod>2023-09-18T14:47:26.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindGuestswithHighBlastRadius&amp;clmp02qj900fzmc0kkysa6kii</loc>
    <lastmod>2023-09-18T14:47:19.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindAtRiskandHighBlastRadiusUsers&amp;clmp02h4q00fxmc0kse8y6vzb</loc>
    <lastmod>2023-09-18T14:47:07.322Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindAccountswithsameEmployeeId&amp;clmp02bvp00fvmc0kye3qqrsz</loc>
    <lastmod>2023-09-18T14:47:00.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityInfo-FindAccountsPasswordNotRequired&amp;clmp025eq00ftmc0k49rln71o</loc>
    <lastmod>2023-09-18T14:46:52.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SysLog-DetectAnomaliesInEvents&amp;clmp01zyw00frmc0k6pppsd6t</loc>
    <lastmod>2023-09-18T14:46:44.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-WhichTablesAreInUse&amp;clmp01ufw00fpmc0k4j0rcdbh</loc>
    <lastmod>2023-09-18T14:46:37.916Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-VisualizeTotalAlertsvsUniqueAlerts&amp;clmp01n9i00fnmc0k0v5ol3mo</loc>
    <lastmod>2023-09-18T14:46:28.613Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-VisualizeTopPhishingDomains&amp;clmp01hmx00flmc0klahv9jeg</loc>
    <lastmod>2023-09-18T14:46:21.177Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-VisualizeMDEAlertSeverity&amp;clmp01b2z00fjmc0keclfkyo2</loc>
    <lastmod>2023-09-18T14:46:12.825Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-VisualizeAlertsbyProduct&amp;clmp0158000fhmc0kin80nyjm</loc>
    <lastmod>2023-09-18T14:46:05.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-VisualizeAlertsbyMITRE&amp;clmp010f800ffmc0kyu5zdfjy</loc>
    <lastmod>2023-09-18T14:45:58.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Top20RandomStats&amp;clmp00tu600fdmc0k3y1elkd3</loc>
    <lastmod>2023-09-18T14:45:50.477Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-SuspectedGoldenTicket&amp;clmp00of900fbmc0k72954936</loc>
    <lastmod>2023-09-18T14:45:43.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-SummarizeSigninsafterMailboxRule&amp;clmp00hxn00f9mc0ktbob48bk</loc>
    <lastmod>2023-09-18T14:45:35.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-RetrieveEmailforSuspiciousEmailPatterns&amp;clmp007pl00f7mc0k47599w20</loc>
    <lastmod>2023-09-18T14:45:21.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-PotentialPhishingDomainCommunication&amp;clmozzyv200f5mc0kc40iz2xz</loc>
    <lastmod>2023-09-18T14:45:10.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-PossibleDNSDataTransfer&amp;clmozzpkl00f3mc0kvh1mlz5k</loc>
    <lastmod>2023-09-18T14:44:58.292Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-PercentageofAlertsHighorCritical&amp;clmozzkqr00f1mc0k6j5v3puk</loc>
    <lastmod>2023-09-18T14:44:52.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-ParseMaliciousFileInfoandFindDeviceEvents&amp;clmozzed300ezmc0kv2t1piy5</loc>
    <lastmod>2023-09-18T14:44:43.767Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-MultipleLowSeverityAlertsTriggered&amp;clmozz7zd00exmc0kpoj9u08a</loc>
    <lastmod>2023-09-18T14:44:35.496Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-MultipleAlertsTriggered&amp;clmozz2fv00evmc0ku5lbu3r6</loc>
    <lastmod>2023-09-18T14:44:28.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-MalwareDetectedinISO&amp;clmozyxau00etmc0k43516ebk</loc>
    <lastmod>2023-09-18T14:44:21.652Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-ForecastIdentityProtection&amp;clmozyr0s00ermc0keenm9h0a</loc>
    <lastmod>2023-09-18T14:44:13.373Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindUsersWhoSigninfromMaliciousIPs&amp;clmozylls00epmc0knaa0ymol</loc>
    <lastmod>2023-09-18T14:44:06.495Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindSigninsforAnomalousToken&amp;clmozyb8o00enmc0kewaft66b</loc>
    <lastmod>2023-09-18T14:43:53.063Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindRecipientsofPotentialPhishing&amp;clmozy12q00emmc0ky7qz7uyj</loc>
    <lastmod>2023-09-18T14:43:38.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindNetworkConnectionsSinkholedDomain&amp;clmozxsw400elmc0ka8bbmn1s</loc>
    <lastmod>2023-09-18T14:43:29.141Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindMostPhishedUsers&amp;clmozxlpa00ekmc0k57w9618m</loc>
    <lastmod>2023-09-18T14:43:19.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindBlastRadiusofPasswordSpray&amp;clmozxghy00ejmc0k3ts1rjov</loc>
    <lastmod>2023-09-18T14:43:13.079Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-FindBlastRadiusInfrequentCountry&amp;clmozx27w00eimc0kxj09q13d</loc>
    <lastmod>2023-09-18T14:42:54.573Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-EncodedPowershell&amp;clmozwmwq00ehmc0ktfthb04s</loc>
    <lastmod>2023-09-18T14:42:34.730Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-DeviceAlertwithLateralMovement&amp;clmozwfvc00egmc0k4fgi8r3s</loc>
    <lastmod>2023-09-18T14:42:25.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-DetectNewAlerts&amp;clmozw93b00efmc0kamx06fo6</loc>
    <lastmod>2023-09-18T14:42:16.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-DefenderforIdParser&amp;clmozw22c00eemc0kwhv39c2b</loc>
    <lastmod>2023-09-18T14:42:07.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-DefenderforIDRecon&amp;clmozvtdc00edmc0kgp6vwko8</loc>
    <lastmod>2023-09-18T14:41:56.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeTopGuestDownloads&amp;clmozvmna00ecmc0ktcxe2hd4</loc>
    <lastmod>2023-09-18T14:41:47.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeGuestsRedeemedvsAddedtoTeams&amp;clmozvh9i00ebmc0k3xpa5ek0</loc>
    <lastmod>2023-09-18T14:41:40.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeGuestsAddedRemovedfromTeams&amp;clmozv88u00eamc0kqqvtqglt</loc>
    <lastmod>2023-09-18T14:41:29.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeGuestDownloadsfromO365withTrend&amp;clmozv19k00e9mc0k9pbco9gl</loc>
    <lastmod>2023-09-18T14:41:20.024Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeFilesSharedtoGuests&amp;clmozuvej00e8mc0kc16847vs</loc>
    <lastmod>2023-09-18T14:41:12.570Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeFileShareTopGuestDomains&amp;clmozumjo00e7mc0k0uioqjeq</loc>
    <lastmod>2023-09-18T14:41:00.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeDownloadsvsUploads&amp;clmozug7o00e6mc0kktbwxu76</loc>
    <lastmod>2023-09-18T14:40:52.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualizeDownloadsbyTrustType&amp;clmozu8h700e5mc0kwny01lsn</loc>
    <lastmod>2023-09-18T14:40:42.716Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-VisualisingAnomalousDownloads&amp;clmoztzww00e4mc0k3gd2q8d1</loc>
    <lastmod>2023-09-18T14:40:31.759Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Top20RandomStats&amp;clmoztrej00e3mc0ks7kplh41</loc>
    <lastmod>2023-09-18T14:40:20.588Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-TeamsRoleChanges&amp;clmoztfal00e2mc0kudk2mmpu</loc>
    <lastmod>2023-09-18T14:40:04.893Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SummaryofExternalActivity&amp;clmozt8q500e1mc0kftuq2gxp</loc>
    <lastmod>2023-09-18T14:39:56.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SummarizeTeamsCreatedDeleted&amp;clmozt0op00e0mc0k8klvfx4b</loc>
    <lastmod>2023-09-18T14:39:46.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SummarizeTeamsAppInstalls&amp;clmozsun600dzmc0krn5hwoss</loc>
    <lastmod>2023-09-18T14:39:38.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SummarizeGuestsAddedtoTeams&amp;clmozspff00dymc0kck87d3dt</loc>
    <lastmod>2023-09-18T14:39:31.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SummarizeDownloadActivitybyGuests&amp;clmozsj3h00dxmc0k0rm8cb3p</loc>
    <lastmod>2023-09-18T14:39:23.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SharedTeamsChannelCreated&amp;clmozscyo00dwmc0k6x6zp2nu</loc>
    <lastmod>2023-09-18T14:39:15.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-NewTeamsAppInstalled&amp;clmozs86000dvmc0kc0h2wb23</loc>
    <lastmod>2023-09-18T14:39:09.001Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-MultipleFilesSharedtoGuests&amp;clmozs00h00dumc0kljrto9zm</loc>
    <lastmod>2023-09-18T14:38:58.576Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-MalwareDetected&amp;clmozrsno00dtmc0kjjsksv18</loc>
    <lastmod>2023-09-18T14:38:48.900Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-InboxRuleParse&amp;clmozrmd500dsmc0k1lec5y2v</loc>
    <lastmod>2023-09-18T14:38:40.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-GuestDomainsHighestDownloads&amp;clmozrd9f00drmc0k1w4s605d</loc>
    <lastmod>2023-09-18T14:38:28.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-GuestAddedtoMultipleTeams&amp;clmozr6kn00dqmc0ko1pahh08</loc>
    <lastmod>2023-09-18T14:38:20.422Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-FindUserswhoDownloadedMalware&amp;clmozqwj500dpmc0kyojvjyfz</loc>
    <lastmod>2023-09-18T14:38:07.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-FindNewOperations&amp;clmozqrb600domc0kzgh1bmsm</loc>
    <lastmod>2023-09-18T14:38:00.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-FilesSharedtoGuestsfromOnedrive&amp;clmozqlej00dnmc0klh1vew5g</loc>
    <lastmod>2023-09-18T14:37:52.843Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-ExchangeScopingPolicyApplied&amp;clmozqbrb00dmmc0kam8vhbb3</loc>
    <lastmod>2023-09-18T14:37:40.486Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-DetectUsermadeOwneronmultipleTeams&amp;clmozq60900dlmc0k4ib76wbf</loc>
    <lastmod>2023-09-18T14:37:32.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-DetectNewExchangeAdminRole&amp;clmozpxqq00dkmc0kh6fjenju</loc>
    <lastmod>2023-09-18T14:37:22.321Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-DetectFullMailboxAccess&amp;clmozps6z00djmc0kirc38vbm</loc>
    <lastmod>2023-09-18T14:37:14.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-DetectEmailsReadbyAdmins&amp;clmozpiih00dimc0klbdr6mkp</loc>
    <lastmod>2023-09-18T14:37:02.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-CalculateTimetoDetectMalware&amp;clmozpav800dhmc0kaevf7wah</loc>
    <lastmod>2023-09-18T14:36:52.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-CalculatePercentageofDownloadsperDomain&amp;clmozp2s900dgmc0k7trls6q7</loc>
    <lastmod>2023-09-18T14:36:42.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-CalculatePercentageofDownloadsforTopGuests&amp;clmozowjy00dfmc0kwgv240nj</loc>
    <lastmod>2023-09-18T14:36:33.983Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-CalculatePercentageofDownloadsUntrustedDevices&amp;clmozoq3l00demc0kpx5eh521</loc>
    <lastmod>2023-09-18T14:36:25.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-AnomalousGuestFileShares&amp;clmozoivq00ddmc0kz8mylzw7</loc>
    <lastmod>2023-09-18T14:36:16.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-AnomalousDownloadsfromGuests&amp;clmozo6ap00dcmc0kh8su4dkp</loc>
    <lastmod>2023-09-18T14:36:00.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Office-DownloadsfromGuestafterAddedtoTeams&amp;clmoznynh00dbmc0kz9q4jjpf</loc>
    <lastmod>2023-09-18T14:35:50.046Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-VisualizePostDeliveryActions&amp;clmoznmqd00damc0kot63vkhn</loc>
    <lastmod>2023-09-18T14:35:34.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-VisualizeDeliveryActions&amp;clmozng9s00d9mc0kpvkusci9</loc>
    <lastmod>2023-09-18T14:35:26.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-VisualizeBlockedEmailPercentage&amp;clmozna7500d8mc0kwsiwliv2</loc>
    <lastmod>2023-09-18T14:35:18.497Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-VisualizeBlockedEmailDeviation&amp;clmozn3b500d7mc0kyzdqmhpb</loc>
    <lastmod>2023-09-18T14:35:09.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-PotentialNewSpammer&amp;clmozmyhk00d6mc0krrxvyjqm</loc>
    <lastmod>2023-09-18T14:35:03.319Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-MostBlockedDomains&amp;clmozmqgq00d5mc0kogjt91dn</loc>
    <lastmod>2023-09-18T14:34:52.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-MacroReceivedbyEmail&amp;clmozmj0u00d4mc0k4rop61ho</loc>
    <lastmod>2023-09-18T14:34:43.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-FindUsersWhoReadMaliciousEmail&amp;clmozm9ii00d3mc0k0wetczkn</loc>
    <lastmod>2023-09-18T14:34:30.811Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailEvents-FindEmailswithPotentialPhishingURL&amp;clmozm1hc00d2mc0k78triqmc</loc>
    <lastmod>2023-09-18T14:34:20.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DailySummaryofO365AdminActivity&amp;clmozlu0f00d1mc0k8x2pgjiu</loc>
    <lastmod>2023-09-18T14:34:10.862Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LAQuery-VisualizeQueriesRun&amp;clmozloaz00d0mc0koibkajuc</loc>
    <lastmod>2023-09-18T14:34:03.467Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LAQuery-UsersvsAutomationQueryStats&amp;clmozlig200czmc0k1putgs59</loc>
    <lastmod>2023-09-18T14:33:55.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LAQuery-NewUsersQueryingData&amp;clmozl9oq00cymc0kfepu0c18</loc>
    <lastmod>2023-09-18T14:33:44.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LAQuery-FindQueryStats&amp;clmozl1u600cxmc0k9j18knkg</loc>
    <lastmod>2023-09-18T14:33:34.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-VisualizeMatchingDeviceIds&amp;clmozkwre00cvmc0k9bqsrrpp</loc>
    <lastmod>2023-09-18T14:33:27.770Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-VisualizeLastContact&amp;clmozkoqt00ctmc0k5ivo3l96</loc>
    <lastmod>2023-09-18T14:33:17.238Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-VisualizeDeviceJoinTypebyWeek&amp;clmozkgiy00crmc0kzt1o0s7f</loc>
    <lastmod>2023-09-18T14:33:06.730Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-VisualizeDeviceComplianceovertime&amp;clmozk8v500cpmc0klohgryuo</loc>
    <lastmod>2023-09-18T14:32:56.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-RetrieveDeviceInfoAfterWipe&amp;clmozk1yp00cnmc0k0dht2yjz</loc>
    <lastmod>2023-09-18T14:32:47.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IntuneDevices-FindDetailsofNonCompliantDevices&amp;clmozjuhh00clmc0k0z4hak2a</loc>
    <lastmod>2023-09-18T14:32:38.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IP-LabelDowngradeThenEmail&amp;clmozjo2x00cjmc0kxxdtsjhh</loc>
    <lastmod>2023-09-18T14:32:29.864Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IP-LabelDowngradeThenCopytoUSB&amp;clmozjg2r00chmc0kue9qlxq2</loc>
    <lastmod>2023-09-18T14:32:19.348Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Heartbeat-VisualizeDistinctComputersperMonth&amp;clmozj61400cfmc0ke302r67m</loc>
    <lastmod>2023-09-18T14:32:06.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Heartbeat-NoHeartbeatinTimeframe&amp;clmozj1ek00cdmc0k2e2xpz6g</loc>
    <lastmod>2023-09-18T14:32:00.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-UserLookup&amp;clmoziw4300cbmc0k9ra7tz3z</loc>
    <lastmod>2023-09-18T14:31:53.618Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-UserLogins&amp;clmozinrr00c9mc0k5u8lw0rm</loc>
    <lastmod>2023-09-18T14:31:42.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-UserInvestigation&amp;clmozih0v00c8mc0kuxo2ezri</loc>
    <lastmod>2023-09-18T14:31:34.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-TeamsAccess&amp;clmozi8gz00c6mc0k85kqhzjy</loc>
    <lastmod>2023-09-18T14:31:22.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-RetrieveAllDCs&amp;clmozhwyo00c4mc0k77sc0pzc</loc>
    <lastmod>2023-09-18T14:31:07.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-PrivilegeChanges&amp;clmozho0100c2mc0k0qn3logj</loc>
    <lastmod>2023-09-18T14:30:56.448Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-NewDetections&amp;clmozhebc00c0mc0kkwelv6x5</loc>
    <lastmod>2023-09-18T14:30:43.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-IdentityInfowithSigninRisk&amp;clmozh69s00bymc0kae4zlp5x</loc>
    <lastmod>2023-09-18T14:30:33.471Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-GuestDomainInfo&amp;clmozgzot00bwmc0k32asqen2</loc>
    <lastmod>2023-09-18T14:30:24.940Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-GroupChanges&amp;clmozgqlu00bumc0ka8i82uc0</loc>
    <lastmod>2023-09-18T14:30:13.169Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-FailedActiveDirectoryLogons&amp;clmozgirc00bsmc0ksllfnb3s</loc>
    <lastmod>2023-09-18T14:30:02.857Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-DeviceLookup&amp;clmozgd8q00bqmc0kdddoyvgc</loc>
    <lastmod>2023-09-18T14:29:55.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-AzureKeyVaultAccess&amp;clmozg05c00bomc0kvx0twsm1</loc>
    <lastmod>2023-09-18T14:29:38.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Function-ADGroupChanges&amp;clmozftns00bmmc0ky8zy5s2p</loc>
    <lastmod>2023-09-18T14:29:30.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Duo-LogParserwithIdentityInfo&amp;clmozfm7h00bkmc0kz0n3l7hj</loc>
    <lastmod>2023-09-18T14:29:20.812Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityLogonEvents-SummarizeNTLM&amp;clmozfg7d00bimc0k6b19pbr0</loc>
    <lastmod>2023-09-18T14:29:13.033Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityLogonEvents-SummarizeClearTextLDAP&amp;clmozf9as00bgmc0k3wqyfgcv</loc>
    <lastmod>2023-09-18T14:29:04.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-PasswordSettoNeverExpire&amp;clmozf4qa00bemc0kbrs65ory</loc>
    <lastmod>2023-09-18T14:28:58.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-EncryptionChange&amp;clmozeyeq00bcmc0kcqa5nu6e</loc>
    <lastmod>2023-09-18T14:28:49.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityDirectoryEvents-AccountDelegationChanged&amp;clmozerzn00bamc0ktywr7oyf</loc>
    <lastmod>2023-09-18T14:28:41.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vuln-PublicFacingDeviceswithKnownExploitedVuln&amp;clmozel4t00b8mc0kz90w369i</loc>
    <lastmod>2023-09-18T14:28:32.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vuln-KnownExploitableVuln&amp;clmozef9n00b6mc0kdd3hxii7</loc>
    <lastmod>2023-09-18T14:28:25.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vuln-InternetExposedDevices&amp;clmoze97i00b4mc0krttojlx0</loc>
    <lastmod>2023-09-18T14:28:17.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vuln-HighestExposedDevices&amp;clmoze3gq00b2mc0k81vqv9rn</loc>
    <lastmod>2023-09-18T14:28:09.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Vuln-CVE-2021-40444&amp;clmozdxdp00b0mc0k2x4gw48d</loc>
    <lastmod>2023-09-18T14:28:01.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-SummarizeInboundTraffic&amp;clmozdq5900aymc0kkr5vqty0</loc>
    <lastmod>2023-09-18T14:27:52.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-NoSSH&amp;clmozdioj00awmc0kqnm6plul</loc>
    <lastmod>2023-09-18T14:27:42.788Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-NoSMB&amp;clmozdb4800aumc0kigcfv5ow</loc>
    <lastmod>2023-09-18T14:27:33.127Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-NoRDP&amp;clmozd5xf00asmc0kntirvxsr</loc>
    <lastmod>2023-09-18T14:27:26.403Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-NoHTTP&amp;clmozd0qq00aqmc0kjb4ldp7r</loc>
    <lastmod>2023-09-18T14:27:19.681Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-msdtPotentialExploit&amp;clmozcujj00aomc0k9jjf1596</loc>
    <lastmod>2023-09-18T14:27:11.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-WindowsVersionPivotTable&amp;clmozcjil00ammc0kuuxmhy7e</loc>
    <lastmod>2023-09-18T14:26:57.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-Windows11DevicesandUsers&amp;clmozcc3500akmc0khwoei4qh</loc>
    <lastmod>2023-09-18T14:26:47.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeVolumeofDataCopiedtoUSB&amp;clmozc4sk00ajmc0ks3s20sll</loc>
    <lastmod>2023-09-18T14:26:38.275Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeRemotePowerShellURLs&amp;clmozbw9100ahmc0k2fmc280d</loc>
    <lastmod>2023-09-18T14:26:27.205Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeRDPClients&amp;clmozbprj00afmc0kvzxlk0z3</loc>
    <lastmod>2023-09-18T14:26:18.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizePort22Proccesses&amp;clmozbjfk00admc0k1mn9vnw4</loc>
    <lastmod>2023-09-18T14:26:10.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeOSBuildspermonth&amp;clmozbbzz00abmc0k52d8t199</loc>
    <lastmod>2023-09-18T14:26:00.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeMostCommonISOFiles&amp;clmozb3zo00a9mc0kzh5c5mr5</loc>
    <lastmod>2023-09-18T14:25:50.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeMaliciousSmartScreenURLs&amp;clmozatr200a7mc0ka5aete3h</loc>
    <lastmod>2023-09-18T14:25:37.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeASREventswithtrend&amp;clmozan6w00a5mc0k2wouef9f</loc>
    <lastmod>2023-09-18T14:25:28.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-UserAddedasLocalAdmin&amp;clmozag1e00a3mc0kay16biho</loc>
    <lastmod>2023-09-18T14:25:19.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-Top20RandomActions&amp;clmoza66y00a1mc0kcdg62uor</loc>
    <lastmod>2023-09-18T14:25:06.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-Top20DepartmentsCopyingDatatoUSBbySize&amp;clmoza075009zmc0k1qbf30yi</loc>
    <lastmod>2023-09-18T14:24:59.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-Top20DepartmentsCopyingDatatoUSBbyCount&amp;clmoz9s7c009xmc0kzneqii4j</loc>
    <lastmod>2023-09-18T14:24:48.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummaryofDeviceLogons&amp;clmoz9k5i009vmc0k78msqz19</loc>
    <lastmod>2023-09-18T14:24:38.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeSmartScreenUntrustedFiles&amp;clmoz9dpa009tmc0kdj3knvj6</loc>
    <lastmod>2023-09-18T14:24:29.711Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeSmartScreenPhishingDomains&amp;clmoz96yy009rmc0kxi4k188e</loc>
    <lastmod>2023-09-18T14:24:21.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeSSHPortOpenedInbound&amp;clmoz90db009pmc0klv6ggk5s</loc>
    <lastmod>2023-09-18T14:24:12.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeRDPConnections&amp;clmoz8u32009nmc0k08jbsd9r</loc>
    <lastmod>2023-09-18T14:24:04.430Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeMacroUsage&amp;clmoz8nki009lmc0k9rvag2by</loc>
    <lastmod>2023-09-18T14:23:55.841Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeLocalLogonActivity&amp;clmoz8dol009jmc0k4xky5qmc</loc>
    <lastmod>2023-09-18T14:23:43.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeLocalGroupAdditions&amp;clmoz8764009hmc0ks4bnfzr8</loc>
    <lastmod>2023-09-18T14:23:34.731Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SummarizeLDAPandLDAPStraffic&amp;clmoz814z009gmc0kz4lh262e</loc>
    <lastmod>2023-09-18T14:23:26.915Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SSHTrafficOnNonStandardPort&amp;clmoz7tyq009emc0kunkziei0</loc>
    <lastmod>2023-09-18T14:23:17.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-PublicPort22Allowed&amp;clmoz7kt4009cmc0kmbjs6a25</loc>
    <lastmod>2023-09-18T14:23:05.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ProcessModifiedPrimaryToken&amp;clmoz7da6009amc0ke8so9up7</loc>
    <lastmod>2023-09-18T14:22:55.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-PowershellConnectingtoInternet&amp;clmoz74q70098mc0k1uq9khnx</loc>
    <lastmod>2023-09-18T14:22:44.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-PowerShellExecutionModeChanged&amp;clmoz6xe20096mc0kpzii8std</loc>
    <lastmod>2023-09-18T14:22:35.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-PotentialDNSTunnelling&amp;clmoz6rc50094mc0klnr7calm</loc>
    <lastmod>2023-09-18T14:22:27.556Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ParseURL&amp;clmoz6lda0092mc0k4pureyyg</loc>
    <lastmod>2023-09-18T14:22:19.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-NewHashAccessingLSASS&amp;clmoz6e4i0090mc0k4k5750mg</loc>
    <lastmod>2023-09-18T14:22:10.433Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-NewASREvents&amp;clmoz69cg008ymc0kdrapl7wk</loc>
    <lastmod>2023-09-18T14:22:04.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-LocalUserswithAdmin&amp;clmoz63p7008wmc0k8e8qb0u5</loc>
    <lastmod>2023-09-18T14:21:56.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-InterestingPortsOpened&amp;clmoz5uey008umc0k84508qnx</loc>
    <lastmod>2023-09-18T14:21:44.889Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FirstTimeWhoAmI&amp;clmoz5om8008smc0k7w7cro05</loc>
    <lastmod>2023-09-18T14:21:37.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindUsersWhoClickedonPhishing&amp;clmoz5g85008qmc0khqcoz49x</loc>
    <lastmod>2023-09-18T14:21:26.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindNewEvents&amp;clmoz5980008omc0klchbgixg</loc>
    <lastmod>2023-09-18T14:21:17.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindNewDevices&amp;clmoz53la008mmc0kjggw47ei</loc>
    <lastmod>2023-09-18T14:21:10.125Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindNetworkRecon&amp;clmoz4xfs008kmc0kmonplchp</loc>
    <lastmod>2023-09-18T14:21:02.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDeviceswithnoASR&amp;clmoz4qnx008imc0kufft6for</loc>
    <lastmod>2023-09-18T14:20:53.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDeviceswithmostSmartScreenEvents&amp;clmoz4huh008gmc0kmdv9th4q</loc>
    <lastmod>2023-09-18T14:20:41.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDevicesToOnboard&amp;clmoz49u1008fmc0ks8wri5gr</loc>
    <lastmod>2023-09-18T14:20:31.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDevicesNoLongerSendingEvents&amp;clmoz42kp008emc0kzilkigb3</loc>
    <lastmod>2023-09-18T14:20:22.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDevicesMostASR&amp;clmoz3x28008dmc0kj8zfbfuw</loc>
    <lastmod>2023-09-18T14:20:15.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FindDeviceWithoutCurrentAVScan&amp;clmoz3p0o008cmc0kogddy2y7</loc>
    <lastmod>2023-09-18T14:20:04.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FilesCopiedtoUSBCertainGroups&amp;clmoz3hng008bmc0kcvokq82y</loc>
    <lastmod>2023-09-18T14:19:55.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FileDownloadedfromO365thenCopiedtoUSB&amp;clmoz39nh008amc0kpr4dolfk</loc>
    <lastmod>2023-09-18T14:19:44.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectURLopenedfromISOfile&amp;clmoz2zwk0089mc0kxb7qjsk0</loc>
    <lastmod>2023-09-18T14:19:32.035Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectSecurityLogCleared&amp;clmoz2s1x0088mc0k0c331hid</loc>
    <lastmod>2023-09-18T14:19:21.717Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectRegistryTampering&amp;clmoz2mkb0087mc0khlrisj04</loc>
    <lastmod>2023-09-18T14:19:14.746Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectRDPRecon&amp;clmoz2fxk0086mc0kraxbajo3</loc>
    <lastmod>2023-09-18T14:19:06.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectPuttyConnectingPublic&amp;clmoz29rw0085mc0k96pbllyy</loc>
    <lastmod>2023-09-18T14:18:58.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectPotentialNetworkRecon&amp;clmoz23gi0084mc0k7km3kn9n</loc>
    <lastmod>2023-09-18T14:18:49.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectMultipleFailedRemoteLogons&amp;clmoz1wxs0083mc0k34ykgfpt</loc>
    <lastmod>2023-09-18T14:18:41.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectMacroUsage&amp;clmoz1py00082mc0kgdne898k</loc>
    <lastmod>2023-09-18T14:18:32.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectMacroConnectingtoInternet&amp;clmoz1g7x0081mc0kl6d1cjqm</loc>
    <lastmod>2023-09-18T14:18:19.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectLogonsPriortoMDEAlert&amp;clmoz19k9007zmc0kuofo861l</loc>
    <lastmod>2023-09-18T14:18:11.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectLocaltoPublicRDP&amp;clmoz12lv007xmc0kz26hz22f</loc>
    <lastmod>2023-09-18T14:18:02.226Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectLocalUserCreated&amp;clmoz0uox007vmc0ksm5cnsxb</loc>
    <lastmod>2023-09-18T14:17:51.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectLocalAdminsWhoHaventElevated&amp;clmoz0ohf007tmc0kkm7i3cq5</loc>
    <lastmod>2023-09-18T14:17:43.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectInternaltoExternalTeamviewer&amp;clmoz0gtn007rmc0kq4812ttt</loc>
    <lastmod>2023-09-18T14:17:33.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectInboundPublicRDP&amp;clmoz0ae3007pmc0kujs5z0ao</loc>
    <lastmod>2023-09-18T14:17:25.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectFirstTimeTeamviewerUsage&amp;clmoz02td007nmc0kj6dvxfpw</loc>
    <lastmod>2023-09-18T14:17:15.840Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectEncodedPowershellandDecode&amp;clmoyzwmo007lmc0kc2i71vb6</loc>
    <lastmod>2023-09-18T14:17:07.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectCredentialBackup&amp;clmoyzpw5007jmc0ksnmmww24</loc>
    <lastmod>2023-09-18T14:16:59.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectCertUtilConnectingExternally&amp;clmoyzjj3007hmc0k6i1dk8ml</loc>
    <lastmod>2023-09-18T14:16:50.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DetectAnomalousRDPConnections&amp;clmoyzd81007fmc0k17bfjpk6</loc>
    <lastmod>2023-09-18T14:16:42.672Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-CreateSetofLocalAdminsperDevice&amp;clmoyz72o007dmc0kjepc0zvd</loc>
    <lastmod>2023-09-18T14:16:34.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-AccountswithMostLocalAdmin&amp;clmoyz202007bmc0k83syl8ip</loc>
    <lastmod>2023-09-18T14:16:27.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ASRSummary&amp;clmoyyvug0079mc0kebhz2lw5</loc>
    <lastmod>2023-09-18T14:16:20.151Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ASROfficeChildProcessAudit&amp;clmoyyqhw0077mc0kzzs1hjzg</loc>
    <lastmod>2023-09-18T14:16:13.220Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ASRLsassAudit&amp;clmoyykxk0076mc0kwlre45fy</loc>
    <lastmod>2023-09-18T14:16:06.008Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ASRAudit&amp;clmoyy9fd0074mc0ko7hlg36y</loc>
    <lastmod>2023-09-18T14:15:50.954Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anamoly-USBFileCopiesfromUserswithAnamolousDownloads&amp;clmoyxzsn0073mc0k1ia7zyd1</loc>
    <lastmod>2023-09-18T14:15:38.614Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-VisualizeEmojiReactions&amp;clmoyxr4b0071mc0k39nhtb3i</loc>
    <lastmod>2023-09-18T14:15:27.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-TeamsAppInstalled&amp;clmoyxjzm006zmc0kgbdcfpfl</loc>
    <lastmod>2023-09-18T14:15:17.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-SuspiciousMailboxRuleCreated&amp;clmoyxets006ymc0k76knpfkf</loc>
    <lastmod>2023-09-18T14:15:11.438Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-RiskEventFollowedbyMailboxRuleChanges&amp;clmoyx779006xmc0kaxu3vcpx</loc>
    <lastmod>2023-09-18T14:15:01.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-RiskEventFollowedbyEmailForward&amp;clmoywzp9006wmc0kwnqflpjw</loc>
    <lastmod>2023-09-18T14:14:51.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-PotentialConsentPhishing&amp;clmoywprh006vmc0k2zigv83o</loc>
    <lastmod>2023-09-18T14:14:38.814Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-PivotTableAdminOperations&amp;clmoywfsy006umc0kepotwmj9</loc>
    <lastmod>2023-09-18T14:14:26.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-PivotTableAdminActions&amp;clmoywaf3006tmc0kbgvvh1ir</loc>
    <lastmod>2023-09-18T14:14:18.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-PaidTrialStarted&amp;clmoyw2r2006smc0kpp02bimc</loc>
    <lastmod>2023-09-18T14:14:09.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-FormPhishingStatusChanged&amp;clmoyvx23006rmc0kby0gemp6</loc>
    <lastmod>2023-09-18T14:14:01.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-FindUserSubmittedPhishingSpam&amp;clmoyvoya006qmc0k2yozncfy</loc>
    <lastmod>2023-09-18T14:13:51.249Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-FindNewEvents&amp;clmoyvht2006pmc0katwdcrf6</loc>
    <lastmod>2023-09-18T14:13:41.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-FindAzureADAdminActions&amp;clmoyv84w006omc0khq43wfe6</loc>
    <lastmod>2023-09-18T14:13:29.455Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-ExchangeOnlineEventsduringRiskySignin&amp;clmoyv2n9006nmc0k03q2ho0u</loc>
    <lastmod>2023-09-18T14:13:22.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-DetectMailboxForward&amp;clmoyux3s006mmc0k7vpbd141</loc>
    <lastmod>2023-09-18T14:13:15.159Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-DetectAdminGrantingOwnAccesstoMailbox&amp;clmoyuqfe006lmc0k7prz40c3</loc>
    <lastmod>2023-09-18T14:13:06.363Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DCA-DetectAADInternalsUse&amp;clmoyujqq006kmc0kzfogj1b1</loc>
    <lastmod>2023-09-18T14:12:57.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data-TableSizePerMDEDevice&amp;clmoyubgn006jmc0kgyaxbu43</loc>
    <lastmod>2023-09-18T14:12:46.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data-NewTablesFound&amp;clmoyqt68006imc0k0zj64tho</loc>
    <lastmod>2023-09-18T14:10:03.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data-DetectAnomalousDataIngestion&amp;clmoyqn35006hmc0kzpel7eqy</loc>
    <lastmod>2023-09-18T14:09:55.410Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data-CalculateTableSizeChanges&amp;clmoyqax8006gmc0kvrzbkdq4</loc>
    <lastmod>2023-09-18T14:09:39.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data-CalculatePercentageperTable&amp;clmoyq2iv006fmc0koi0uewed</loc>
    <lastmod>2023-09-18T14:09:28.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/365-Visualize365DaysofKql&amp;clmoypun1006emc0kxlqnnbo4</loc>
    <lastmod>2023-09-18T14:09:18.684Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DnsEvents-FindStaleDomains&amp;clmoypqhz006dmc0ko28xped6</loc>
    <lastmod>2023-09-18T14:09:13.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DNS-FindDevicesThatHaveQueriedSuspiciousDomains&amp;clmoypi8o006cmc0kv9ey3won</loc>
    <lastmod>2023-09-18T14:09:02.615Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-VisualizeMitreAtt%26ck&amp;clmoypcmq006bmc0kwmgxphf3</loc>
    <lastmod>2023-09-18T14:08:55.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-VisualizeIncidentswithTrend&amp;clmoyp7zl006amc0krydihqah</loc>
    <lastmod>2023-09-18T14:08:49.185Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-VisualizeIncidentSeverity&amp;clmoyp23i0069mc0k7hp7m5w2</loc>
    <lastmod>2023-09-18T14:08:41.693Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-PlaybookActivities&amp;clmoyowxf0068mc0kuam8cpzj</loc>
    <lastmod>2023-09-18T14:08:34.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-DaysSinceLastIncident&amp;clmoyorhj0067mc0k1hxl2jj2</loc>
    <lastmod>2023-09-18T14:08:27.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-PotentiallySensitiveOperations&amp;clmoyom250066mc0kfvgd76c6</loc>
    <lastmod>2023-09-18T14:08:20.908Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-ObjectIDAddedtoAccessPolicy&amp;clmoyog9l0065mc0k4jl7zfp2</loc>
    <lastmod>2023-09-18T14:08:13.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-IPAddedtoFirewall&amp;clmoyo9ff0064mc0kvlqucong</loc>
    <lastmod>2023-09-18T14:08:04.538Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-DefaultFirewallRuleSettoAllow&amp;clmoyo3i00063mc0kby0w9a71</loc>
    <lastmod>2023-09-18T14:07:56.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-AnomalousKeyVaultAccessbyUser&amp;clmoynv2c0062mc0kmymywwy7</loc>
    <lastmod>2023-09-18T14:07:45.923Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KeyVault-AnomalousKeyVaultAccessbyApp&amp;clmoynoj00061mc0kj07eo5b4</loc>
    <lastmod>2023-09-18T14:07:37.309Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2021-44228&amp;clmoynhpw0060mc0kaeru8r1x</loc>
    <lastmod>2023-09-18T14:07:28.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVE-2021-44228-2&amp;clmoyn7m2005zmc0ka3rkrsvp</loc>
    <lastmod>2023-09-18T14:07:15.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppGateway-VisualizeWAFTraffic&amp;clmoymxey005ymc0kuv64uj2y</loc>
    <lastmod>2023-09-18T14:07:02.313Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppGateway-MostAttackedHostName&amp;clmoymqgh005xmc0kr2usl31h</loc>
    <lastmod>2023-09-18T14:06:53.296Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Bastion-SummarizeAccountAccess&amp;clmoymk8y005wmc0k3qgvzv1f</loc>
    <lastmod>2023-09-18T14:06:45.250Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Bastion-AuditUsage&amp;clmoymf62005vmc0k0uxecpfp</loc>
    <lastmod>2023-09-18T14:06:38.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Sentinel-DetectAccessAddedtoWorkspace&amp;clmoym90l005umc0kwiabeh83</loc>
    <lastmod>2023-09-18T14:06:30.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureVM-DiskImageURLGenerated&amp;clmoym050005tmc0kf4l6bfhh</loc>
    <lastmod>2023-09-18T14:06:19.045Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureStorage-FirstTimeStorageKeyEnumeration&amp;clmoylun6005smc0kr7hn1hf7</loc>
    <lastmod>2023-09-18T14:06:12.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureLogAnalytics-DetectwhenWorkspaceKeysareRead&amp;clmoylnfc005rmc0k0igme64c</loc>
    <lastmod>2023-09-18T14:06:02.569Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure-ServicePrincipalAddedtoAzure&amp;clmoyle9w005qmc0kmbuqmjb7</loc>
    <lastmod>2023-09-18T14:05:50.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure-ResourceLockAddedorRemoved&amp;clmoyl80l005pmc0kt1uomp7y</loc>
    <lastmod>2023-09-18T14:05:42.598Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SSPR-PasswordResetInitiatedviaMSGraph&amp;clmoyl16n005omc0kgaxaf4qi</loc>
    <lastmod>2023-09-18T14:05:33.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PIM-UserAssignedRolebutHasntActivated&amp;clmoyksrl005nmc0kfzbn7f2x</loc>
    <lastmod>2023-09-18T14:05:22.834Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-TrackEventsonServicePrincipals&amp;clmoykh88005mmc0kla4x9ffb</loc>
    <lastmod>2023-09-18T14:05:08.023Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-SummarizeServicePrincipalInactivity&amp;clmoyk9wl005lmc0ktladbhch</loc>
    <lastmod>2023-09-18T14:04:58.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-SummarizePermissionGrantedtoApps&amp;clmoyk3o6005kmc0kftts6dmr</loc>
    <lastmod>2023-09-18T14:04:50.453Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-SummarizeCurrentAppPermissions&amp;clmoyjwoo005jmc0krire9p08</loc>
    <lastmod>2023-09-18T14:04:41.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-PermissionsAddedRemoved&amp;clmoyjjky005imc0kfgcohzog</loc>
    <lastmod>2023-09-18T14:04:24.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-InactiveServicePrincipalswithPrivilege&amp;clmoyj8vq005hmc0khv6c1h33</loc>
    <lastmod>2023-09-18T14:04:10.407Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-FirstTimeAppConsent&amp;clmoyj1bv005gmc0keuiwsd5t</loc>
    <lastmod>2023-09-18T14:04:00.762Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-DetectingFirstTimeCredentialAddition&amp;clmoyit9i005fmc0kdbmxxn9g</loc>
    <lastmod>2023-09-18T14:03:50.167Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-DelegatedPermissionsGrant&amp;clmoyil5s005emc0kajxht344</loc>
    <lastmod>2023-09-18T14:03:39.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-ApporDelegatedAccessGranted&amp;clmoyifhc005dmc0k7r6g8ek2</loc>
    <lastmod>2023-09-18T14:03:32.305Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OAuth-ApplicationPermissionsGrant&amp;clmoyi9za005cmc0kmuaagg51</loc>
    <lastmod>2023-09-18T14:03:25.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-YourUsersSigningIntoOtherTenantsAsGuests&amp;clmoyi332005bmc0k5a8irrum</loc>
    <lastmod>2023-09-18T14:03:16.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeWorldMap&amp;clmoyhwrt005amc0ks9ref8jd</loc>
    <lastmod>2023-09-18T14:03:08.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeTotalvsDistinctsignins&amp;clmoyhq880059mc0k41m16vm0</loc>
    <lastmod>2023-09-18T14:02:59.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeSigninsbyDeviceTrust&amp;clmoyhgpl0058mc0kvtckz7mr</loc>
    <lastmod>2023-09-18T14:02:47.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeSSPR&amp;clmoyh9nf0057mc0kqvtrmamj</loc>
    <lastmod>2023-09-18T14:02:38.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeRiskEventsoverTime&amp;clmoyh23f0056mc0k5f9wyivy</loc>
    <lastmod>2023-09-18T14:02:28.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizePasswordvsPasswordless&amp;clmoygw770054mc0kopvt77n9</loc>
    <lastmod>2023-09-18T14:02:20.660Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeMFAMethodsovertime&amp;clmoygpo90052mc0kpnfonpls</loc>
    <lastmod>2023-09-18T14:02:12.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeMFAMethods&amp;clmoygh7d0050mc0kkb5a19dk</loc>
    <lastmod>2023-09-18T14:02:01.369Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeMFAChallengevsPreviouslySatisfied&amp;clmoyga0o004ymc0k8y7sa5mm</loc>
    <lastmod>2023-09-18T14:01:52.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeLegacyAuthMethods&amp;clmoyg3tw004wmc0ks1yg2zhv</loc>
    <lastmod>2023-09-18T14:01:44.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeLegacyAuth&amp;clmoyfw11004umc0kyg0ekjsp</loc>
    <lastmod>2023-09-18T14:01:33.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeKnownvsUnknownLocation&amp;clmoyfohg004smc0kw758vila</loc>
    <lastmod>2023-09-18T14:01:24.146Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeInboundvsOutboundGuests&amp;clmoyfjam004qmc0k1rmtepsv</loc>
    <lastmod>2023-09-18T14:01:17.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeGuestRedemptionswithTrend&amp;clmoyfd1z004omc0km34t3b8o</loc>
    <lastmod>2023-09-18T14:01:09.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeGuestDomains&amp;clmoyf5ux004mmc0k0mmmqxcv</loc>
    <lastmod>2023-09-18T14:00:59.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeGuestAppAccess&amp;clmoyez89004kmc0kp7kzh9br</loc>
    <lastmod>2023-09-18T14:00:51.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeExternalAADGuestsvsExternalGuests&amp;clmoyes42004jmc0krq5dyu8w</loc>
    <lastmod>2023-09-18T14:00:42.050Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeDistinctInboundGuests&amp;clmoyel45004imc0kb36bpf14</loc>
    <lastmod>2023-09-18T14:00:33.124Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeControlsvsNoControls&amp;clmoyee9z004hmc0k062bwiwe</loc>
    <lastmod>2023-09-18T14:00:24.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualizeConditionalAccessFailures&amp;clmoye6lo004gmc0kz40xpdyf</loc>
    <lastmod>2023-09-18T14:00:14.315Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-VisualStdDevofMFAFailures&amp;clmoye0t9004fmc0k7ofyy0wd</loc>
    <lastmod>2023-09-18T14:00:06.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-UserTryingtoAccessMultipleApps&amp;clmoydqhs004emc0khy1n09b8</loc>
    <lastmod>2023-09-18T13:59:53.439Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-UserReportedSuspiciousMFA&amp;clmoydjt9004dmc0kghaeppe9</loc>
    <lastmod>2023-09-18T13:59:44.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-Top20RiskyLocations&amp;clmoyd9ti004cmc0k9zoqcl85</loc>
    <lastmod>2023-09-18T13:59:31.830Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-Top20RandomStats&amp;clmoy1vv9004bmc0k6hz29our</loc>
    <lastmod>2023-09-18T13:50:40.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-Top20AppswithnoCA&amp;clmoy1fqt004amc0k9z88c2bv</loc>
    <lastmod>2023-09-18T13:50:19.635Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ThirdPartyMFAFailures&amp;clmoy17xu0049mc0kxa6rs72f</loc>
    <lastmod>2023-09-18T13:50:09.374Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeUnknownLocationnoMFA&amp;clmoy0urw0048mc0k4oprzyds</loc>
    <lastmod>2023-09-18T13:49:52.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeSuspiciousIPAddresses&amp;clmoy0ntp0047mc0kkmqxmbbg</loc>
    <lastmod>2023-09-18T13:49:43.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeSigninInfoafterMFAconfig&amp;clmoy0efv0046mc0ka6uesf6t</loc>
    <lastmod>2023-09-18T13:49:31.148Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeOutboundGuestActivity&amp;clmoy059f0045mc0k1xdgidv7</loc>
    <lastmod>2023-09-18T13:49:19.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeMFATop20Apps&amp;clmoxzydn0043mc0k400c61uk</loc>
    <lastmod>2023-09-18T13:49:10.333Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeMFAFailures&amp;clmoxzq0w0041mc0kdebmp7k4</loc>
    <lastmod>2023-09-18T13:48:59.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeLoginInfofromMaliciousIP&amp;clmoxzjcv003zmc0k8v0mo55s</loc>
    <lastmod>2023-09-18T13:48:51.006Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeLocationSignins&amp;clmoxz8kn003xmc0kqpu569j0</loc>
    <lastmod>2023-09-18T13:48:36.888Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeLegacyAuth&amp;clmoxz11h003vmc0k5yszygvn</loc>
    <lastmod>2023-09-18T13:48:27.269Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeInternetExplorerSignins&amp;clmoxyroh003tmc0kmggvh5ij</loc>
    <lastmod>2023-09-18T13:48:15.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeGuestTenantActivity&amp;clmoxyidf003rmc0kjv3771ou</loc>
    <lastmod>2023-09-18T13:48:03.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeGuestInactivity&amp;clmoxyb8i003pmc0k84s6n0j4</loc>
    <lastmod>2023-09-18T13:47:53.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeGuestDomainbyType&amp;clmoxy38r003nmc0kwifemyk1</loc>
    <lastmod>2023-09-18T13:47:43.466Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeGuestConditionalAccess&amp;clmoxxy2y003lmc0klwnzep3j</loc>
    <lastmod>2023-09-18T13:47:36.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeConditionalAccessPoliciesfailures&amp;clmoxxptf003jmc0kaizi4go1</loc>
    <lastmod>2023-09-18T13:47:26.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeAppUsageMonthonMonth&amp;clmoxxjg5003hmc0kdkm6t7u1</loc>
    <lastmod>2023-09-18T13:47:17.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SummarizeAccountInactivity&amp;clmoxxbak003fmc0kdjy5mcee</loc>
    <lastmod>2023-09-18T13:47:07.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SingleFactorSigninsFromPrivUsers&amp;clmoxx28c003emc0kccas18ui</loc>
    <lastmod>2023-09-18T13:46:55.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SingleFactorConnectionstoAzure&amp;clmoxwu27003dmc0k4h01bd6h</loc>
    <lastmod>2023-09-18T13:46:44.769Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalswithSingleIP&amp;clmoxwi8p003cmc0k9vrlz6fj</loc>
    <lastmod>2023-09-18T13:46:29.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalsOnlyExpiredSecret&amp;clmoxwazp003bmc0kvvs9d90m</loc>
    <lastmod>2023-09-18T13:46:20.055Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalsMultipleLocations&amp;clmoxw39h003amc0ky4f7weo8</loc>
    <lastmod>2023-09-18T13:46:10.181Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalSummaryofResources&amp;clmoxvun70039mc0ktnay1trl</loc>
    <lastmod>2023-09-18T13:45:58.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalSigninsbyIP&amp;clmoxvo9b0038mc0krit7g5sx</loc>
    <lastmod>2023-09-18T13:45:50.734Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalSigninfromnewIP&amp;clmoxviy10037mc0kbia7cnlj</loc>
    <lastmod>2023-09-18T13:45:43.707Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalSigninErrors&amp;clmoxvcct0036mc0ksyldvg91</loc>
    <lastmod>2023-09-18T13:45:35.308Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalExpiredSecret&amp;clmoxv6nh0035mc0koqbm37xd</loc>
    <lastmod>2023-09-18T13:45:27.774Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ServicePrincipalCreatedbyManagedIdentity&amp;clmoxuttd0034mc0kpr9ekal7</loc>
    <lastmod>2023-09-18T13:45:11.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SecurityAlertWithNewAgent&amp;clmoxunw00033mc0k4h5ofgba</loc>
    <lastmod>2023-09-18T13:45:03.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-SSPRfollowedbyRiskySignin&amp;clmoxufdp0032mc0klp428z6h</loc>
    <lastmod>2023-09-18T13:44:52.431Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-RoleAddedtoServicePrincipal&amp;clmoxu7dp0031mc0kn7956jmd</loc>
    <lastmod>2023-09-18T13:44:42.204Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-RiskySigninFollowedbyAdminMFAChange&amp;clmoxtzp50030mc0kzyeos17u</loc>
    <lastmod>2023-09-18T13:44:32.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-RiskyMFARequirementfollowedbyMFAregistration&amp;clmoxtr8s002zmc0k8kcskaxz</loc>
    <lastmod>2023-09-18T13:44:21.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-RiskEventfollowedbyMFAchanges&amp;clmoxtjbx002ymc0k9f1yiblf</loc>
    <lastmod>2023-09-18T13:44:11.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-PotentialMFASpam&amp;clmoxt7wu002xmc0k9uq245pq</loc>
    <lastmod>2023-09-18T13:43:56.096Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-PotentialMFANumberMatchingAbuse&amp;clmoxsoy3002wmc0kk6kb765o</loc>
    <lastmod>2023-09-18T13:43:31.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-PotentialAppRecon&amp;clmoxsfbq002vmc0kylt0u4ge</loc>
    <lastmod>2023-09-18T13:43:19.047Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-PotentialAiTM&amp;clmoxs5q2002umc0kytnd5xo6</loc>
    <lastmod>2023-09-18T13:43:06.745Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ParseUserAgent&amp;clmoxrwnu002tmc0k2lnnqbnz</loc>
    <lastmod>2023-09-18T13:42:54.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ParseIPInfofromSecurityAlert&amp;clmoxr9mm002smc0k6sq8zyw1</loc>
    <lastmod>2023-09-18T13:42:25.149Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MultipleMFAFailuresPrivUsers&amp;clmoxr2cz002rmc0kc1vh5lte</loc>
    <lastmod>2023-09-18T13:42:15.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MultipleCAFailures&amp;clmoxqu39002qmc0k837l7bw0</loc>
    <lastmod>2023-09-18T13:42:05.012Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MuiltipleConditionalAccessFailures&amp;clmoxql7r002pmc0kgfhx27i2</loc>
    <lastmod>2023-09-18T13:41:53.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ManagedIdentitySummaryofResources&amp;clmoxq5w0002omc0kjjvtago9</loc>
    <lastmod>2023-09-18T13:41:33.648Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ManagedIdentityAccessingNewResources&amp;clmoxpzz9002nmc0knu8iz258</loc>
    <lastmod>2023-09-18T13:41:25.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFARegistrationfollowedbySSPR&amp;clmoxpq50002mmc0knl4wr1k6</loc>
    <lastmod>2023-09-18T13:41:13.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFAPercentageperapp&amp;clmoxpjz5002lmc0kbj48a5bt</loc>
    <lastmod>2023-09-18T13:41:05.107Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFANewLocationandMethod&amp;clmoxpbww002kmc0kvaba8ak6</loc>
    <lastmod>2023-09-18T13:40:54.799Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFAMethodsPivotTable&amp;clmoxp21n002jmc0kilggntj8</loc>
    <lastmod>2023-09-18T13:40:41.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFACountPerUser&amp;clmoxox5a002imc0kl93taike</loc>
    <lastmod>2023-09-18T13:40:35.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-MFAChangesfromunknownIP&amp;clmoxop9f002hmc0kcasood0s</loc>
    <lastmod>2023-09-18T13:40:25.301Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-LegacyAuthPivotTable&amp;clmoxofow002gmc0kl2stnzd7</loc>
    <lastmod>2023-09-18T13:40:13.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-InactivePrivilegedUsers&amp;clmoxo8b4002fmc0kq9h6hi76</loc>
    <lastmod>2023-09-18T13:40:03.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-InactiveGuestAccounts&amp;clmoxnysa002emc0k9htw7uvu</loc>
    <lastmod>2023-09-18T13:39:51.129Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-HighMediumRealtimeRiskforAADRoles&amp;clmoxnp62002dmc0k1xiwf6yl</loc>
    <lastmod>2023-09-18T13:39:38.524Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-GuestsInvitedbutnotRedeemed&amp;clmoxn8l5002cmc0kzcv05n9s</loc>
    <lastmod>2023-09-18T13:39:17.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-GuestsAccessingNewApplications&amp;clmoxn2qv002bmc0kkerq38i0</loc>
    <lastmod>2023-09-18T13:39:09.465Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-GuestTypeParser&amp;clmoxmvho002amc0k5bbfenno</loc>
    <lastmod>2023-09-18T13:39:00.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-GuestInvitesSentvsRedeemed&amp;clmoxmn2w0029mc0kdgg7ca50</loc>
    <lastmod>2023-09-18T13:38:49.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-GuestAddedtoAADRole&amp;clmoxmcli0028mc0k8gyb0irt</loc>
    <lastmod>2023-09-18T13:38:35.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FirstTimeSPBlockedbyCA&amp;clmoxm4dy0027mc0kp3n024hx</loc>
    <lastmod>2023-09-18T13:38:24.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FirstTimeRoleAddition&amp;clmoxlr7d0026mc0ks25hy7mi</loc>
    <lastmod>2023-09-18T13:38:07.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FirstTimeLegacyAuth&amp;clmoxlkkm0025mc0kumdz4je7</loc>
    <lastmod>2023-09-18T13:37:59.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FirstPartyApps&amp;clmoxlbyo0024mc0ksi0nkk98</loc>
    <lastmod>2023-09-18T13:37:48.239Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindUsersOnlyusingTextforMFA&amp;clmoxl4pf0023mc0kno93fw4d</loc>
    <lastmod>2023-09-18T13:37:38.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindUsersMultipleCountriesSameDay&amp;clmoxkxvd0022mc0ktprttj9m</loc>
    <lastmod>2023-09-18T13:37:29.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindNewEnterpriseApps&amp;clmoxkpw80021mc0kpjedcqp6</loc>
    <lastmod>2023-09-18T13:37:19.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindMultipleCASuccesses&amp;clmoxkiky0020mc0kv2rcyiy9</loc>
    <lastmod>2023-09-18T13:37:10.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindInactiveServicePrincipals&amp;clmoxkb27001zmc0kwdxhkiac</loc>
    <lastmod>2023-09-18T13:37:00.273Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindInactiveManagedIdentities&amp;clmoxk1eu001xmc0k5yb6odw6</loc>
    <lastmod>2023-09-18T13:36:47.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindGuestsAccessingMostApps&amp;clmoxjrh3001vmc0kosqc09m4</loc>
    <lastmod>2023-09-18T13:36:34.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindCAFailurePercentage&amp;clmoxjebq001tmc0kpa41mpia</loc>
    <lastmod>2023-09-18T13:36:17.849Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-FindAppswithNoSignins&amp;clmoxj77v001rmc0k4e1g5zc2</loc>
    <lastmod>2023-09-18T13:36:08.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-DeviceCodePhishing&amp;clmoxj0jh001pmc0kmrq09tvo</loc>
    <lastmod>2023-09-18T13:35:59.984Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-DetectingFirstTimeAccesstoAzureManagement&amp;clmoxispa001nmc0kl0ecmor3</loc>
    <lastmod>2023-09-18T13:35:49.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-DetectMultipleDistinctRiskEvents&amp;clmoxijem001lmc0kh0mc8ems</loc>
    <lastmod>2023-09-18T13:35:37.776Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-DailySummaryofUsersAddedtoAADGroups&amp;clmoxidkw001kmc0kcrthpadb</loc>
    <lastmod>2023-09-18T13:35:30.368Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ConditionalAccessPoliciesNotinUse&amp;clmoxi6vf001imc0klii1qi4w</loc>
    <lastmod>2023-09-18T13:35:21.533Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ConditionalAccessPivotTable&amp;clmoxi20z001gmc0k8hri7h3q</loc>
    <lastmod>2023-09-18T13:35:15.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ConditionalAccessMostFailures&amp;clmoxhw07001emc0kf70a9be2</loc>
    <lastmod>2023-09-18T13:35:07.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-CalculateRiskyUsers&amp;clmoxhobn001cmc0k2qjohywj</loc>
    <lastmod>2023-09-18T13:34:57.494Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-CalculateRiskyApps&amp;clmoxhhjq001amc0k1ky4avyk</loc>
    <lastmod>2023-09-18T13:34:48.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-CAPolicyStats&amp;clmoxhaqc0018mc0k3nqpm9re</loc>
    <lastmod>2023-09-18T13:34:39.879Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AuthStrengthMFASFAPercentage&amp;clmoxh1ao0016mc0ktuhwb2gv</loc>
    <lastmod>2023-09-18T13:34:27.792Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AppswithmostSFAPrivUsers&amp;clmoxgt5l0014mc0k1aspbl8q</loc>
    <lastmod>2023-09-18T13:34:17.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AppsWithMoreGuests&amp;clmoxglmk0012mc0krj2j9xbg</loc>
    <lastmod>2023-09-18T13:34:07.483Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-ApplicationAccessReview&amp;clmoxgezm0010mc0k9uhh5vl9</loc>
    <lastmod>2023-09-18T13:33:58.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AppAccessMembersvsGuests&amp;clmoxg7fu000ymc0ku6p1u7o0</loc>
    <lastmod>2023-09-18T13:33:49.097Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AnomalousConditionalAccessFailures&amp;clmoxg0qj000wmc0kvqxheny6</loc>
    <lastmod>2023-09-18T13:33:40.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AlertsFromPrivilegedUsers&amp;clmoxfo6p000umc0kezspp9az</loc>
    <lastmod>2023-09-18T13:33:24.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AlertGuestDeniedAccesstoMultipleApps&amp;clmoxfga7000smc0k56m5bc0f</loc>
    <lastmod>2023-09-18T13:33:13.761Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AdminUpdatingSecurityInfo&amp;clmoxf52a000qmc0knsk9fz2r</loc>
    <lastmod>2023-09-18T13:32:59.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AADRiskEventCorrelation&amp;clmoxez3x000omc0k4oxj6rcc</loc>
    <lastmod>2023-09-18T13:32:51.503Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-VisualizeSSPRSuccessvsFailure&amp;clmoxep6m000mmc0k4md26ub8</loc>
    <lastmod>2023-09-18T13:32:38.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-UserswithPrivRolesbutnoActivity&amp;clmoxehog000kmc0knjc9zh88</loc>
    <lastmod>2023-09-18T13:32:28.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-UsersWhoHaventElevatedPIM&amp;clmoxe651000imc0kk1t1q8w8</loc>
    <lastmod>2023-09-18T13:32:14.101Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-UsersAddedtoDynamicGroups&amp;clmoxe01v000gmc0kq77zvolw</loc>
    <lastmod>2023-09-18T13:32:06.210Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-UserAddedtoRoleOutsidePIM&amp;clmoxdue9000emc0k3diymeuy</loc>
    <lastmod>2023-09-18T13:31:58.881Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-UserAddedandRemovedfromRole&amp;clmoxdp4w000cmc0k06te8czs</loc>
    <lastmod>2023-09-18T13:31:51.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-SummarizeWeeklyPIM&amp;clmoxdgv0000amc0k4g2x36yj</loc>
    <lastmod>2023-09-18T13:31:41.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-SummarizePIMRolesActivated&amp;clmoxdc5m0008mc0k0mkqzvq7</loc>
    <lastmod>2023-09-18T13:31:35.099Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-RedirectURIChanged&amp;clmoxd4za0006mc0kc874zht5</loc>
    <lastmod>2023-09-18T13:31:25.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-PivotTableofPrivilegedUserActions&amp;clmoxcxh30004mc0kypupfm2b</loc>
    <lastmod>2023-09-18T13:31:16.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NewTenantCreated&amp;clmoxcpy70002mc0kbc3acrdy</loc>
    <lastmod>2023-09-18T13:31:06.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NewPrivilegedActions&amp;clmoxcj5u0000mc0k4lrmr3zq</loc>
    <lastmod>2023-09-18T13:30:57.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NewPIMRoleActivated&amp;clmox0mly00245i9s75m4nb7k</loc>
    <lastmod>2023-09-18T13:21:42.261Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NewOperations&amp;clmox0f4b00235i9sii7aqhpl</loc>
    <lastmod>2023-09-18T13:21:32.547Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NewDomainAdded&amp;clmox085y00225i9srustccnv</loc>
    <lastmod>2023-09-18T13:21:23.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-NamedLocationsChanged&amp;clmox03oi00215i9s54qu7c1y</loc>
    <lastmod>2023-09-18T13:21:17.729Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-MultipleUsersSameMFANumber&amp;clmowzxdh00205i9sbxxokhsg</loc>
    <lastmod>2023-09-18T13:21:09.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-MFAChangesforPrivlegedUsers&amp;clmowzp7c001z5i9scbv7swhi</loc>
    <lastmod>2023-09-18T13:20:58.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ListBulkActivities&amp;clmowzfrk001y5i9sv710rdan</loc>
    <lastmod>2023-09-18T13:20:46.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-GuestAddedtoPIM&amp;clmowzak5001x5i9skt258z2b</loc>
    <lastmod>2023-09-18T13:20:39.988Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-GroupMFARegistrationbyPhoneNumber&amp;clmowz4d9001w5i9s5rhs7j58</loc>
    <lastmod>2023-09-18T13:20:31.957Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-GroupAddedtoPIM&amp;clmowyxiy001v5i9s50w8uaxg</loc>
    <lastmod>2023-09-18T13:20:23.098Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-FirstTimePIMActivationOutsideWorkingHours&amp;clmowyqak001u5i9snjs9lijs</loc>
    <lastmod>2023-09-18T13:20:13.715Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-FindUsersFailingSSPR&amp;clmowyi6a001t5i9sgq0pkmf6</loc>
    <lastmod>2023-09-18T13:20:03.201Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-FindUsersFailingNewPasswordSSPR&amp;clmowybr3001s5i9simr5xgif</loc>
    <lastmod>2023-09-18T13:19:54.871Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-EventsbyRiskyPrivilegedUser&amp;clmowy3lb001r5i9srgsniisd</loc>
    <lastmod>2023-09-18T13:19:44.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectSSPRFromUnknownIP&amp;clmowxsuu001q5i9santyr3rb</loc>
    <lastmod>2023-09-18T13:19:30.381Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectSSPRAfterHours&amp;clmowxl79001p5i9s7m83dhqe</loc>
    <lastmod>2023-09-18T13:19:20.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectSPAddedAfterHours&amp;clmowxf4b001o5i9sl1yhk7h2</loc>
    <lastmod>2023-09-18T13:19:12.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectPIMActivationsOutsideWorkingHours&amp;clmowx6lk001n5i9stqay77gh</loc>
    <lastmod>2023-09-18T13:19:01.543Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectNewPrivilegedGroupAdded&amp;clmowwz6s001m5i9sfv05m1s6</loc>
    <lastmod>2023-09-18T13:18:51.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectNewCrossTenantSetting&amp;clmowws7w001l5i9s0v5b0u65</loc>
    <lastmod>2023-09-18T13:18:42.907Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectFirstTimeServicePrincipalCreation&amp;clmowwizd001k5i9sita38p7a</loc>
    <lastmod>2023-09-18T13:18:30.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectFirstTimeCAPolicyChange&amp;clmoww7ea001j5i9so8jp5360</loc>
    <lastmod>2023-09-18T13:18:15.922Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectCredentialAddedtoApp&amp;clmoww1lj001h5i9sn3nlsje3</loc>
    <lastmod>2023-09-18T13:18:08.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectConditionalAccessChangesAfterHours&amp;clmowvv5v001f5i9sn6ut5ao8</loc>
    <lastmod>2023-09-18T13:18:00.066Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectAdvancedAuditingDisabled&amp;clmowvo5a001d5i9sdf97awib</loc>
    <lastmod>2023-09-18T13:17:50.965Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectActivePIMAssignment&amp;clmowvgxm001b5i9s09uponc5</loc>
    <lastmod>2023-09-18T13:17:41.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DetectAADInternalsUse&amp;clmowv9ol001a5i9s2cj40idf</loc>
    <lastmod>2023-09-18T13:17:32.219Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DailySummaryofAdminActivity&amp;clmowux8x00185i9sheomixyo</loc>
    <lastmod>2023-09-18T13:17:16.105Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-CustomSecurityAttributeSet&amp;clmowuq4400165i9sead7y73l</loc>
    <lastmod>2023-09-18T13:17:06.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-BitLockerKeyRetrieved&amp;clmowuk4600145i9strhwzchx</loc>
    <lastmod>2023-09-18T13:16:59.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-AppProxySettoPassThrough&amp;clmowue2f00125i9sbswsg3lp</loc>
    <lastmod>2023-09-18T13:16:51.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-AllowedBlockedDomainListChanges&amp;clmowu80q00105i9sruz2xirr</loc>
    <lastmod>2023-09-18T13:16:43.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-AccessPackageCreated&amp;clmowu2lp000y5i9s5558nfot</loc>
    <lastmod>2023-09-18T13:16:36.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anamoly-HigherThanExpectedSysLog&amp;clmowtwmx000w5i9sxwffbity</loc>
    <lastmod>2023-09-18T13:16:28.664Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-VisualizeAccountsCreatedDisabledDeleted&amp;clmowtr8b000u5i9szbajaw67</loc>
    <lastmod>2023-09-18T13:16:21.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-UnconstrainedDelegationtoUser&amp;clmowtknj000s5i9so5afd326</loc>
    <lastmod>2023-09-18T13:16:13.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-UnconstrainedDelegationEnabled&amp;clmowtfe7000q5i9s8rvfmbi9</loc>
    <lastmod>2023-09-18T13:16:06.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-UACFlagParser&amp;clmowt79r000o5i9sueehxztk</loc>
    <lastmod>2023-09-18T13:15:55.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-SummarizeRDPActivity&amp;clmowt2b2000m5i9s27aq96x4</loc>
    <lastmod>2023-09-18T13:15:49.350Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-SummarizePrivilegesAssignedonLogon&amp;clmowsw5e000k5i9sw4wt7hdv</loc>
    <lastmod>2023-09-18T13:15:41.378Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-LogonToDeviceListChanged&amp;clmowsr1k000i5i9sv9u61wfl</loc>
    <lastmod>2023-09-18T13:15:34.760Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-GPOInheritanceChanged&amp;clmowskrp000g5i9sucsgvb41</loc>
    <lastmod>2023-09-18T13:15:26.628Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-DetectPrivilegedAADAdminPasswordChange&amp;clmowseey000e5i9s48kya6hk</loc>
    <lastmod>2023-09-18T13:15:18.393Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-DailySummaryofGroupAdditions&amp;clmows8m9000c5i9s12nlyi2h</loc>
    <lastmod>2023-09-18T13:15:10.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AnomalousIPCRecon&amp;clmows30i000a5i9sligw78d9</loc>
    <lastmod>2023-09-18T13:15:03.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AccountSetPasswordNotRequired&amp;clmowrx9i00085i9seatax079</loc>
    <lastmod>2023-09-18T13:14:56.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AccountSensitivityChanged&amp;clmowrq2300065i9s4vjr0r3q</loc>
    <lastmod>2023-09-18T13:14:46.826Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AccountPreAuthChanges&amp;clmowrjr300045i9sg26sjlhx</loc>
    <lastmod>2023-09-18T13:14:38.646Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADPasswordProtection-AllEvents&amp;clmowrdaf00025i9sczthr9av</loc>
    <lastmod>2023-09-18T13:14:30.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWS-PublicIPAddedtoInstance&amp;clmowr9kt00005i9sqf80r5t9</loc>
    <lastmod>2023-09-18T13:14:25.463Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MS%20Exchange%20Zero%20Day%20Sept%202022&amp;clmo2dv1o00czmc0jrkd1mswx</loc>
    <lastmod>2023-09-17T23:04:11.627Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Follina&amp;clmo2dqja00cxmc0jpvb3l2of</loc>
    <lastmod>2023-09-17T23:04:05.640Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WeakSSHVersionUsed&amp;clmo2djyc00cvmc0jvjz5bzk9</loc>
    <lastmod>2023-09-17T23:03:57.252Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WSLInstallations&amp;clmo2delw00ctmc0jnay3zuy7</loc>
    <lastmod>2023-09-17T23:03:50.323Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VulnerabilitiesWithAvailablePOC&amp;clmo2d95500crmc0j3u2otlkt</loc>
    <lastmod>2023-09-17T23:03:43.100Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20VulnerabilitiesBySeverity&amp;clmo2d2r900cpmc0j90wnl0cc</loc>
    <lastmod>2023-09-17T23:03:34.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20BrowserExtension%20-%20MostCommonCricitalExtensions&amp;clmo2czfa00cnmc0j5m48ywd0</loc>
    <lastmod>2023-09-17T23:03:30.645Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Upcomming-EOS-Software&amp;clmo2cvso00clmc0jyssnw48o</loc>
    <lastmod>2023-09-17T23:03:25.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top-Devices-Most-Vulnerabilities&amp;clmo2crpu00cjmc0j0oxgkbmi</loc>
    <lastmod>2023-09-17T23:03:20.658Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top-Devices-Most-Exploitable-Vulnerabilities&amp;clmo2cn3f00chmc0j2j9bj0jd</loc>
    <lastmod>2023-09-17T23:03:14.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Pivot%20-%20DeviceVulnerabilities&amp;clmo2cj0300cfmc0jfvyvvi4u</loc>
    <lastmod>2023-09-17T23:03:09.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OpenSSLVulnerableDevices&amp;clmo2cfk300cdmc0j3gz20ebx</loc>
    <lastmod>2023-09-17T23:03:04.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/InternetFacingDevicesWithAvailableExploits&amp;clmo2cbed00cbmc0jg3mgocuf</loc>
    <lastmod>2023-09-17T23:02:59.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DomainControllersWithTheMostVulnerabilities&amp;clmo2c6hv00c9mc0jung48f01</loc>
    <lastmod>2023-09-17T23:02:53.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Devices-With-Recent-Exploitable-Vulnerability&amp;clmo2c1n700c7mc0j0g72mcm7</loc>
    <lastmod>2023-09-17T23:02:46.726Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-EDR-Configuration-Not-Compliant&amp;clmo2bv4t00c5mc0jzjlycze1</loc>
    <lastmod>2023-09-17T23:02:38.429Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-Configuration-Not-Compliant&amp;clmo2bqg900c3mc0j0enq9ozl</loc>
    <lastmod>2023-09-17T23:02:32.360Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CveLookup&amp;clmo2blp300c1mc0jeqaengr5</loc>
    <lastmod>2023-09-17T23:02:26.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CVEWithMetaSploitExploitDeviceTotal&amp;clmo2bge600bzmc0jyj9116x1</loc>
    <lastmod>2023-09-17T23:02:19.326Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKnowExploitsVulnerabilitiesTotalVulnerableDevices&amp;clmo2bbcu00bxmc0jui4usb7w</loc>
    <lastmod>2023-09-17T23:02:12.797Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CISAKnowExploitsVulnerabilitiesDeviceTotal&amp;clmo2b7eq00bvmc0jqkpdqyer</loc>
    <lastmod>2023-09-17T23:02:07.539Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BrowserExtension%20-%20Top100MostPermissiveExtensionsInstalled&amp;clmo2b18x00btmc0jdkxnawh6</loc>
    <lastmod>2023-09-17T23:01:59.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BrowserExtension%20-%20Top100DevicesWithTheMostBrowserExtensions&amp;clmo2awib00brmc0jgvbo6q8b</loc>
    <lastmod>2023-09-17T23:01:53.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BrowserExtension%20-%20InstalledExtensionsWithTheMostRequiredPermissions&amp;clmo2aruc00bpmc0jdpu0ux8v</loc>
    <lastmod>2023-09-17T23:01:47.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BrowserExtension%20-%20InstalledExtensionsWithNotificationPermissions&amp;clmo2am9800bnmc0jgzb5t7em</loc>
    <lastmod>2023-09-17T23:01:40.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Active-EOS-Software&amp;clmo2ahub00blmc0jf27icd4v</loc>
    <lastmod>2023-09-17T23:01:34.546Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20TwitterIOCs&amp;clmo2aduc00bkmc0ji9p35dan</loc>
    <lastmod>2023-09-17T23:01:29.221Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20ThreatfoxMalwareDomains&amp;clmo2a5k500bimc0j8wt3fs06</loc>
    <lastmod>2023-09-17T23:01:18.629Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MISP%20IPSum%20level%208&amp;clmo29zw800bgmc0jq1m60txp</loc>
    <lastmod>2023-09-17T23:01:11.287Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MISP%20IPSum%20level%207&amp;clmo29tz800bemc0j6d05tigb</loc>
    <lastmod>2023-09-17T23:01:03.619Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MISP%20IPSum%20level%206&amp;clmo29oog00bcmc0jnoaujdhf</loc>
    <lastmod>2023-09-17T23:00:56.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MISP%20IPSum%20level%205&amp;clmo29j0p00bamc0jkhb2sags</loc>
    <lastmod>2023-09-17T23:00:49.416Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20MISP%20IPSum%20level%204&amp;clmo29dmb00b8mc0jzxd8xj69</loc>
    <lastmod>2023-09-17T23:00:42.418Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20CERT-FR-MISPFeed&amp;clmo297pc00b6mc0jsa4y1b86</loc>
    <lastmod>2023-09-17T23:00:34.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20C2URLFeedFilterAbuse&amp;clmo293gq00b4mc0jrymi7tm9</loc>
    <lastmod>2023-09-17T23:00:29.257Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20C2URLFeed&amp;clmo28wvp00b2mc0jvgqc2kx3</loc>
    <lastmod>2023-09-17T23:00:20.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20C2IPFeed&amp;clmo28sd100b0mc0ju9mrkhbb</loc>
    <lastmod>2023-09-17T23:00:14.868Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20BlocklistDEAllMaliciousIP&amp;clmo28mjc00aymc0j607nt4mc</loc>
    <lastmod>2023-09-17T23:00:07.320Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20AbuseCHMD5Malware&amp;clmo28ilc00awmc0j358aofe4</loc>
    <lastmod>2023-09-17T23:00:02.207Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20AbuseCHIPBlacklistFeed&amp;clmo28dh000aumc0j0tcli083</loc>
    <lastmod>2023-09-17T22:59:55.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%20AbuseCHBotnetC2Indicators&amp;clmo287qd00asmc0jmjp8sgfu</loc>
    <lastmod>2023-09-17T22:59:47.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%202022-TalosEmotetSHA256&amp;clmo27yih00aqmc0j3rsb82i7</loc>
    <lastmod>2023-09-17T22:59:36.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TI%20Feed%20-%202022-TalosEmotetDomain&amp;clmo27tl900aomc0jvfymiea4</loc>
    <lastmod>2023-09-17T22:59:29.663Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Ransomware%20-%20APTNotesSHA1IOC&amp;clmo27mt400ammc0jyij7uww4</loc>
    <lastmod>2023-09-17T22:59:21.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Ransomware%20-%20APTNotesJoinTable&amp;clmo27h0n00akmc0j9u93b1ad</loc>
    <lastmod>2023-09-17T22:59:13.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOC%20-%20NighthawkRat&amp;clmo27dsd00aimc0j4m8chsxi</loc>
    <lastmod>2023-09-17T22:59:09.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOC%20-%20CiscoYanluowangRansomware&amp;clmo278cc00agmc0jysi22rzp</loc>
    <lastmod>2023-09-17T22:59:02.267Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOC%20-%20BlackCatRansomware&amp;clmo273d400aemc0jclabe83f</loc>
    <lastmod>2023-09-17T22:58:55.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behavior%20-%20TelegramC2&amp;clmo26y9n00acmc0jsk55g8p7</loc>
    <lastmod>2023-09-17T22:58:49.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behavior%20-%20InboundConnectionFromMaliciousIP&amp;clmo26u6200aamc0j4ri1sfen</loc>
    <lastmod>2023-09-17T22:58:43.897Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Behavior%20-%20AsyncRATInitialAccess&amp;clmo26mf500a8mc0jc3z3f22d</loc>
    <lastmod>2023-09-17T22:58:33.856Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20SMB%20Sessions&amp;clmo26e1q00a6mc0juzaaw3fv</loc>
    <lastmod>2023-09-17T22:58:22.863Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Suspicious%20Encoded%20Powershell&amp;clmo25vso00a4mc0jp1g6furm</loc>
    <lastmod>2023-09-17T22:57:59.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HTTP%20Traffic&amp;clmo25jdt00a2mc0jc5zkw0d3</loc>
    <lastmod>2023-09-17T22:57:43.122Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ThreatIntelligenceIndicatorTriggeredByDay&amp;clmo257ed00a0mc0jsjtof3sf</loc>
    <lastmod>2023-09-17T22:57:27.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ThreatIntelligenceIndicatorTriggered&amp;clmo252xi009ymc0jc1mez2g1</loc>
    <lastmod>2023-09-17T22:57:21.942Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20IncidentsTriggeredByMitreTechniques&amp;clmo24zlt009wmc0jb9mxb23z</loc>
    <lastmod>2023-09-17T22:57:17.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20IncidentsTriggeredByMitreTactic&amp;clmo24uec009umc0jzq5qamna</loc>
    <lastmod>2023-09-17T22:57:10.741Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelAnomalies&amp;clmo24pzt009smc0jabdwrjfj</loc>
    <lastmod>2023-09-17T22:57:05.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListGlobalAdmins&amp;clmo24lxc009qmc0jh43xryy7</loc>
    <lastmod>2023-09-17T22:56:59.903Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnalyticsRulesEfficiency&amp;clmo24hry009omc0jbrixcf1s</loc>
    <lastmod>2023-09-17T22:56:54.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20DailyIncidentTriggers&amp;clmo24akn009mmc0jafl501ui</loc>
    <lastmod>2023-09-17T22:56:45.190Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20AntivirusEventsByDay&amp;clmo246c7009kmc0jgv1m0gc3</loc>
    <lastmod>2023-09-17T22:56:39.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Statistics%20-%20MostTriggeredMitreTechniques&amp;clmo242mb009imc0jtbyba83q</loc>
    <lastmod>2023-09-17T22:56:34.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Statistics%20-%20MostTriggeredIncidents&amp;clmo23y2m009gmc0jrnl0wrhu</loc>
    <lastmod>2023-09-17T22:56:28.847Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MalwareFileDetected&amp;clmo23t4u009emc0jfdj3son7</loc>
    <lastmod>2023-09-17T22:56:22.589Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListSafeLinkEvents&amp;clmo23oqf009cmc0jnczujknc</loc>
    <lastmod>2023-09-17T22:56:16.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20SafeLinksTrigger&amp;clmo23k9j009amc0j61nniu4y</loc>
    <lastmod>2023-09-17T22:56:11.094Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20MostRareFileExtensionsRecieved&amp;clmo23epj0098mc0jtq7jfxel</loc>
    <lastmod>2023-09-17T22:56:03.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20MacroAttachmentOpenedFromRareSender&amp;clmo23a160096mc0jrbqkjx8o</loc>
    <lastmod>2023-09-17T22:55:57.691Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20ISOAttachmentRecieved&amp;clmo233bt0094mc0jidyo6fp8</loc>
    <lastmod>2023-09-17T22:55:49.144Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20ExecutableFileRecieved&amp;clmo22xwp0092mc0jbzugoohe</loc>
    <lastmod>2023-09-17T22:55:41.979Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email%20-%20ASRExecutableContentTriggered&amp;clmo22sw70090mc0jabnaa90u</loc>
    <lastmod>2023-09-17T22:55:35.622Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Mapping&amp;clmo22lzc008ymc0jeup1jce0</loc>
    <lastmod>2023-09-17T22:55:26.521Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RegexExamples&amp;clmo225f4008wmc0jiy17d093</loc>
    <lastmod>2023-09-17T22:55:05.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/vm%20connection%20check&amp;clmo205d3008umc0j0fz5n1s3</loc>
    <lastmod>2023-09-17T22:53:31.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/timescope%20query%20parameters&amp;clmo201o6008smc0jlaj78wna</loc>
    <lastmod>2023-09-17T22:53:27.030Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/stringtoregex%20deprecated&amp;clmo1zyj9008qmc0jc4tb90oj</loc>
    <lastmod>2023-09-17T22:53:22.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/enumerating%20identities%20deprecated&amp;clmo1zuc7008omc0jb8u3m8nu</loc>
    <lastmod>2023-09-17T22:53:17.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SuspiciousASNs&amp;clmo1zkbt008mmc0j949etjjo</loc>
    <lastmod>2023-09-17T22:53:04.552Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Data%20source%20anomalies&amp;clmo1zbx6008kmc0jq5zdhdy5</loc>
    <lastmod>2023-09-17T22:52:53.657Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ConditionalAccessReportOnly&amp;clmo1z7od008imc0jv2aomg34</loc>
    <lastmod>2023-09-17T22:52:48.157Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20AD%20Identity%20Protection%20glitch&amp;clmo1z2v5008gmc0j1jr9509m</loc>
    <lastmod>2023-09-17T22:52:41.778Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-Events&amp;clmo1yx1k008emc0jy2ltoehd</loc>
    <lastmod>2023-09-17T22:52:34.375Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-All%20watchlist%20items&amp;clmo1ytmw008dmc0jh44ejbcg</loc>
    <lastmod>2023-09-17T22:52:29.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ThreatIntelligenceIndicator-Stopped%20event%20reception%20-%20ThreatIntelligenceIndicator&amp;clmo1ylco008bmc0jsayp2evp</loc>
    <lastmod>2023-09-17T22:52:19.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SentinelHealth-Sentinel%20failure&amp;clmo1yha40089mc0jd1y9dkyo</loc>
    <lastmod>2023-09-17T22:52:13.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-Stopped%20event%20reception%20-%20SecurityIncident&amp;clmo1ybh30087mc0j09zk1ria</loc>
    <lastmod>2023-09-17T22:52:06.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Stopped%20event%20reception%20-%20Domain%20Controllers%20-%20SecurityEvent&amp;clmo1y5f10085mc0j93d41ak0</loc>
    <lastmod>2023-09-17T22:51:58.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Alert%20generation%20anomaly&amp;clmo1y1rn0083mc0jioetccc9</loc>
    <lastmod>2023-09-17T22:51:53.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Stopped%20event%20reception&amp;clmo1xwxb0081mc0jh2w8nrs4</loc>
    <lastmod>2023-09-17T22:51:47.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Ingestion%20delays&amp;clmo1xqlr007zmc0jf6hdefb4</loc>
    <lastmod>2023-09-17T22:51:39.233Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Delayed%20event%20ingestion&amp;clmo1xm56007xmc0juks84o0k</loc>
    <lastmod>2023-09-17T22:51:33.593Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Heartbeat-Stopped%20event%20reception%20-%20Domain%20Controllers&amp;clmo1xhb6007vmc0j3b5mh39v</loc>
    <lastmod>2023-09-17T22:51:27.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDiagnostics-Stopped%20event%20reception%20-%20AzureDiagnostics%20-%20ResourceType&amp;clmo1xe4k007umc0j5vd26u45</loc>
    <lastmod>2023-09-17T22:51:23.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-True%20positive%20incidents%20from%20previous%20month&amp;clmo1x6kr007smc0j3u88etc5</loc>
    <lastmod>2023-09-17T22:51:13.419Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityIncident-Monthly%20incidents%20closed%20by%20Automation%20Rules&amp;clmo1x285007qmc0jqsy7mby7</loc>
    <lastmod>2023-09-17T22:51:07.779Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Sign%20In&amp;clmo1wwoj007omc0jhbiq2rpw</loc>
    <lastmod>2023-09-17T22:51:00.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Process%20Creation&amp;clmo1wr6m007mmc0j7i5y42fk</loc>
    <lastmod>2023-09-17T22:50:53.469Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Privilege%20Granted&amp;clmo1wls4007kmc0j225zigtu</loc>
    <lastmod>2023-09-17T22:50:46.468Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Password%20Reset&amp;clmo1wgte007imc0j6yyclne4</loc>
    <lastmod>2023-09-17T22:50:39.892Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Failed%20Sign-in&amp;clmo1wb6g007gmc0jjfr73len</loc>
    <lastmod>2023-09-17T22:50:32.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Defensive%20Mechanism%20Modification&amp;clmo1w77o007emc0j4l3bgtuk</loc>
    <lastmod>2023-09-17T22:50:27.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Data%20Destruction&amp;clmo1w27b007cmc0jxnaj7sxe</loc>
    <lastmod>2023-09-17T22:50:21.095Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Code%20Execution&amp;clmo1vwxs007amc0jj05juual</loc>
    <lastmod>2023-09-17T22:50:14.271Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Account%20Manipulation&amp;clmo1vrzo0078mc0j3ig8x5pz</loc>
    <lastmod>2023-09-17T22:50:07.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Account%20Deletion&amp;clmo1vmk60076mc0jr735ldkl</loc>
    <lastmod>2023-09-17T22:50:00.679Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Account%20Creation&amp;clmo1vhfs0074mc0jxhzov2wv</loc>
    <lastmod>2023-09-17T22:49:54.184Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-UEBA%20Anomalous%20Account%20Access%20Removal&amp;clmo1vchb0072mc0j4yc7smmr</loc>
    <lastmod>2023-09-17T22:49:47.758Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20logins%20to%20user%20account%20with%20elevated%20token&amp;clmo1v7hc0070mc0j3eeagvo4</loc>
    <lastmod>2023-09-17T22:49:41.279Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20logins%20to%20user%20account%20by%20logon%20types&amp;clmo1v1oo006ymc0jujld46m7</loc>
    <lastmod>2023-09-17T22:49:33.768Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20logins%20to%20computer&amp;clmo1uw4i006wmc0jtdrx1drt</loc>
    <lastmod>2023-09-17T22:49:26.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20logins%20to%20computer%20with%20elevated%20token&amp;clmo1uqq3006umc0jbxknueb9</loc>
    <lastmod>2023-09-17T22:49:19.421Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20failed%20login%20attempts%20to%20AWS%20Console%20by%20each%20source%20IP%20address&amp;clmo1ukuq006smc0j9w4q2u1d</loc>
    <lastmod>2023-09-17T22:49:11.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20failed%20login%20attempts%20to%20AWS%20Console%20by%20each%20group%20user%20account&amp;clmo1ufzm006qmc0jeyexl4zd</loc>
    <lastmod>2023-09-17T22:49:05.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20AWS%20write%20API%20calls%20from%20a%20user%20account&amp;clmo1ub23006omc0jpiwxqyxi</loc>
    <lastmod>2023-09-17T22:48:59.117Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20AWS%20cloud%20trail%20logs%20events%20of%20group%20user%20account%20by%20EventTypeName&amp;clmo1u6db006mmc0j42cdt0el</loc>
    <lastmod>2023-09-17T22:48:53.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Suspicious%20volume%20of%20AWS%20API%20calls%20from%20Non-AWS%20source%20IP%20address%20from%20a%20user%20account%20id%20per%20workspace%20on%20a%20daily%20basis&amp;clmo1u0tq006kmc0jc06c6al9</loc>
    <lastmod>2023-09-17T22:48:45.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Rare%20privileged%20process%20calls%20on%20a%20daily%20basis&amp;clmo1tvep006imc0jpn75wblf</loc>
    <lastmod>2023-09-17T22:48:38.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Potential%20data%20staging&amp;clmo1tq9r006gmc0j9kdnfcly</loc>
    <lastmod>2023-09-17T22:48:32.318Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Domain%20generation%20algorithm%20(DGA)%20on%20DNS%20domains&amp;clmo1tk2j006emc0j64qggizr</loc>
    <lastmod>2023-09-17T22:48:24.140Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Attempted%20user%20account%20bruteforce&amp;clmo1tedq006cmc0jxvug8svj</loc>
    <lastmod>2023-09-17T22:48:16.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Attempted%20user%20account%20bruteforce%20per%20failure%20reason&amp;clmo1t9ae006amc0jhvdxwurw</loc>
    <lastmod>2023-09-17T22:48:10.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Attempted%20computer%20bruteforce&amp;clmo1t4nr0068mc0ji9wmjttl</loc>
    <lastmod>2023-09-17T22:48:04.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20volume%20of%20privileged%20process%20calls%20of%20commonly%20seen%20windows%20attack%20vectors%20on%20a%20daily%20basis&amp;clmo1sz0y0066mc0jhzunr46v</loc>
    <lastmod>2023-09-17T22:47:57.009Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20user-app%20activities%20in%20Azure%20audit%20logs&amp;clmo1stsk0064mc0jpymt5xf3</loc>
    <lastmod>2023-09-17T22:47:50.228Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20user%20activities%20in%20Office%20Exchange&amp;clmo1sosf0062mc0jtho5xg26</loc>
    <lastmod>2023-09-17T22:47:43.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20local%20account%20creation&amp;clmo1skcx0061mc0j6a3epgb5</loc>
    <lastmod>2023-09-17T22:47:38.000Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20Process%20Path%20used%20by%20a%20user%20account&amp;clmo1sfnk005zmc0jorqlphxf</loc>
    <lastmod>2023-09-17T22:47:31.904Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20Azure%20operations&amp;clmo1sajb005xmc0jj5242zr3</loc>
    <lastmod>2023-09-17T22:47:25.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Anomalies-Anomalous%20Azure%20AD%20sign-in%20sessions&amp;clmo1s54e005vmc0jo4eydtig</loc>
    <lastmod>2023-09-17T22:47:18.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Malware%20file%20in%20SharePoint&amp;clmo1rzzg005tmc0jy86k6yet</loc>
    <lastmod>2023-09-17T22:47:11.596Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Excessive%20SharePoint%20activity&amp;clmo1rtya005rmc0jylb388u8</loc>
    <lastmod>2023-09-17T22:47:03.777Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Correlate%20OfficeActivity%20to%20EmailEvents&amp;clmo1rkqw005pmc0jp5o1xeez</loc>
    <lastmod>2023-09-17T22:46:51.705Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Activity%20with%20monitored%20Office%20file&amp;clmo1rdbb005nmc0j7ugqcn0z</loc>
    <lastmod>2023-09-17T22:46:42.214Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalData-pyWhat%20Regular%20expressions&amp;clmo1r5yj005lmc0jqybgg046</loc>
    <lastmod>2023-09-17T22:46:32.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalData-LOLBAS&amp;clmo1r254005jmc0jat3wgav9</loc>
    <lastmod>2023-09-17T22:46:27.735Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalData-Azure%20IP%20address%20ranges&amp;clmo1qxx9005hmc0jeuz0po7v</loc>
    <lastmod>2023-09-17T22:46:22.268Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/-Example%20scan%20operator&amp;clmo1qu9j005gmc0jv5cf9eem</loc>
    <lastmod>2023-09-17T22:46:17.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/-Example%20activity_counts_metrics&amp;clmo1qmdk005emc0j3jxf2lbp</loc>
    <lastmod>2023-09-17T22:46:07.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Heartbeat-Last%20heartbeats&amp;clmo1qhod005cmc0jsm3qdq3u</loc>
    <lastmod>2023-09-17T22:46:01.070Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-A%20potentially%20malicious%20URL%20click%20was%20detected&amp;clmo1qdhu005amc0jozfeb546</loc>
    <lastmod>2023-09-17T22:45:55.793Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Sensitive%20account%20authentication%20in%20AD%20FS%20from%20unexpected%20device&amp;clmo1q7hp0058mc0jlf6v8eyq</loc>
    <lastmod>2023-09-17T22:45:47.870Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityQueryEvents-Suspicious%20LDAP%20query%20from%20unexpected%20device&amp;clmo1pvps0056mc0jaf7yck1c</loc>
    <lastmod>2023-09-17T22:45:32.751Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityQueryEvents-SAMR%20query%20enumerating%20users&amp;clmo1posw0054mc0jry04ifvm</loc>
    <lastmod>2023-09-17T22:45:23.650Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityQueryEvents-DNS%20zone%20transfer%20from%20unexpected%20device&amp;clmo1phtl0052mc0j40prw638</loc>
    <lastmod>2023-09-17T22:45:14.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityLogonEvents-Unexpected%20access%20to%20multiple%20devices&amp;clmo1pc1g0050mc0j3117ll2t</loc>
    <lastmod>2023-09-17T22:45:07.109Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-VulnerabilitiesByCVE&amp;clmo1oyq2004ymc0jpxsgpakr</loc>
    <lastmod>2023-09-17T22:44:49.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceTvmSoftwareVulnerabilities-VulnerabilitiesBySoftware&amp;clmo1os3m004wmc0jp0g504me</loc>
    <lastmod>2023-09-17T22:44:41.409Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceTvmSoftwareVulnerabilities-VulnerabilitiesByDevice&amp;clmo1omvz004umc0j8f1upyek</loc>
    <lastmod>2023-09-17T22:44:34.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Unusual%20number%20of%20failed%20sign-in%20attempts&amp;clmo1oh04004smc0jxs81vumm</loc>
    <lastmod>2023-09-17T22:44:27.027Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Suspicious%20request%20to%20Kubernetes%20API&amp;clmo1oawf004qmc0jr1hv4vse</loc>
    <lastmod>2023-09-17T22:44:18.976Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Script%20extension%20mismatch%20detected&amp;clmo1o5kx004omc0j7lg8d2l8</loc>
    <lastmod>2023-09-17T22:44:12.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Rare%20SVCHOST%20service%20group%20executed&amp;clmo1ny7e004mmc0jpbsocww6</loc>
    <lastmod>2023-09-17T22:44:02.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-PsExec%20execution%20detected&amp;clmo1nse7004kmc0jp9s8q2vt</loc>
    <lastmod>2023-09-17T22:43:55.134Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Possible%20exploitation%20of%20Hadoop%20Yarn&amp;clmo1nmn5004imc0jkq6ft2sd</loc>
    <lastmod>2023-09-17T22:43:47.680Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Possible%20attack%20tool%20detected&amp;clmo1ngo1004gmc0jzic01ks7</loc>
    <lastmod>2023-09-17T22:43:39.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Antimalware%20Action&amp;clmo1nae4004emc0jz9szn8jk</loc>
    <lastmod>2023-09-17T22:43:31.803Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Anomalous%20access%20to%20Kubernetes%20secret&amp;clmo1n20z004cmc0jc8hg1kk7</loc>
    <lastmod>2023-09-17T22:43:20.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-Adaptive%20application%20control%20policy%20violation%20was%20audited&amp;clmo1mwf6004amc0jn4hbn0l0</loc>
    <lastmod>2023-09-17T22:43:13.698Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlert-A%20history%20file%20has%20been%20cleared&amp;clmo1mqb40048mc0j15gqlttr</loc>
    <lastmod>2023-09-17T22:43:05.634Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Virtual%20machines%20TVM%20vulnerability%20assessments&amp;clmo1mkrg0046mc0jn1cv0c1k</loc>
    <lastmod>2023-09-17T22:42:58.587Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Virtual%20machines%20SQL%20vulnerability%20assessments&amp;clmo1mei90044mc0jzk0gzfq3</loc>
    <lastmod>2023-09-17T22:42:50.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Virtual%20machines%20Qualys%20vulnerability%20assessments&amp;clmo1m8ql0042mc0jpeyqsc3c</loc>
    <lastmod>2023-09-17T22:42:43.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Container%20registry%20image%20vulnerability%20assessments&amp;clmo1m1nx0040mc0jdnoityrg</loc>
    <lastmod>2023-09-17T22:42:33.694Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Suspicious%20inbox%20manipulation%20rule&amp;clmo1lrd6003zmc0jqxdnb1cu</loc>
    <lastmod>2023-09-17T22:42:20.489Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Suspicious%20inbox%20forwarding%20rule&amp;clmo1lb9r003xmc0jo4e526f6</loc>
    <lastmod>2023-09-17T22:41:59.630Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Impossible%20travel%20activity%20alerts&amp;clmo1l5pn003wmc0j1lpcw3pi</loc>
    <lastmod>2023-09-17T22:41:52.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Activity%20from%20infrequent%20country&amp;clmo1kyu5003vmc0jmsp310sm</loc>
    <lastmod>2023-09-17T22:41:43.516Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Excessive%20rDNS%20queries&amp;clmo1k5kr003tmc0jq010nks2</loc>
    <lastmod>2023-09-17T22:41:05.594Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Excessive%20NXDOMAIN%20DNS%20queries&amp;clmo1jyw2003smc0j0py0ihyh</loc>
    <lastmod>2023-09-17T22:40:56.787Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DNS%20query%20ends%20with%20IP%20address&amp;clmo1jpu6003rmc0jik6udw5y</loc>
    <lastmod>2023-09-17T22:40:45.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DNS%20query%20contains%20IP%20address&amp;clmo1jgho003qmc0j85tx9jvp</loc>
    <lastmod>2023-09-17T22:40:32.941Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cisco_Umbrella_dns_CL-Monitored%20category%20DNS%20query%20-%20Reprehensible&amp;clmo1hi5l003omc0jqshzddiv</loc>
    <lastmod>2023-09-17T22:39:01.929Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cisco_Umbrella_dns_CL-Monitored%20category%20DNS%20query%20-%20Malicious&amp;clmo1hare003nmc0jjkq27xkw</loc>
    <lastmod>2023-09-17T22:38:52.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Cisco_Umbrella_dns_CL-Monitored%20category%20DNS%20query%20-%20Filter%20avoidance&amp;clmo1h4kr003mmc0jutqahr57</loc>
    <lastmod>2023-09-17T22:38:44.330Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SubscriptionInventoryLogs-Azure%20subscription%20modification&amp;clmo1gyqb003lmc0jx8p32qxc</loc>
    <lastmod>2023-09-17T22:38:36.612Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Resources-Storage%20Accounts&amp;clmo1gqhw003kmc0j7cckcnfr</loc>
    <lastmod>2023-09-17T22:38:26.084Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Azure%20Virtual%20Machines&amp;clmo1gnke003jmc0jrrjm6j6k</loc>
    <lastmod>2023-09-17T22:38:22.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Azure%20RBAC%20role%20assignment&amp;clmo1ggbv003imc0joqt5dudo</loc>
    <lastmod>2023-09-17T22:38:12.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureDiagnostics-Azure%20Firewall%20events&amp;clmo1duw4003gmc0j4p17t2ns</loc>
    <lastmod>2023-09-17T22:36:11.669Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-SdeletedeployedviaGPOandrunrecursively&amp;clmo1dsch003emc0jysz8auid</loc>
    <lastmod>2023-09-17T22:36:08.513Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-NonDCActiveDirectoryReplication&amp;clmo1dmyq003cmc0jgfn56ibr</loc>
    <lastmod>2023-09-17T22:36:01.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-NewEXEdeployedviaDefaultDomainorDefaultDomainControllerPolicies&amp;clmo1dhzs003amc0j4nla825m</loc>
    <lastmod>2023-09-17T22:35:54.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-ExchangeOABVirtualDirectoryAttributeContainingPotentialWebshell&amp;clmo1dd630038mc0jbm1pas3a</loc>
    <lastmod>2023-09-17T22:35:48.842Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_Syslog&amp;clmo1d4sc0036mc0j3omutpn2</loc>
    <lastmod>2023-09-17T22:35:37.838Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_SecurityAlert&amp;clmo1cr800035mc0jwvsjb4sd</loc>
    <lastmod>2023-09-17T22:35:20.258Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_OfficeActivity&amp;clmo1cg310034mc0ja24aky52</loc>
    <lastmod>2023-09-17T22:35:05.964Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_EmailUrlInfo&amp;clmo1c5fk0033mc0jeg50dxax</loc>
    <lastmod>2023-09-17T22:34:52.018Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_DeviceNetworkEvents&amp;clmo1aasx0031mc0jchxuufll</loc>
    <lastmod>2023-09-17T22:33:25.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-URLEntity_AuditLogs&amp;clmo1a04u0030mc0jw9cw7khq</loc>
    <lastmod>2023-09-17T22:33:11.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_VMConnection&amp;clmo19pkk002zmc0jd7z5dqss</loc>
    <lastmod>2023-09-17T22:32:58.150Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Syslog&amp;clmo19bkz002xmc0jmilv5zvl</loc>
    <lastmod>2023-09-17T22:32:40.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_StorageFileLogs&amp;clmo192cv002vmc0jcxmb49t9</loc>
    <lastmod>2023-09-17T22:32:28.206Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_StorageBlobLogs&amp;clmo18sfu002tmc0j5c3rjyin</loc>
    <lastmod>2023-09-17T22:32:15.213Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_SigninLogs&amp;clmo18ita002rmc0j69lwyd8w</loc>
    <lastmod>2023-09-17T22:32:02.877Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_SecurityAlert&amp;clmo186mp002pmc0jw7zjr0yl</loc>
    <lastmod>2023-09-17T22:31:47.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_OfficeActivity&amp;clmo17wth002nmc0j2lbf4p49</loc>
    <lastmod>2023-09-17T22:31:34.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_EmailEvents&amp;clmo17hr2002lmc0jubsqxro9</loc>
    <lastmod>2023-09-17T22:31:14.704Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_DnsEvents&amp;clmo17545002jmc0jfulwur8u</loc>
    <lastmod>2023-09-17T22:30:58.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_DeviceNetworkEvents&amp;clmo16z6g002imc0jpt0eiyb3</loc>
    <lastmod>2023-09-17T22:30:50.775Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_SQL&amp;clmo16oa9002hmc0jtx6845az</loc>
    <lastmod>2023-09-17T22:30:36.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Kubernetes&amp;clmo1676f002gmc0jmmrefycp</loc>
    <lastmod>2023-09-17T22:30:14.344Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Key_Vault&amp;clmo15s33002fmc0jklh9g0o3</loc>
    <lastmod>2023-09-17T22:29:54.784Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Firewall&amp;clmo14zdv002dmc0j6fudeef5</loc>
    <lastmod>2023-09-17T22:29:16.670Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_Azure_Data_Lake&amp;clmo14js4002bmc0jmwrwgvcz</loc>
    <lastmod>2023-09-17T22:28:57.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AzureActivity&amp;clmo1341e0029mc0jcdbo0bk2</loc>
    <lastmod>2023-09-17T22:27:50.449Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AuditLogs&amp;clmo12u920028mc0jlfzn3mmk</loc>
    <lastmod>2023-09-17T22:27:37.623Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AWSCloudTrail&amp;clmo12lvm0027mc0jnjqderty</loc>
    <lastmod>2023-09-17T22:27:26.913Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_ADFSSignInLogs&amp;clmo12bn80026mc0ju03gooc3</loc>
    <lastmod>2023-09-17T22:27:13.509Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AADServicePrincipalSignInLogs&amp;clmo11xnd0024mc0j8ro4gtsm</loc>
    <lastmod>2023-09-17T22:26:55.370Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-IPEntity_AADNonInteractiveUserSignInLogs&amp;clmo11jnl0022mc0jmxtkhxkn</loc>
    <lastmod>2023-09-17T22:26:37.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-FileHashEntity_EmailAttachmentInfo&amp;clmo1167p0020mc0jvm433od2</loc>
    <lastmod>2023-09-17T22:26:19.813Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-FileHashEntity_DeviceFileEvents&amp;clmo10pzf001ymc0jg0lnt6ay</loc>
    <lastmod>2023-09-17T22:25:58.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_SigninLogs&amp;clmo10cqe001xmc0jmj7aq6sv</loc>
    <lastmod>2023-09-17T22:25:41.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_SecurityAlert&amp;clmo104in001wmc0jhzjx1a3p</loc>
    <lastmod>2023-09-17T22:25:30.960Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_OfficeActivity&amp;clmo0yb6q001umc0j9ieoru5e</loc>
    <lastmod>2023-09-17T22:24:06.291Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_EmailEvents&amp;clmo0xtw5001tmc0j8t357tij</loc>
    <lastmod>2023-09-17T22:23:43.878Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_AzureActivity&amp;clmo0whpc001rmc0j6juwrdcj</loc>
    <lastmod>2023-09-17T22:22:41.425Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_AuditLogs&amp;clmo0w3x4001qmc0ja1jz3nsv</loc>
    <lastmod>2023-09-17T22:22:23.561Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-EmailEntity_AADNonInteractiveUserSignInLogs&amp;clmo0u8w6001omc0jv6zzq0yn</loc>
    <lastmod>2023-09-17T22:20:56.696Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_VMConnection&amp;clmo0tvqb001nmc0j327si8na</loc>
    <lastmod>2023-09-17T22:20:39.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_Syslog&amp;clmo0rrr5001lmc0j0okxf1vq</loc>
    <lastmod>2023-09-17T22:19:01.171Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_SecurityAlert&amp;clmo0r4wd001jmc0jusgf5aj1</loc>
    <lastmod>2023-09-17T22:18:31.550Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_OfficeActivity&amp;clmo0qjd3001imc0jrlpj4lr5</loc>
    <lastmod>2023-09-17T22:18:03.782Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_EmailUrlInfo&amp;clmo0q9md001hmc0jv1g8pl77</loc>
    <lastmod>2023-09-17T22:17:51.015Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_EmailEvents&amp;clmo0proo001gmc0jzvmgbmbg</loc>
    <lastmod>2023-09-17T22:17:27.911Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_DnsEvents&amp;clmo0pgpg001fmc0j0xjcbkz2</loc>
    <lastmod>2023-09-17T22:17:13.541Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_DeviceNetworkEvents&amp;clmo0p09w001dmc0jagnqw3te</loc>
    <lastmod>2023-09-17T22:16:52.245Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_Cisco_Umbrella_dns_CL&amp;clmo0oet5001bmc0jp9k3zkz8</loc>
    <lastmod>2023-09-17T22:16:24.426Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-DomainEntity_AuditLogs&amp;clmo0nxf10019mc0jgsqfrvcf</loc>
    <lastmod>2023-09-17T22:16:01.886Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-KeyvaultMassSecretRetrieval&amp;clmo0nkjk0017mc0jh4akz7jv</loc>
    <lastmod>2023-09-17T22:15:45.202Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-DisabledAccountSigninsAcrossManyApplications&amp;clmo0n7rz0015mc0jyc9cpkek</loc>
    <lastmod>2023-09-17T22:15:28.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-AppOrServicePrincipalCredential&amp;clmo0muq40014mc0j9bmnkzcz</loc>
    <lastmod>2023-09-17T22:15:11.883Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-powershell_empire&amp;clmo0mke50013mc0j5l4bug45</loc>
    <lastmod>2023-09-17T22:14:58.349Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-RDP_RareConnection&amp;clmo0l8050011mc0j2djo1kar</loc>
    <lastmod>2023-09-17T22:13:55.780Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Application%20consent%20or%20assignment&amp;clmo0kxt10010mc0jg27d8owg</loc>
    <lastmod>2023-09-17T22:13:42.564Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unfamiliar%20sign-in%20properties&amp;clmo0kkbp000zmc0judsuvxe4</loc>
    <lastmod>2023-09-17T22:13:25.092Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Risky%20account%20changed%20authentication%20method&amp;clmo0kaux000ymc0jxbjl3pol</loc>
    <lastmod>2023-09-17T22:13:12.682Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Malicious%20IP%20address&amp;clmo0k3lp000xmc0j0kixo8bg</loc>
    <lastmod>2023-09-17T22:13:03.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Azure%20AD%20Identity%20Protection%20alerts&amp;clmo0jffz000vmc0jgxhbdii4</loc>
    <lastmod>2023-09-17T22:12:31.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Atypical%20travel&amp;clmo0j7cp000tmc0jcspma2sj</loc>
    <lastmod>2023-09-17T22:12:21.624Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Anonymous%20IP%20address&amp;clmo0j0yv000rmc0jq2578k8p</loc>
    <lastmod>2023-09-17T22:12:13.209Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Anomalous%20Token&amp;clmo0itzk000pmc0jbaxz6m29</loc>
    <lastmod>2023-09-17T22:12:04.303Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20account%20created&amp;clmo0ik7f000nmc0jyq32wb0g</loc>
    <lastmod>2023-09-17T22:11:51.484Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Unexpected%20AD%20attributes%20accessed&amp;clmo0ibcy000mmc0jo6utzj5a</loc>
    <lastmod>2023-09-17T22:11:40.161Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Activity%20with%20monitored%20AD%20group&amp;clmo0i4vs000kmc0jl1oe27e9</loc>
    <lastmod>2023-09-17T22:11:31.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-AzureFirewallLogs-AzureDiagnostics&amp;clmo0hltz000imc0jdtfm6nfo</loc>
    <lastmod>2023-09-17T22:11:06.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-AzureFirewallLogs-AZFW*&amp;clmo0g976000gmc0jj49fb384</loc>
    <lastmod>2023-09-17T22:10:04.049Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UserRiskStatus&amp;clmnzwzqt001f5i44y3bkyvua</loc>
    <lastmod>2023-09-17T21:55:05.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListDomainControllers&amp;clmnzwvc1001e5i44t1xi4lxg</loc>
    <lastmod>2023-09-17T21:54:59.608Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListAllActionsAndOperations&amp;clmnzwryo001d5i44nfdb4tl1</loc>
    <lastmod>2023-09-17T21:54:55.247Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LastPowerShellExecutions&amp;clmnzwnz3001c5i44hwzpapwi</loc>
    <lastmod>2023-09-17T21:54:50.078Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IsDomainController&amp;clmnzwih7001b5i44zg7uktnb</loc>
    <lastmod>2023-09-17T21:54:42.946Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DeviceCommandLinePublicIPs&amp;clmnzwcfh001a5i44vz8jy16r</loc>
    <lastmod>2023-09-17T21:54:35.116Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20MostInteractiveSignInsByUser&amp;clmnzw72w00195i44iz17d031</loc>
    <lastmod>2023-09-17T21:54:28.183Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ClearTextLDAPSignIns&amp;clmnzw3hz00185i447yje2qtz</loc>
    <lastmod>2023-09-17T21:54:23.534Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UserAddedToSensitiveGroup&amp;clmnzvzsi00175i44m7eail2z</loc>
    <lastmod>2023-09-17T21:54:18.737Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMBFileCopy&amp;clmnzvub500165i44ylff4d9x</loc>
    <lastmod>2023-09-17T21:54:11.633Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialKerberosEncryptionDowngrade&amp;clmnzvpb000155i44rgslac41</loc>
    <lastmod>2023-09-17T21:54:05.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PasswordChangeAfterSuccesfulBruteForce&amp;clmnzvlv200145i44fy7etrwx</loc>
    <lastmod>2023-09-17T21:54:00.685Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewLateralMovementPathToSensitiveAccountIdentified&amp;clmnzvg1u00135i442pklvzm6</loc>
    <lastmod>2023-09-17T21:53:53.153Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousLDAPTraffic&amp;clmnzvbdh00125i448bcsa7bv</loc>
    <lastmod>2023-09-17T21:53:47.085Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousGroupPolicyDiscovery&amp;clmnzv19q00115i44u497vwnv</loc>
    <lastmod>2023-09-17T21:53:33.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AccountWithPasswordNeverExpiresEnabled&amp;clmnzuxsf00105i44txmqz8bh</loc>
    <lastmod>2023-09-17T21:53:29.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WindowsNetworkSniffing&amp;clmnzutvs000z5i44xd7kbh3e</loc>
    <lastmod>2023-09-17T21:53:24.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WMICAntivirusDiscovery&amp;clmnzuqv3000y5i44rewyz416</loc>
    <lastmod>2023-09-17T21:53:20.510Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization-%20%20DefenderMachineGroups&amp;clmnzule0000x5i44sxgt8rmi</loc>
    <lastmod>2023-09-17T21:53:13.415Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20UnauthorizedLogonsByAccount&amp;clmnzuj0p000w5i44xi46qvcp</loc>
    <lastmod>2023-09-17T21:53:10.336Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20SysinternalToolUsage&amp;clmnzudbu000v5i447b2s7cw1</loc>
    <lastmod>2023-09-17T21:53:02.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20LogonFailureReasons&amp;clmnzua9i000u5i441u9q7voc</loc>
    <lastmod>2023-09-17T21:52:58.997Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20InspectedNetworkSignatures&amp;clmnzu7bw000t5i44swen5cj7</loc>
    <lastmod>2023-09-17T21:52:55.188Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SmartScreenOverride&amp;clmnzu36b000s5i44dsza2r4n</loc>
    <lastmod>2023-09-17T21:52:49.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SmartScreenEvents&amp;clmnzu0cp000r5i44khyy7a9a</loc>
    <lastmod>2023-09-17T21:52:46.152Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ShadowCopyDeletion&amp;clmnztutl000q5i44jp8srwix</loc>
    <lastmod>2023-09-17T21:52:38.977Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityLogCleared&amp;clmnztra3000p5i44ti879466</loc>
    <lastmod>2023-09-17T21:52:34.395Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMBSessionsGeneratedByFile&amp;clmnztnkd000o5i44ddag5q1p</loc>
    <lastmod>2023-09-17T21:52:29.580Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMBSessionsByFileName&amp;clmnztklq000n5i44oudteg0i</loc>
    <lastmod>2023-09-17T21:52:25.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SMBSessionsByDevice&amp;clmnzthtb000m5i44l878gael</loc>
    <lastmod>2023-09-17T21:52:22.118Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RunasWithSavedCredentials&amp;clmnztcxs000l5i44euhu5mvc</loc>
    <lastmod>2023-09-17T21:52:15.807Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RemoteSMBConnection&amp;clmnzt7wd000j5i44w9tu4tax</loc>
    <lastmod>2023-09-17T21:52:09.276Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Regsvr32StartedByOfficeApplication&amp;clmnzt44m000h5i4495b8585s</loc>
    <lastmod>2023-09-17T21:52:04.389Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RareISOFile&amp;clmnzt0d1000f5i447zwspj4m</loc>
    <lastmod>2023-09-17T21:51:59.508Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RareConnectionsMadeByOffice&amp;clmnzsw92000d5i44yin680u8</loc>
    <lastmod>2023-09-17T21:51:54.180Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RansomwareNoteFound&amp;clmnzss3q000b5i443yk6vbpn</loc>
    <lastmod>2023-09-17T21:51:48.805Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RansomwareExtensionFound&amp;clmnzsoge000a5i44cqaka2os</loc>
    <lastmod>2023-09-17T21:51:44.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RansomwareDoubleExtention&amp;clmnzsgzs00085i449gnr26ea</loc>
    <lastmod>2023-09-17T21:51:34.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/KillNetRansomwareDetection&amp;clmnzsb9f00065i44tra94x00</loc>
    <lastmod>2023-09-17T21:51:26.978Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/QakbotPostCompromiseCommandsExecuted&amp;clmnzs7t700045i44xnpo8xxq</loc>
    <lastmod>2023-09-17T21:51:22.505Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PublicFacingDeviceScanned&amp;clmnzs3v500025i44skw8fqis</loc>
    <lastmod>2023-09-17T21:51:17.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellEncodedWebRequests&amp;clmnzs03v00005i44ks58nm3e</loc>
    <lastmod>2023-09-17T21:51:12.522Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellEncodedReconActivities&amp;clmnzhpek001y5isk6hh4jozz</loc>
    <lastmod>2023-09-17T21:43:12.091Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellEncodedCommandsExecuted&amp;clmnzhl8d001x5isklj6rn2cy</loc>
    <lastmod>2023-09-17T21:43:06.676Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PowerShellEncodedCommandsByDevice&amp;clmnzheh4001w5isk6jnba1ks</loc>
    <lastmod>2023-09-17T21:42:57.927Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PSExecExecutions&amp;clmnzh8xd001v5iskdtbkdn0v</loc>
    <lastmod>2023-09-17T21:42:50.728Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewSysinternalToolDetected&amp;clmnzh444001u5iskueie8k04</loc>
    <lastmod>2023-09-17T21:42:44.499Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewRDPConnections&amp;clmnzgzg7001t5iskuwkei7vh</loc>
    <lastmod>2023-09-17T21:42:38.454Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20-%20OpenRemoteServicePorts&amp;clmnzguua001s5isk9dujvzuh</loc>
    <lastmod>2023-09-17T21:42:32.473Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20-%20OpenDatabasePorts&amp;clmnzgrl7001r5iskw6ytqnwg</loc>
    <lastmod>2023-09-17T21:42:28.266Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20-%20InterestingOpenPorts&amp;clmnzgonx001q5iskrlnwqggl</loc>
    <lastmod>2023-09-17T21:42:24.476Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20-%20DevicesWithMostOpenPorts&amp;clmnzgk5q001o5iskll19bz6e</loc>
    <lastmod>2023-09-17T21:42:18.638Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Network%20-%20AnyDeskConnectionToPublicIP&amp;clmnzggqn001m5iskvtnrs2g3</loc>
    <lastmod>2023-09-17T21:42:14.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalFirewallDeletions&amp;clmnzgckq001k5iska2jyd0b0</loc>
    <lastmod>2023-09-17T21:42:08.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalFirewallAdditions&amp;clmnzg8j0001i5iskcryz4zrw</loc>
    <lastmod>2023-09-17T21:42:03.563Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalAdminsWithTheMostDevicesAccessed&amp;clmnzg4vs001g5isk8kuc7z3i</loc>
    <lastmod>2023-09-17T21:41:58.831Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LocalAccountCreated&amp;clmnzg091001e5iskx9qm5ith</loc>
    <lastmod>2023-09-17T21:41:52.836Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WMICRemoteCommand&amp;clmnzfubn001c5iskya40r4x3</loc>
    <lastmod>2023-09-17T21:41:45.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewLOLBinExternalConnection&amp;clmnzfqaw001a5isk1cavfxjw</loc>
    <lastmod>2023-09-17T21:41:39.935Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LOTSUsage&amp;clmnzfjph00185iskyw5sppfe</loc>
    <lastmod>2023-09-17T21:41:31.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LOLDriverUsage&amp;clmnzfcvb00165isk6rcc0gik</loc>
    <lastmod>2023-09-17T21:41:22.526Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LOLBinStatistics&amp;clmnzf82400145iskyw882d92</loc>
    <lastmod>2023-09-17T21:41:16.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ListTamperingAttempts&amp;clmnzf4lp00125iskj59wbmx3</loc>
    <lastmod>2023-09-17T21:41:11.820Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Linux%20-%20UsersAddedToSudoersGroup&amp;clmnzeyvu00105iskruktcwft</loc>
    <lastmod>2023-09-17T21:41:04.401Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HTTPRequestMethodsStatistics&amp;clmnzev1g000y5iskpfu6z1od</loc>
    <lastmod>2023-09-17T21:40:59.427Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HTTPExecutableFilesDownloaded&amp;clmnzerll000w5isk3zqax3e8</loc>
    <lastmod>2023-09-17T21:40:54.969Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HTTPDownloadsByFileExtention&amp;clmnzemzv000u5iskztxdqhb5</loc>
    <lastmod>2023-09-17T21:40:48.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExploitGuardNetworkProtection&amp;clmnzeima000s5iskh3eifr44</loc>
    <lastmod>2023-09-17T21:40:43.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExecutableFilesPublicFolder&amp;clmnzeevw000q5iskrb2zdumq</loc>
    <lastmod>2023-09-17T21:40:38.491Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Discovery%20-%20DatabaseServices&amp;clmnze9zm000o5iskj2y9nhjt</loc>
    <lastmod>2023-09-17T21:40:32.137Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevicesWithTheMostSMBSessions&amp;clmnze4r7000m5iskq9257oxx</loc>
    <lastmod>2023-09-17T21:40:25.362Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DevicesWithMostSMBConnections&amp;clmnze1uw000k5iskpqs6c4ad</loc>
    <lastmod>2023-09-17T21:40:21.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BloodHoundProcessDetection&amp;clmnzdwgh000i5isknqvv8ydw</loc>
    <lastmod>2023-09-17T21:40:14.601Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousSMBSessionsCreated&amp;clmnzdrj5000g5iskn4qlgp9s</loc>
    <lastmod>2023-09-17T21:40:08.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Pivot%20-%20ASRTriggers&amp;clmnzdkcr000e5isk7j7ahzzw</loc>
    <lastmod>2023-09-17T21:39:58.914Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrRansomware&amp;clmnzdh3p000c5iskm4g5moe0</loc>
    <lastmod>2023-09-17T21:39:54.708Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AsrExecutableOfficeContent&amp;clmnzdbgj000a5isksmtepicc</loc>
    <lastmod>2023-09-17T21:39:47.394Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASR-RulesTriggeredByDevice&amp;clmnzd71600085isky74khjsu</loc>
    <lastmod>2023-09-17T21:39:41.649Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AMSIScriptDetections&amp;clmnzd3t600065iskd4yw4ohf</loc>
    <lastmod>2023-09-17T21:39:37.481Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20OutdatedOSUsed&amp;clmnzd0h000045iskzwd2x83g</loc>
    <lastmod>2023-09-17T21:39:33.155Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20OperationsPerformed&amp;clmnzcwsm00025iskg7s4tyka</loc>
    <lastmod>2023-09-17T21:39:28.390Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20HardDeletionsByUser&amp;clmnzctgx00005isk5wf7i4uj</loc>
    <lastmod>2023-09-17T21:39:24.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20ActionsPerformed&amp;clmnz6klh001e5imcybiojt55</loc>
    <lastmod>2023-09-17T21:34:32.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SupressionRuleCreations&amp;clmnz6gzq001d5imcqpc891v8</loc>
    <lastmod>2023-09-17T21:34:27.974Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RiskyIPActivities&amp;clmnz6di4001c5imck37vg0c3</loc>
    <lastmod>2023-09-17T21:34:23.443Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MostImpersonatorsByAccount&amp;clmnz6a1x001b5imcohrf52w1</loc>
    <lastmod>2023-09-17T21:34:18.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MaliciousEmailDeliveredInMailbox&amp;clmnz64he001a5imc1v0suuql</loc>
    <lastmod>2023-09-17T21:34:11.762Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MITREBehaviors&amp;clmnz5zul00195imc1efiyruz</loc>
    <lastmod>2023-09-17T21:34:05.749Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HardUserDelete&amp;clmnz5u5a00185imci8z7kbbg</loc>
    <lastmod>2023-09-17T21:33:58.365Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FileContainingMalwareDetected&amp;clmnz5qbt00175imc98db76ts</loc>
    <lastmod>2023-09-17T21:33:53.417Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalAdminActivities&amp;clmnz5mse00165imcju9d0pv2</loc>
    <lastmod>2023-09-17T21:33:48.821Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenseEvasionAlerts&amp;clmnz5ids00155imcidxzbjix</loc>
    <lastmod>2023-09-17T21:33:43.120Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnonymousProxyEvents&amp;clmnz5dqu00145imcgx3ptb0s</loc>
    <lastmod>2023-09-17T21:33:37.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AccountsWithMostImpersonatedActions&amp;clmnz58wp00135imcp35koewy</loc>
    <lastmod>2023-09-17T21:33:30.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ATPDetectionEvents&amp;clmnz4zda00125imcniptrxxu</loc>
    <lastmod>2023-09-17T21:33:18.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity%20-%20OfficeActivitiesCompromisedAccount&amp;clmnz4v8w00115imca6cy8xys</loc>
    <lastmod>2023-09-17T21:33:13.135Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI%20-%20Lateral-Movement-By-Compromised-Accounts&amp;clmnz4pxe00105imc1mvt5vke</loc>
    <lastmod>2023-09-17T21:33:06.234Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI%20-%20LDAPQueriesByCompromisedDevice&amp;clmnz4ltj000z5imcd4yd4xrf</loc>
    <lastmod>2023-09-17T21:33:00.919Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI%20-%20Devices-Accessed-By-Compromised-Device&amp;clmnz4ih3000y5imchhk0mi9n</loc>
    <lastmod>2023-09-17T21:32:56.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDI%20-%20ADGroupAdditions&amp;clmnz4e3a000x5imcchc1scfx</loc>
    <lastmod>2023-09-17T21:32:50.894Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20UrlsOpenedWithOutlookFromCompromisedDevice&amp;clmnz46ib000w5imc0hc5wk7x</loc>
    <lastmod>2023-09-17T21:32:41.074Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20URLLookup&amp;clmnz420e000v5imcb1wiqqj8</loc>
    <lastmod>2023-09-17T21:32:35.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20TriggeredASREventsFromCompromisedDevice&amp;clmnz3ty3000u5imcu1qa7eb8</loc>
    <lastmod>2023-09-17T21:32:24.794Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20Registry-Run-Keys-Forensics&amp;clmnz3q53000t5imcq6s0mrwh</loc>
    <lastmod>2023-09-17T21:32:19.853Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20Open-SMB-Connections-By-Compromised-Device&amp;clmnz392c000s5imcmcbk8p47</loc>
    <lastmod>2023-09-17T21:31:57.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20MostRecentPowershellExecutionsByCompromisedDevice&amp;clmnz35uc000r5imc7trd7t2w</loc>
    <lastmod>2023-09-17T21:31:53.555Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20MD365-EmailAttachmentsSendFromCompromisedMailbox&amp;clmnz32sv000q5imcahyfvj9v</loc>
    <lastmod>2023-09-17T21:31:49.607Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20ListMaliciousActivities&amp;clmnz2xf1000p5imc6n5ppogp</loc>
    <lastmod>2023-09-17T21:31:42.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20InternalConnectionsMadeByCompromisedDevice&amp;clmnz2qvg000o5imczgzvxlsh</loc>
    <lastmod>2023-09-17T21:31:34.147Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20InboundConnectionsCompromisedDevice&amp;clmnz2h14000n5imc0i89h0zr</loc>
    <lastmod>2023-09-17T21:31:21.399Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20IPLookup&amp;clmnz2d9n000m5imc7ivi5a3d</loc>
    <lastmod>2023-09-17T21:31:16.523Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20FileEnrichmentOnSuspiciousFile&amp;clmnz25t2000l5imcvcmvdrxp</loc>
    <lastmod>2023-09-17T21:31:06.845Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20Connections-Made-By-Office-Compromised-Device&amp;clmnz21f0000k5imcom0gxa7z</loc>
    <lastmod>2023-09-17T21:31:01.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20BrowserLaunchedToOpenUrlByCompromisedDevice&amp;clmnz1wnj000j5imc36khuuoj</loc>
    <lastmod>2023-09-17T21:30:54.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20Antivirus-Detections-by-Compromised-Device&amp;clmnz1pwf000i5imc8ymxithd</loc>
    <lastmod>2023-09-17T21:30:46.231Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20AllProcessesCreatedByMaliciousFile&amp;clmnz1jst000h5imcnfomxsg8</loc>
    <lastmod>2023-09-17T21:30:38.332Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20UserRiskEvents&amp;clmnz1f63000g5imca1sq0356</loc>
    <lastmod>2023-09-17T21:30:32.331Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Visualization%20-%20PimActivation&amp;clmnz1c5p000f5imc17k8rjy9</loc>
    <lastmod>2023-09-17T21:30:28.420Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Top10UsersWithTheMostSignInIPsUsed&amp;clmnz18eg000e5imcmo2jiyny</loc>
    <lastmod>2023-09-17T21:30:23.559Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInsByUserAgent&amp;clmnz14sq000d5imc4kwb14oz</loc>
    <lastmod>2023-09-17T21:30:18.890Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SignInsByOS&amp;clmnz102s000c5imc1j49syrv</loc>
    <lastmod>2023-09-17T21:30:12.764Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityAlertTriggeredByRiskyUser&amp;clmnz0v92000b5imc6xqj2xdi</loc>
    <lastmod>2023-09-17T21:30:06.518Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewUserAgentUsed&amp;clmnz0qhs000a5imcz5xozj1z</loc>
    <lastmod>2023-09-17T21:30:00.351Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewAuthenticationAppDetected&amp;clmnz0lhe00095imck4lb7gj8</loc>
    <lastmod>2023-09-17T21:29:53.850Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GuestUsersWithADRoles&amp;clmnz0f1900085imcmc3o4ut1</loc>
    <lastmod>2023-09-17T21:29:45.501Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudPersistenceActivityByUserAtRisk&amp;clmnz09o200065imces2vbfsm</loc>
    <lastmod>2023-09-17T21:29:38.545Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CloudDiscoveryByUserAtRisk&amp;clmnz05w300045imc9uuirtk8</loc>
    <lastmod>2023-09-17T21:29:33.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureADDownloadAllUsers&amp;clmnz00y500025imcij6wqf5r</loc>
    <lastmod>2023-09-17T21:29:27.244Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ADRoleAdditions&amp;clmnyzxif00005imcffbwq9jw</loc>
    <lastmod>2023-09-17T21:29:22.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TopLevelDomains&amp;clmnymyzs00225i4sooju29dz</loc>
    <lastmod>2023-09-17T21:19:18.175Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BlockedURLs&amp;clmnymrvf00205i4syopzfcov</loc>
    <lastmod>2023-09-17T21:19:08.955Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Template&amp;clmnymm0q001y5i4sk47h81wz</loc>
    <lastmod>2023-09-17T21:19:01.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Active%20Directory%20-%20TI%20map%20IP%20entity%20to%20SigninLogs&amp;clmnymjqw001x5i4stqitcyea</loc>
    <lastmod>2023-09-17T21:18:58.424Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Active%20Directory%20-%20Suspicious%20Resource%20deployment&amp;clmnymcak001v5i4see249zd5</loc>
    <lastmod>2023-09-17T21:18:48.763Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Active%20Directory%20-%20Password%20spray%20attack%20against%20Azure%20AD%20application&amp;clmnym8ow001t5i4s6417bpth</loc>
    <lastmod>2023-09-17T21:18:44.088Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/mapping&amp;clmnym38w001r5i4sjvfkf7v8</loc>
    <lastmod>2023-09-17T21:18:37.039Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDO%20-%20Email%20Attachment%20File%20Extensions&amp;clmnylw8w001p5i4stmvcu57h</loc>
    <lastmod>2023-09-17T21:18:27.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows%20Server%20-%20Missing%20Security%20Updates&amp;clmnylqmf001n5i4sdkxhrhx8</loc>
    <lastmod>2023-09-17T21:18:20.678Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows%2010%20-%20Missing%20Security%20Updates&amp;clmnyljaj001l5i4s38f8m5tq</loc>
    <lastmod>2023-09-17T21:18:11.170Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TVM-Exposure-VulnerabilitySeverityLevel&amp;clmnylfpk001j5i4sxuzrmhd3</loc>
    <lastmod>2023-09-17T21:18:06.535Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Linux-RedHat%20-%20Missing%20Security%20Updates&amp;clmnylb3j001h5i4s88h47ue7</loc>
    <lastmod>2023-09-17T21:18:00.558Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DefenderNetworkProtectionEvents&amp;clmnyl5u4001f5i4s40y4xupy</loc>
    <lastmod>2023-09-17T21:17:53.732Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Zeek&amp;clmnykyyf001d5i4smc92wcfb</loc>
    <lastmod>2023-09-17T21:17:44.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Windows%2010%20LTSC%20Inventory&amp;clmnyktzm001b5i4sw4rylm5l</loc>
    <lastmod>2023-09-17T21:17:38.385Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WMIEventSubscription&amp;clmnyko2f00195i4snfyvr0ph</loc>
    <lastmod>2023-09-17T21:17:30.702Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WDACBlockList&amp;clmnykkfa00175i4s12odxd57</loc>
    <lastmod>2023-09-17T21:17:25.989Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Unified%20Agent&amp;clmnykgft00155i4syxb5j02y</loc>
    <lastmod>2023-09-17T21:17:20.824Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TroubleshootingMode&amp;clmnykbgi00135i4s1zz3hc7t</loc>
    <lastmod>2023-09-17T21:17:14.361Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Tampering&amp;clmnyk3k100115i4sodobd5z1</loc>
    <lastmod>2023-09-17T21:17:04.128Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-PUA%20Detections&amp;clmnyjzkp000z5i4s4346ncjs</loc>
    <lastmod>2023-09-17T21:16:58.968Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-Offboarding&amp;clmnyjvb7000y5i4sfrxv57a8</loc>
    <lastmod>2023-09-17T21:16:53.434Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-NTFS%20File%20Attributes%20-%20alternate%20data%20streams&amp;clmnyjs22000x5i4sjr7g57q4</loc>
    <lastmod>2023-09-17T21:16:49.225Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-MMA-Update&amp;clmnyjpav000w5i4sr02w5bv9</loc>
    <lastmod>2023-09-17T21:16:45.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-InternetFacing&amp;clmnyjlac000v5i4s9a47kfgx</loc>
    <lastmod>2023-09-17T21:16:40.452Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-GroupPolicyModificationEvents&amp;clmnyjhax000u5i4s5bnogjt3</loc>
    <lastmod>2023-09-17T21:16:35.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceInventory%20-%20Network-IoT&amp;clmnyj6hi000s5i4sisebbbg1</loc>
    <lastmod>2023-09-17T21:16:21.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceDiscovery_SeenBy&amp;clmnyiygj000q5i4sql98jsh0</loc>
    <lastmod>2023-09-17T21:16:10.866Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DeviceDiscovery&amp;clmnyip0w000o5i4sph2s5osh</loc>
    <lastmod>2023-09-17T21:15:58.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DefenderSmartScreenEvents&amp;clmnyigut000n5i4sjdw5ue8v</loc>
    <lastmod>2023-09-17T21:15:48.052Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-DefenderEngine&amp;clmnyicpm000m5i4sxk777qgv</loc>
    <lastmod>2023-09-17T21:15:42.674Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-AmsiScriptDetection&amp;clmnyi2k6000l5i4sulxa4pqn</loc>
    <lastmod>2023-09-17T21:15:29.525Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-ASR%20State&amp;clmnyhx6x000k5i4suvkem1bc</loc>
    <lastmod>2023-09-17T21:15:22.560Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE%20-%20Detection%20-%20Removal%20and%20Quarantine%20actions&amp;clmnyhpoh000j5i4svr0h9v9a</loc>
    <lastmod>2023-09-17T21:15:12.832Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-ExploitGuard&amp;clmnyhj9o000i5i4sbt8zeosn</loc>
    <lastmod>2023-09-17T21:15:04.515Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-FirewallEvents&amp;clmnyhg79000h5i4s3m4rpq0v</loc>
    <lastmod>2023-09-17T21:15:00.548Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MCAS-ShadowReporting&amp;clmnyhchy000g5i4sdriyc7d8</loc>
    <lastmod>2023-09-17T21:14:55.748Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EASM-Usage&amp;clmnyh5ns000f5i4sv5r9ueob</loc>
    <lastmod>2023-09-17T21:14:46.880Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EASM-Risky%20Assets&amp;clmnygzqw000e5i4sk16ygmlw</loc>
    <lastmod>2023-09-17T21:14:39.223Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EASM-OpenPorts&amp;clmnyguwj000d5i4s7od5x1qr</loc>
    <lastmod>2023-09-17T21:14:32.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MD365-PasswordSprayAttacks&amp;clmnygqzg000c5i4sjsdfq71d</loc>
    <lastmod>2023-09-17T21:14:27.859Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MD365%20-%20SafeDocs&amp;clmnygi9o000a5i4sxqx09a6k</loc>
    <lastmod>2023-09-17T21:14:16.572Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Azure%20Resource%20Graph&amp;clmnygdc700085i4snzusgmkn</loc>
    <lastmod>2023-09-17T21:14:10.175Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-PowerShell&amp;clmnyg0ag00065i4sjsopazrz</loc>
    <lastmod>2023-09-17T21:13:53.272Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureAD-ConditionalAccessPolicyChanges&amp;clmnyfudp00045i4soprq1y1p</loc>
    <lastmod>2023-09-17T21:13:45.605Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppG-AppActivities&amp;clmnyfrbb00025i4sgtvfozc2</loc>
    <lastmod>2023-09-17T21:13:41.639Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AD-ExtractUserOU&amp;clmnyfmcz00005i4sd08vpy06</loc>
    <lastmod>2023-09-17T21:13:35.217Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/wmi3&amp;clmnyb9d5000a5ip40sbjf6y4</loc>
    <lastmod>2023-09-17T21:10:11.743Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/wmi2&amp;clmnyb4wy00095ip4s3vtmenr</loc>
    <lastmod>2023-09-17T21:10:05.985Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/wmi1&amp;clmnyaysb00075ip4qz8iemur</loc>
    <lastmod>2023-09-17T21:09:58.042Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/find_scheduled_tasks&amp;clmnyau3x00065ip41raf508f</loc>
    <lastmod>2023-09-17T21:09:51.972Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/device_events_scheduled_tasks&amp;clmnyaphj00045ip4vg6ngnvn</loc>
    <lastmod>2023-09-17T21:09:45.990Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/psexec1&amp;clmnyal9500025ip4a0jwg3db</loc>
    <lastmod>2023-09-17T21:09:40.504Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/find_rmm_processes&amp;clmnyai1o00005ip4gm8dlvyr</loc>
    <lastmod>2023-09-17T21:09:36.347Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UncommonTLDs&amp;clmny51xy002h5i6w242lf4z8</loc>
    <lastmod>2023-09-17T21:05:22.189Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TopAppsCrashing&amp;clmny4vqi002f5i6wxb4dbb1t</loc>
    <lastmod>2023-09-17T21:05:14.154Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IdentityCorrelation&amp;clmny4mrm002d5i6whjosp7qj</loc>
    <lastmod>2023-09-17T21:05:02.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AppLockerPolicy&amp;clmny4h8a002b5i6woz5mf2ck</loc>
    <lastmod>2023-09-17T21:04:55.353Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/WiFiNetworkNames&amp;clmny4a4400295i6wud9rfkis</loc>
    <lastmod>2023-09-17T21:04:46.131Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TopSocialMedia&amp;clmny45yu00275i6wrt9kxref</loc>
    <lastmod>2023-09-17T21:04:40.757Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialLeavers&amp;clmny3ys900255i6w596l6gwk</loc>
    <lastmod>2023-09-17T21:04:31.440Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PersonalEmailUsage&amp;clmny3p6g00235i6wdl8r7uyr</loc>
    <lastmod>2023-09-17T21:04:18.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SystemProcessNetCons&amp;clmny3kmo00215i6wt4se87nn</loc>
    <lastmod>2023-09-17T21:04:13.104Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GloballyRareService&amp;clmny3h6k001z5i6wbed7s5cc</loc>
    <lastmod>2023-09-17T21:04:08.636Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DetectAllTheThings&amp;clmny3aq1001x5i6wgz1k2do9</loc>
    <lastmod>2023-09-17T21:04:00.256Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/VulnerabilityPercentages&amp;clmny366i001v5i6wjb0bt49g</loc>
    <lastmod>2023-09-17T21:03:54.377Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UndocumentedRMM&amp;clmny2yk4001t5i6wsz1o9981</loc>
    <lastmod>2023-09-17T21:03:44.492Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/FilesWithPasswords&amp;clmny2sg8001r5i6wsggjceuu</loc>
    <lastmod>2023-09-17T21:03:36.583Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EndpointStatusReport&amp;clmny2opp001p5i6wopctqtru</loc>
    <lastmod>2023-09-17T21:03:31.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CriticalVulnerabilities&amp;clmny2jsb001n5i6woku71ng5</loc>
    <lastmod>2023-09-17T21:03:25.346Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CleartextLDAP&amp;clmny2cst001l5i6wrhwycsiy</loc>
    <lastmod>2023-09-17T21:03:16.300Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PhishLinkClickers&amp;clmny28o0001j5i6wt4b1ujir</loc>
    <lastmod>2023-09-17T21:03:10.944Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PhishDelivered&amp;clmny255f001h5i6wdd6l6amz</loc>
    <lastmod>2023-09-17T21:03:06.379Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MassIncomingEmail&amp;clmny1xr4001f5i6wknoovebr</loc>
    <lastmod>2023-09-17T21:02:56.800Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/EmailsWithOAuthRequests&amp;clmny1t85001d5i6w2oevlhpn</loc>
    <lastmod>2023-09-17T21:02:50.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/IOCSearch&amp;clmny1p5q001b5i6wpr81nuc7</loc>
    <lastmod>2023-09-17T21:02:45.661Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/CompromisedDevicesSMB&amp;clmny1hk300195i6wcortez26</loc>
    <lastmod>2023-09-17T21:02:35.810Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/BaselineComparison&amp;clmny1cch00175i6wv2ydvmo5</loc>
    <lastmod>2023-09-17T21:02:29.057Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SeriousSAM&amp;clmny13tk00155i6wkuetqd1o</loc>
    <lastmod>2023-09-17T21:02:18.007Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Follina&amp;clmny0z7p00135i6wtjo96a4p</loc>
    <lastmod>2023-09-17T21:02:12.037Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XLLDropper&amp;clmny0v3z00115i6w1sgwyz30</loc>
    <lastmod>2023-09-17T21:02:06.718Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/URLhausNetworkEvents&amp;clmny0nwc000z5i6w900m8fkf</loc>
    <lastmod>2023-09-17T21:01:57.371Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SilentPARegistration&amp;clmny0kdf000x5i6wfza890fw</loc>
    <lastmod>2023-09-17T21:01:52.802Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SharpHoundOutput&amp;clmny0gx4000v5i6wnzouyar6</loc>
    <lastmod>2023-09-17T21:01:48.328Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SensitiveGroupModification&amp;clmny0dk4000t5i6wvpzjuefz</loc>
    <lastmod>2023-09-17T21:01:43.963Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/RenamedRclone&amp;clmny07vb000r5i6wd0pgj5z0</loc>
    <lastmod>2023-09-17T21:01:36.598Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Rclone&amp;clmny033x000p5i6wcj3t6hfl</loc>
    <lastmod>2023-09-17T21:01:30.428Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OneNoteWeirdLocation&amp;clmny00et000o5i6wdqhu5yl2</loc>
    <lastmod>2023-09-17T21:01:26.932Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MegaExfiltration&amp;clmnxzx2q000m5i6wc2h1g8i7</loc>
    <lastmod>2023-09-17T21:01:22.609Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/LoLDrivers&amp;clmnxzs7r000k5i6wfkoatpp3</loc>
    <lastmod>2023-09-17T21:01:16.310Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DoubleFileExtension&amp;clmnxzn5j000i5i6wp7qdeetp</loc>
    <lastmod>2023-09-17T21:01:09.742Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/TopRemoteLogons&amp;clmnxzhhz000g5i6w8p4n2i81</loc>
    <lastmod>2023-09-17T21:01:02.423Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousLogonTimeline&amp;clmnxz9vm000e5i6w4dwwal2s</loc>
    <lastmod>2023-09-17T21:00:52.537Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousEmailAttachment&amp;clmnxz32w000c5i6wqthdit4r</loc>
    <lastmod>2023-09-17T21:00:43.736Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AnomalousBatExecTimeline&amp;clmnxywuo000a5i6wv5l7os29</loc>
    <lastmod>2023-09-17T21:00:35.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASRTopUsers&amp;clmnxym0q00085i6wm0ems3x6</loc>
    <lastmod>2023-09-17T21:00:21.625Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASRTopRules&amp;clmnxyg3000065i6wat6pnkpz</loc>
    <lastmod>2023-09-17T21:00:13.931Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASRTopFiles&amp;clmnxyc5c00045i6wka4ye6ex</loc>
    <lastmod>2023-09-17T21:00:08.823Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASRSummary&amp;clmnxy8ft00025i6w32e1y20t</loc>
    <lastmod>2023-09-17T21:00:04.025Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ASRSingleRuleAudits&amp;clmnxy3r000005i6wm0h1dbac</loc>
    <lastmod>2023-09-17T20:59:57.947Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnusualSensitiveActionPerformedByAzureADConnectAccount&amp;clmnxtk5d00065iy0hbu0siob</loc>
    <lastmod>2023-09-17T20:56:25.921Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialMaliciousSign-inFromAzureADConnectAccountUEBA&amp;clmnxtbf900045iy0owbj8o4a</loc>
    <lastmod>2023-09-17T20:56:14.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OwnerAddedToHighPrivilegedApplication&amp;clmnxt37900025iy0dmdamrml</loc>
    <lastmod>2023-09-17T20:56:03.956Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/HighPrivilegedRoleAssigned&amp;clmnxswmk00005iy08btdkoqn</loc>
    <lastmod>2023-09-17T20:55:55.435Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/UnusualSensitiveActionPerformedByAzureADConnectAccountUEBA&amp;clmnxsjgm000p5ih8twlk9caa</loc>
    <lastmod>2023-09-17T20:55:38.366Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ChangesToAzureLighthouseDelegation&amp;clmnxqumh000o5ih8ftksd6fk</loc>
    <lastmod>2023-09-17T20:54:19.528Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureVMRunCommandorCustomScriptExecution&amp;clmnxqox7000n5ih84fv214m0</loc>
    <lastmod>2023-09-17T20:54:12.130Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecretAddedToHighPrivilegedApplication&amp;clmnxps4d000i5ih8fh84sdjn</loc>
    <lastmod>2023-09-17T20:53:29.620Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialMalicousDomainRegistration&amp;clmnxpiq4000g5ih8cmlc7iwm</loc>
    <lastmod>2023-09-17T20:53:17.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PotentialMaliciousSign-inFromAzureADConnectAccount&amp;clmnxp0tb000c5ih848mc479c</loc>
    <lastmod>2023-09-17T20:52:54.230Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/PasswordResetOnHighPrivilegedUser&amp;clmnxosrx000a5ih87h7b78el</loc>
    <lastmod>2023-09-17T20:52:43.820Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/NewLighthouseServiceProviderWasAdded&amp;clmnxodz200065ih8oqoxitf0</loc>
    <lastmod>2023-09-17T20:52:24.637Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DangerousAPIPermissionConsented&amp;clmnxo4qx00025ih8trn40krh</loc>
    <lastmod>2023-09-17T20:52:12.673Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureVmRunCommandOrCustomScriptExecutionDetected&amp;clmnxnxzu00005ih8pcn1ds7g</loc>
    <lastmod>2023-09-17T20:52:03.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GrantHighPrivilegeMicrosoftGraphPermissions&amp;clmnxn2n100025i98kwtkiqiy</loc>
    <lastmod>2023-09-17T20:51:23.285Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/GrantHighPrivilegeAzureADRoleToIdentity&amp;clmnxmwmr00005i989acu2sq3</loc>
    <lastmod>2023-09-17T20:51:15.506Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AzureADRoleAssignments&amp;clmnx0wpj00005i3ol92wdvao</loc>
    <lastmod>2023-09-17T20:34:09.174Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-ShowUsersThatAbandonedTheIntuneEnrollment&amp;clmnvqxz900005iq077wocszl</loc>
    <lastmod>2023-09-17T19:58:24.644Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Syslog-FailedLogonAttempts_UnknownUser&amp;clmnu5fdi002e5izsl92gkler</loc>
    <lastmod>2023-09-17T19:13:41.133Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-office_policytampering&amp;clmnu4tuj002c5izswiphtrgu</loc>
    <lastmod>2023-09-17T19:13:13.235Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-exchange_auditlogdisabled&amp;clmnu4ijc002b5izsaz4ranrg</loc>
    <lastmod>2023-09-17T19:12:58.584Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-SharePoint_Downloads_byNewIP&amp;clmnu46ed00295izsxecjxsks</loc>
    <lastmod>2023-09-17T19:12:42.852Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/OfficeActivity-Office_MailForwarding&amp;clmnu3mf600275izs3kgdxs77</loc>
    <lastmod>2023-09-17T19:12:16.953Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-malware_in_recyclebin&amp;clmnu37zf00255izs23r7s695</loc>
    <lastmod>2023-09-17T19:11:58.243Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-WindowsBinariesExecutedfromNon-DefaultDirectory&amp;clmnu2kkj00235izs8ybcs3ml</loc>
    <lastmod>2023-09-17T19:11:27.906Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-PotentialRemoteDesktopTunneling&amp;clmnu20br00215izswg6r4lm5</loc>
    <lastmod>2023-09-17T19:11:01.662Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-MFADisable_AzureAD&amp;clmnu1iwa001z5izs9h0mh518</loc>
    <lastmod>2023-09-17T19:10:39.073Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-AdminPromoAfterRoleMgmtAppPermissionGrant&amp;clmnu1265001y5izsc9hnt6rl</loc>
    <lastmod>2023-09-17T19:10:17.405Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-AzureADRoleManagementPermissionGrant&amp;clmnu11e4001x5izsco8ru9hl</loc>
    <lastmod>2023-09-17T19:10:16.387Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-UserPrincipalNameAssignedToUserAccount&amp;clmnu0959001w5izsbqgpb0nq</loc>
    <lastmod>2023-09-17T19:09:39.789Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-PrivilegedUserLogonfromnewASN&amp;clmnu08gd001v5izs8gxfiwgp</loc>
    <lastmod>2023-09-17T19:09:38.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-RDP_Nesting&amp;clmntyqf1001t5izs38xb5f1e</loc>
    <lastmod>2023-09-17T19:08:28.851Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-PotenialResourceBasedConstrainedDelegationAbuse&amp;clmnty3tj001s5izs2l54bh4x</loc>
    <lastmod>2023-09-17T19:07:59.566Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AdminSDHolder_Modifications&amp;clmntxlnf001r5izszk5fuawb</loc>
    <lastmod>2023-09-17T19:07:36.019Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-SecurityServiceRegistryACLModification&amp;clmntx61j001q5izsbwi6n9iz</loc>
    <lastmod>2023-09-17T19:07:15.790Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-AuditPolicyManipulation_using_auditpol&amp;clmntwida001p5izslocq0g36</loc>
    <lastmod>2023-09-17T19:06:45.110Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-SuspiciousModificationofGlobalAdminProperties&amp;clmntw601001o5izs7vn5l0js</loc>
    <lastmod>2023-09-17T19:06:29.080Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-SuspiciousLoginfromDeletedExternalIdentities&amp;clmntvlwj001n5izsq422xfvi</loc>
    <lastmod>2023-09-17T19:06:03.034Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-RunCommandUEBABreach&amp;clmntv4ij001m5izs5xrk71tv</loc>
    <lastmod>2023-09-17T19:05:40.498Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-MalformedUserAgents&amp;clmntughk001l5izshracsulv</loc>
    <lastmod>2023-09-17T19:05:09.358Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AzureActivity-AzDiagSettingsDeleted&amp;clmnttpyw001k5izs5k5w68yh</loc>
    <lastmod>2023-09-17T19:04:34.992Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-UserStatechangedfromGuesttoMember&amp;clmntta8g001j5izs8r4r3rme</loc>
    <lastmod>2023-09-17T19:04:14.599Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-End-userconsentstoppedduetorisk-basedconsent&amp;clmntsaaw001i5izspn8hwobb</loc>
    <lastmod>2023-09-17T19:03:28.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-ChangestoApplicationOwnership&amp;clmntrp2n001h5izswnw5e8zb</loc>
    <lastmod>2023-09-17T19:03:00.519Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-ApplicationURIAdded&amp;clmntr5r4001g5izsd8xmm5kd</loc>
    <lastmod>2023-09-17T19:02:35.479Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20Azure%20AD%20device&amp;clmntqj0v001f5izs678chn1i</loc>
    <lastmod>2023-09-17T19:02:06.021Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ExternalData-Microsoft%20Graph%20permissions&amp;clmntpuj5001e5izsz40etuzg</loc>
    <lastmod>2023-09-17T19:01:34.280Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-PIM%20settings%20modified&amp;clmntpdsb001d5izsuwt2405q</loc>
    <lastmod>2023-09-17T19:01:12.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-PIM%20alert&amp;clmntoaio001b5izslberaeo1</loc>
    <lastmod>2023-09-17T19:00:21.695Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-PIM%20alert%20disabled&amp;clmntnzfq00195izsadrpnbdz</loc>
    <lastmod>2023-09-17T19:00:07.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20AD%20role%20assignment&amp;clmntnkne00185izskr948jvj</loc>
    <lastmod>2023-09-17T18:59:48.170Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Unexpected%20Conditional%20Access%20authentication%20without%20multifactor&amp;clmntmrlk00165izs5eez3069</loc>
    <lastmod>2023-09-17T18:59:10.512Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Unevaluated%20Conditional%20Access%20apps&amp;clmntm6s800145izsof4ko0ft</loc>
    <lastmod>2023-09-17T18:58:43.544Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Unapplied%20Conditional%20Access%20authentication&amp;clmntlvau00135izsy051pl17</loc>
    <lastmod>2023-09-17T18:58:28.654Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Legacy%20protocols%20used%20in%20Azure%20AD%20authentication&amp;clmntlaon00115izsbrevtizc</loc>
    <lastmod>2023-09-17T18:58:01.934Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unusual%20unsynchronized%20account%20authentication%20in%20AD%20FS&amp;clmntkqvc000z5izsms35u494</loc>
    <lastmod>2023-09-17T18:57:36.263Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Unexpected%20account%20using%20a%20PowerShell%20app%20in%20Azure%20AD&amp;clmntkc25000x5izskgadqkhb</loc>
    <lastmod>2023-09-17T18:57:17.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Slow%20password%20spray%20attack&amp;clmntjmnd000w5izsxho9d5jy</loc>
    <lastmod>2023-09-17T18:56:44.136Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Potential%20MFA%20request%20spam&amp;clmntix32000u5izsjyf2fchp</loc>
    <lastmod>2023-09-17T18:56:10.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Password%20spray%20attack%20-%20Compromised%20account&amp;clmnti2w6000t5izs8fpvt6yy</loc>
    <lastmod>2023-09-17T18:55:31.869Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Match%20ADFSSignInLogs%20unknown%20errors%20with%20IdentityLogonEvents%20events&amp;clmnthcqk000r5izsb0x6to2z</loc>
    <lastmod>2023-09-17T18:54:57.980Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Distinct%20accounts%20configured%20MFA%20with%20the%20same%20device&amp;clmntgr2t000p5izst34ygoqy</loc>
    <lastmod>2023-09-17T18:54:29.909Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Authentication%20method%20changes&amp;clmntg685000n5izs3wolfqil</loc>
    <lastmod>2023-09-17T18:54:02.876Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Activity%20with%20Entra%20ID%20break%20glass%20account&amp;clmntfq2h000l5izs56v8s7vp</loc>
    <lastmod>2023-09-17T18:53:41.936Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Account%20configured%20MFA%20with%20phone%20numbers%20from%20distinct%20countries&amp;clmntfa0c000j5izsjtx1j5sl</loc>
    <lastmod>2023-09-17T18:53:21.123Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Conditional%20Access%20configuration%20modified&amp;clmntes4l000h5izsysp6sbyk</loc>
    <lastmod>2023-09-17T18:52:57.948Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ADFSSignInLogs-Password%20spray%20attack%20against%20AD%20FS&amp;clmntedgl000g5izskzq093wm</loc>
    <lastmod>2023-09-17T18:52:38.949Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/ADFSSignInLogs-Password%20spray%20attack%20against%20AD%20FS%20-%20Private%20IP%20address%20anomaly&amp;clmntdoxy000e5izseexwrq6w</loc>
    <lastmod>2023-09-17T18:52:07.166Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADNonInteractiveUserSignInLogs-Password%20spray%20attack%20against%20Azure%20AD%20Seamless%20SSO&amp;clmntcyns000c5izs9vihv1y0</loc>
    <lastmod>2023-09-17T18:51:33.111Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Cross-tenant%20access%20settings%20modified&amp;clmntcies000a5izsrlqbmcbt</loc>
    <lastmod>2023-09-17T18:51:12.051Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-User%20reported%20suspicious%20activity&amp;clmntcf3900095izs0ah2layt</loc>
    <lastmod>2023-09-17T18:51:07.740Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20AD%20unusual%20operation&amp;clmntc3kn00085izsm843oet4</loc>
    <lastmod>2023-09-17T18:50:52.822Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Password%20Spray&amp;clmntbx7100075izsta8unp28</loc>
    <lastmod>2023-09-17T18:50:44.556Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20AD%20account%20created%20without%20AD%20synchronization&amp;clmntb61x00065izsfitqcxdt</loc>
    <lastmod>2023-09-17T18:50:09.372Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AuditLogs-Azure%20AD%20B2C%20settings%20modified&amp;clmntaugc00055izs1wkczkou</loc>
    <lastmod>2023-09-17T18:49:54.339Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SigninLogs-Risky%20AD%20FS%20sign-in%20event&amp;clmntaf8h00045izshehftyhn</loc>
    <lastmod>2023-09-17T18:49:34.617Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Password%20spray%20attack%20through%20Kerberos&amp;clmnt9vhj00035izsejlfo0s6</loc>
    <lastmod>2023-09-17T18:49:09.031Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Multiple-Azure%20AD%20threat%20intelligence&amp;clmnt99ll00025izszrq6m12j</loc>
    <lastmod>2023-09-17T18:48:40.656Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-IsWorkingTimeOld&amp;clmnt8gq200015izsf3kcu99y</loc>
    <lastmod>2023-09-17T18:48:03.241Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AuthenticationMethodChanges&amp;clmnt7ws200005izsebr7sjnv</loc>
    <lastmod>2023-09-17T18:47:37.392Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-Activity%20with%20monitored%20AWS%20role&amp;clmnt13d3000h5iisdqi0q7mk</loc>
    <lastmod>2023-09-17T18:42:19.334Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AADServicePrincipalRiskEvents-Service%20Principal%20at%20risk&amp;clmnt0zhy000g5iishepxo90v</loc>
    <lastmod>2023-09-17T18:42:14.317Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20IAM%20user%20created&amp;clmnt0f85000f5iiskuolk8w2</loc>
    <lastmod>2023-09-17T18:41:48.053Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-Activity%20with%20monitored%20AWS%20account%20root%20user&amp;clmnt0dcc000e5iisou37wgug</loc>
    <lastmod>2023-09-17T18:41:45.604Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/AWSCloudTrail-AWS%20admin%20emergency%20access%20token&amp;clmnszsh4000d5iisd84pncgp</loc>
    <lastmod>2023-09-17T18:41:18.567Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-ObjectName%20GUID%20%26%20sAMAccountName&amp;clmnsyyvg000b5iisbh96ju54</loc>
    <lastmod>2023-09-17T18:40:40.203Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Account%20removed%20from%20monitored%20AD%20group&amp;clmnsy8m400095iiszc3ni8sy</loc>
    <lastmod>2023-09-17T18:40:06.163Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/SecurityEvent-Account%20allowed%20to%20delegate%20to%20KRBTGT%20service&amp;clmnsxo5w00075iismlgpvx72</loc>
    <lastmod>2023-09-17T18:39:39.667Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-SubscriptionInventoryLogs&amp;clmnsxbin00055iisqq0bmwi3</loc>
    <lastmod>2023-09-17T18:39:23.278Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Parsing-CiscoUmbrellaLogs&amp;clmnsx27a00035iisz8mkg30w</loc>
    <lastmod>2023-09-17T18:39:11.197Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-IsWorkingTime&amp;clmnswk7k00025iisc6d0s2q8</loc>
    <lastmod>2023-09-17T18:38:47.887Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-PrivilegedIdentityInfo&amp;clmnsw6w800015iis9k40k86a</loc>
    <lastmod>2023-09-17T18:38:30.632Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AuditorGroupAlerts&amp;clmnsvs7c00005iisskjhciwh</loc>
    <lastmod>2023-09-17T18:38:11.591Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AuditorAlerts&amp;clmnst2j400025irsymev97la</loc>
    <lastmod>2023-09-17T18:36:04.999Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Analytics-AWSIdentityRole&amp;clmnssfib00005irs326iez5h</loc>
    <lastmod>2023-09-17T18:35:35.162Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-VisualizefailedDeviceDeployments&amp;clmnslls300325iu4jm8zr8nr</loc>
    <lastmod>2023-09-17T18:30:16.697Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-VisualizeEnrollmentStatistics&amp;clmnsl6is00305iu4dt9zbh9p</loc>
    <lastmod>2023-09-17T18:29:56.923Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-ShowIntuneEnrollmentNotSupportedDevices&amp;clmnskj2h002w5iu4b14opawx</loc>
    <lastmod>2023-09-17T18:29:26.529Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-OSBuildDuringAutopilot&amp;clmnsk8uv002u5iu43dwt8k15</loc>
    <lastmod>2023-09-17T18:29:13.302Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-NumberOfSuccessfulEnrollmentsbyOS&amp;clmnsjy20002s5iu4dnt9esrf</loc>
    <lastmod>2023-09-17T18:28:59.304Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-LatestDeviceEnrollments&amp;clmnsjnsj002q5iu4nzyec50m</loc>
    <lastmod>2023-09-17T18:28:45.994Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-EnrollmentTypes&amp;clmnsje2c002o5iu4akzc0vs7</loc>
    <lastmod>2023-09-17T18:28:33.396Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-ESPEnrollmentsWithProfileName&amp;clmnsj5yj002m5iu4yow0m15b</loc>
    <lastmod>2023-09-17T18:28:22.882Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-DidUserReachDesktop&amp;clmnsisc0002k5iu4f61paz5i</loc>
    <lastmod>2023-09-17T18:28:05.224Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Operational-AutopilotDuration&amp;clmnsiix1002i5iu48eus2nrb</loc>
    <lastmod>2023-09-17T18:27:53.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-iOSVersions&amp;clmnsi8sj002g5iu4zrq5x6yv</loc>
    <lastmod>2023-09-17T18:27:39.899Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizetheWindowsBuildNumbersandthenumberofDevices&amp;clmnshy7m002e5iu4fm0ekgd2</loc>
    <lastmod>2023-09-17T18:27:26.193Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeWindowsVersions&amp;clmnsho0n002c5iu46m5kol8z</loc>
    <lastmod>2023-09-17T18:27:12.982Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeWhenYourDevicesLastContactedIntune&amp;clmnshe44002a5iu40578ibru</loc>
    <lastmod>2023-09-17T18:27:00.139Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeTheJoinType&amp;clmnsgzr400285iu4et29agty</loc>
    <lastmod>2023-09-17T18:26:41.527Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeNumberofDeviceswithdifferentSKU&amp;clmnsgp6000265iu4mj2vrjja</loc>
    <lastmod>2023-09-17T18:26:27.815Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-VisualizeAndroidVersions&amp;clmnsggmc00245iu4u2df6x1x</loc>
    <lastmod>2023-09-17T18:26:16.739Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-UnsupportediOSVersions&amp;clmnsg7wr00225iu4ar397db6</loc>
    <lastmod>2023-09-17T18:26:05.442Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-UnsupportedAndroidVersions&amp;clmnsg14g00205iu4vhj8215e</loc>
    <lastmod>2023-09-17T18:25:56.655Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-SignIns&amp;clmnsft27001y5iu4am3qsvd5</loc>
    <lastmod>2023-09-17T18:25:46.198Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ShowiOSDeviceswithJailbreak&amp;clmnsfe0y001w5iu4voxin6or</loc>
    <lastmod>2023-09-17T18:25:26.721Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ShowallWindowsVersionsandNumberofDeviceswitheachVersion&amp;clmnsf68w001u5iu4b8bfkyph</loc>
    <lastmod>2023-09-17T18:25:16.631Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-NumberOfDevicesThatAreManagedByIntuneOrAreCoManaged&amp;clmnseuzx001s5iu45u691vm9</loc>
    <lastmod>2023-09-17T18:25:02.060Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-NumberOfDevicesAndManufacturers&amp;clmnsep8f001q5iu4phpkq04n</loc>
    <lastmod>2023-09-17T18:24:54.582Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ListofallDevicesthatwhereaddedtoIntunewithOSPlatforminformation&amp;clmnsejq4001o5iu48kz5rw27</loc>
    <lastmod>2023-09-17T18:24:47.451Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-ListofDevicesThatAreNotBitlockerEncrypted&amp;clmnsechz001m5iu4v5lay0t0</loc>
    <lastmod>2023-09-17T18:24:38.077Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-LastTimeTheDeviceWasActive&amp;clmnse6dc001k5iu4a0v3v7id</loc>
    <lastmod>2023-09-17T18:24:30.143Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-JoinTypes&amp;clmnsdx1g001i5iu4484q5tep</loc>
    <lastmod>2023-09-17T18:24:18.044Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-FreeStorage&amp;clmnsdmoy001g5iu4x8hj5xni</loc>
    <lastmod>2023-09-17T18:24:04.641Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-EndofLife&amp;clmnsdd72001e5iu4de7cql81</loc>
    <lastmod>2023-09-17T18:23:52.325Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DevicesWithoutPrimaryUser&amp;clmnscxou001c5iu4ald765tu</loc>
    <lastmod>2023-09-17T18:23:32.237Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DevicesRegisteredButNotManagedByIntune&amp;clmnscrwo001a5iu4yumackc6</loc>
    <lastmod>2023-09-17T18:23:24.744Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-DevicesAndPrimaryUser&amp;clmnscm4u00185iu4t8bsejnx</loc>
    <lastmod>2023-09-17T18:23:17.253Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-CountdownEndofLife21H1&amp;clmnscgt000165iu4uo05p52h</loc>
    <lastmod>2023-09-17T18:23:10.356Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device-CompareOSBuildTodayAndYesterday&amp;clmnsc77400145iu4w4kibvel</loc>
    <lastmod>2023-09-17T18:22:57.895Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20-%20Visualize%20device%20compliance&amp;clmnsbwom00125iu49s5jxox6</loc>
    <lastmod>2023-09-17T18:22:44.277Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Device%20-%20Translate%20OS%20Build%20to%20Version&amp;clmnsbnj300105iu49wi36rf0</loc>
    <lastmod>2023-09-17T18:22:32.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance-NumberofDeviceswithDeviceHealthThreatLevelStatus&amp;clmnsb9rv000y5iu4yfjkdo5i</loc>
    <lastmod>2023-09-17T18:22:14.578Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance-NumberOfCompanyOwnedDevicesThatAreCompliantOrNotCompliant&amp;clmnsaxxt000w5iu4alm3sekl</loc>
    <lastmod>2023-09-17T18:21:59.240Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance-NumberOfActiveDevicesInTheLast7And30Days&amp;clmnsaiv4000u5iu41asbjhgt</loc>
    <lastmod>2023-09-17T18:21:39.703Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance-NumberAndListOfCompanyOwnedDevicesWithComplianceStatus&amp;clmnsa650000s5iu46cdehtu9</loc>
    <lastmod>2023-09-17T18:21:23.211Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance-NotcompliantDevices&amp;clmns9vbx000q5iu466svpbl0</loc>
    <lastmod>2023-09-17T18:21:09.212Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Compliance%20-%20List%20of%20Devices%20that%20have%20DeviceHealthThreatLevel%20Status%20of%20Secured&amp;clmns9mw7000o5iu4gmau55g0</loc>
    <lastmod>2023-09-17T18:20:58.270Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-WipedDevices&amp;clmns97k7000k5iu4nxr6ilhi</loc>
    <lastmod>2023-09-17T18:20:38.406Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowWhatActionstookplacefromwhichAppOrUser&amp;clmns8xk5000i5iu40pygh143</loc>
    <lastmod>2023-09-17T18:20:25.437Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowRemoteLockedDevices&amp;clmns8nye000g5iu46crnewok</loc>
    <lastmod>2023-09-17T18:20:12.998Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowLocatedDevices&amp;clmns8h5m000e5iu4pr2r50l9</loc>
    <lastmod>2023-09-17T18:20:04.176Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowFeatureUpdatePolicies&amp;clmns84v5000c5iu44t3n6dif</loc>
    <lastmod>2023-09-17T18:19:48.248Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowEnableLostModeDevices&amp;clmns7x9k000a5iu4bzf2ra39</loc>
    <lastmod>2023-09-17T18:19:38.408Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowDeletedDevices&amp;clmns7nn500085iu4h2j18kr3</loc>
    <lastmod>2023-09-17T18:19:25.928Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ShowClientCertificates&amp;clmns79u500065iu4axdf0nhl</loc>
    <lastmod>2023-09-17T18:19:08.036Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-DeletedDevices&amp;clmns6wya00045iu4asdzvnjw</loc>
    <lastmod>2023-09-17T18:18:51.345Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit-ChangesinConfigurationProfiles&amp;clmns6mss00025iu4l96azyxe</loc>
    <lastmod>2023-09-17T18:18:38.178Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Audit%20-%20Show%20OperationName%20and%20OperationCount&amp;clmns6c9p00015iu4zow5kui3</loc>
    <lastmod>2023-09-17T18:18:24.540Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDR-MITRE-ATTCK-pivot&amp;clmer6tsv000u5iqwduh2g9s5</loc>
    <lastmod>2023-09-11T10:40:52.062Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDR-DetectionPercentage-SecurityProducts&amp;clmer6jux000t5iqw40awewqe</loc>
    <lastmod>2023-09-11T10:40:39.168Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/XDR-AlertReports&amp;clmer6efj000s5iqw1fv0g4lh</loc>
    <lastmod>2023-09-11T10:40:32.142Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Identity-AzureAD-User-RiskCheck&amp;clmer651c000r5iqw8f4qkd7c</loc>
    <lastmod>2023-09-11T10:40:19.959Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-visualizing-ASRrule-detections&amp;clmer5w5e000q5iqwm2dpf550</loc>
    <lastmod>2023-09-11T10:40:08.450Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-WebProtection&amp;clmer5qn0000p5iqwlfukk0iu</loc>
    <lastmod>2023-09-11T10:40:01.299Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TamperProtection&amp;clmer5jiy000o5iqwwaslscx0</loc>
    <lastmod>2023-09-11T10:39:52.089Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-TP-TSmode-AVversions-list&amp;clmer5ays000n5iqwrgobytd6</loc>
    <lastmod>2023-09-11T10:39:40.987Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/MDE-ControlledFolderAccess&amp;clmer54ts000m5iqwysk73mz7</loc>
    <lastmod>2023-09-11T10:39:33.040Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-WDigest-CredentialAccess&amp;clmer4wbq000l5iqwezrdaysd</loc>
    <lastmod>2023-09-11T10:39:22.014Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-UserAccountCreated&amp;clmer4nh7000k5iqw7hnfpixf</loc>
    <lastmod>2023-09-11T10:39:10.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-UrlHunting-EmailToDevice&amp;clmer4gi4000j5iqwzhcejiu6</loc>
    <lastmod>2023-09-11T10:39:01.507Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-Tracking-Mimikatz-CommandLine&amp;clmer49tj000i5iqwoc5tpnrn</loc>
    <lastmod>2023-09-11T10:38:52.854Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-PsExecHunting-LMP&amp;clmer43od000h5iqwvn837g7x</loc>
    <lastmod>2023-09-11T10:38:44.884Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-NetExeListing-Reconnaissance&amp;clmer3tkq000g5iqwdc5vlot2</loc>
    <lastmod>2023-09-11T10:38:31.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-Monitoring-Persistence&amp;clmer3mkf000f5iqw8g46kk9s</loc>
    <lastmod>2023-09-11T10:38:22.710Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-MITRE-ATTCK-Report&amp;clmer3e2p000e5iqw7hh1ezhb</loc>
    <lastmod>2023-09-11T10:38:11.713Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-ListForSuspiciousFiles-Device&amp;clmer379q000d5iqwvhmzszuc</loc>
    <lastmod>2023-09-11T10:38:02.885Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-InstalledApps-Windows&amp;clmer305e000c5iqwmw3aevsr</loc>
    <lastmod>2023-09-11T10:37:53.665Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Endpoint-ImpacketWmi-LMP&amp;clmer2t4j000b5iqwo2ym52fe</loc>
    <lastmod>2023-09-11T10:37:44.554Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderAntivirus-scan-report&amp;clmer2kef000a5iqw8w0kyisu</loc>
    <lastmod>2023-09-11T10:37:33.254Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/DefenderAntivirus-malware-detection-list&amp;clmer2etx00095iqwcitf5352</loc>
    <lastmod>2023-09-11T10:37:26.028Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-ThreatHunting-URL&amp;clmer26on00085iqwpj8h2vke</loc>
    <lastmod>2023-09-11T10:37:15.478Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-Threat-Reports&amp;clmer1zvf00075iqwn5b4c3tk</loc>
    <lastmod>2023-09-11T10:37:06.642Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-MalwareDetection-List&amp;clmer1ufb00065iqw74hfrkm8</loc>
    <lastmod>2023-09-11T10:36:59.590Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-MDO-UserList-for-RemediationAction&amp;clmer1mx900055iqwshq2w55m</loc>
    <lastmod>2023-09-11T10:36:49.860Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-MDO-Phishing-detection&amp;clmer1czx00045iqwaaiep3jc</loc>
    <lastmod>2023-09-11T10:36:37.004Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-MDO-Malware-detection&amp;clmer133p00035iqwkavvtb2c</loc>
    <lastmod>2023-09-11T10:36:24.172Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-MDO-Detection-DailyPercentage&amp;clmer0vl600025iqwa833uf10</loc>
    <lastmod>2023-09-11T10:36:14.441Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-EOP-Phishing-detection&amp;clmer0oxf00015iqwco4jcun7</loc>
    <lastmod>2023-09-11T10:36:05.801Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-EOP-Malware-detection&amp;clmer0fwn00005iqw5qs5rve1</loc>
    <lastmod>2023-09-11T10:35:54.117Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-EOP-Detection-DailyPercentage&amp;clmeqr53l00015i4ghqche3nz</loc>
    <lastmod>2023-09-11T10:28:40.200Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
  <url>
    <loc>https://kqlsearch.com/query/Email-Audit-SafeAttachments-GlobalSetting&amp;clmeqqwzh00005i4giwdouwmy</loc>
    <lastmod>2023-09-11T10:28:29.692Z</lastmod>
    <changefreq>weekly</changefreq>
    <priority>0.6</priority>
  </url>
</urlset>