Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
-
Updated
Jun 2, 2026 - PowerShell
Production-ready KQL queries for Microsoft Defender XDR and Microsoft Sentinel. Focused on Threat Hunting, Detection Engineering, and MITRE ATT&CK mapping.
Microsoft Entra ID Security Assessment Tool
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
🛡️ Scripts and articles about Microsoft Defender M365
Add a description, image, and links to the m365-defender topic page so that developers can more easily learn about it.
To associate your repository with the m365-defender topic, visit your repo's landing page and select "manage topics."