A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Jun 3, 2026
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
A framework for converting natural language text inputs to corresponding Pandas, MongoDB, Kusto and Neo4j (Cypher) queries.
sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Log Analytics Workspaces.
A series of cloud focused KQL queries for threat hunting and DFIR
A technical blog about Kusto
PowerShell-based Microsoft security investigation and defensive gap assessment framework focused on Microsoft XDR, Entra ID, KQL pivots, analyst workflow, and executive exposure reporting.
Microsoft Technical Essentials Workshop is a technical training program to empower veterans. Supported by LA County WDACS; LAVTTA; Microsoft Learning; LA Mayor; Fast Lane; JVS SoCal; and more.
KQL queries for monitor log analytics
A comprehensive collection of Kusto Query Language (KQL) scripts and tools for simplified log analysis and troubleshooting in Azure and DevOps environments.
Cloud security labs: DFIR, detection engineering, and SecOps across Azure Sentinel, AWS GuardDuty, and Entra ID
A practical guide for running daily health checks in Microsoft Defender for Office 365 to maintain security posture and ensure protection effectiveness.
🌿 Microsoft Fabric E2E Tutorial: 🌊Lakehouse | 💙Data Science | ⚡Real-Time Intelligence | 🪣Data warehouse
Comprehensive KQL query reference for Microsoft Defender XDR and Azure Sentinel, optimized for Context7 integration
Scenario-driven hands-on KQL practice and investigation query notes actively updated. Current Rank 180 out of 150K people globally
This project focused on leveraging Azure Log Analytics to monitor cloud function execution, detect errors, and improve operational visibility. I configured Log Analytics to centralize logs from multiple Azure resources, then wrote Kusto Query Language (KQL) queries to filter execution logs, track error rates, and identify anomalies.
Hands-on Azure Monitor + Log Analytics support lab featuring AMA/DCR, KQL, alerts, Windows telemetry, incident investigation, remediation, and recovery validation.
Vim filetype detection and syntax highlighting for Kusto Query Language (KQL)
Powershell scripts repo
To associate your repository with the kusto-query-language topic, visit your repo's landing page and select "manage topics."