BertJanCyber Profile picture
Dec 19 • 14 tweets • 9 min read
In the last months, I have collected some awesome new #KQL sources, and this 🧵lists them.
Are you using Defender For Endpoint, Sentinel, Intune or do you want to learn KQL then have a look!
#MDE #Sentinel #Intune #Detection #ThreatHunting
Type: Query
By: @msftsecurity
Link: github.com/Azure/Azure-Se…
Community-based repository for a lot of available data sources in Sentinel. For the E5 detections take a look in the Microsoft 365 Defender Folder.
Type: Query
By: @reprise_99
Link: github.com/reprise99/Sent…
Repository with 100s of KQL queries you can directly use. They are categorized into different Microsoft product categories. You are guaranteed to find useful queries here.
Type: Query
By: @falconforceteam
Link: github.com/FalconForceTea…
This repository contains very good detections and hunting queries that look for malicious behaviour that does not trigger a default alert. The queries can be complex, but a clear explanation is provided.
Type: Query
By: @rodtrent
Link: github.com/rod-trent/Sent…
Repository with all kinds of detections, also including queries for non-Microsoft products.
Type: Query
By: @alexverboon
Link: github.com/alexverboon/MD…
This repo contains some great advanced hunting queries. Additionally, it also contains a lot of information additional information about KQL.
Type: Query
By: @BertJanCyber
Link: github.com/Bert-JanP/Hunt…
KQL detections & hunting queries for all Microsoft Security Products. Roughly 150 queries are added. MITRE ATT&CK mapping has also been implemented where applicable.
Type: Query
By: @UgurKocDe
Link: github.com/ugurkocde/KQL_…
KQL can be used in a variety of places and if you use Intune, this repository is worth checking out! If you send Intune data to Sentinel you can also use the queries in Sentinel.
Type: Query
By: @cylaris_rg
Link: github.com/cylaris/awesom…
This repository contains KQL queries based on research performed by Cylaris Threat Research Group (TRG).
Type: Query
By: @Thomas_Live
Link: github.com/Cloud-Architek…
A repository with mostly Azure Active Directory based kql queries.
Type: Learning
By: @rodtrent
Link: github.com/rod-trent/Must…
If you want to get started with KQL this is your place to be! It contains a guide on how to get started with practical examples.
Type: Learning
By: @reprise_99
Link: github.com/reprise99/awes…
The readme says it all: "A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel"
Type: Learning
By: @roy_samik
Link: youtube.com/@samikroy/vide…
This is a very recent addition to the list of sources. This channel contains videos with explanations of how to use the basic KQL functionalities.
Type: Learning
By: @KqlCafe
Link: kqlcafe.github.io/website/
The KQL is a monthly event virtual cafe where @alexverboon & @castello_johnny share KQL knowledge with all of you. If you are interested you can watch sessions from most of the KQL developers mentioned in this thread!

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with BertJanCyber

BertJanCyber Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @BertJanCyber

Jun 27
Are you using any of the Microsoft Security products and/or #Sentinel? Then this thread is for you! The best resources for #KQL Advanced Hunting Queries or Analytics rules in my opinion.
#MDE #ThreatHunting #Detection #DFIR
github.com/reprise99/Sent… by @reprise_99. Awsome source! With the #365daysofkql series a lot of useful queries have been added. The queries are categorized by the different Microsoft products.
github.com/Azure/Azure-Se… by @msftsecurity. A lot of KQL queries can be found here, all of which are categorised on the basis of @MITREattack tactics.
Read 8 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(