A grab-and-go set of queries for everyday defensive hunting.
- Fast triage and hunting queries
- Reusable patterns for common investigations
- Focused on Microsoft Sentinel, Defender, and UAL-style telemetry
- Easy to tweak for your tenant, entity, or time window
Queries for suspicious sign-ins, admin changes, impossible travel, and account activity pivots.
Queries for phishing, malicious mail access, inbox abuse, and suspicious URL or attachment activity.
Queries for malware execution, persistence, remote tools, suspicious scripts, and host reconnaissance.
Queries for botnet activity, Nmap-style scanning, brute force patterns, and unusual remote connections.
Queries for tampering, realtime protection changes, AV exclusions, firewall bypass, and other control-disabling behavior.
- Root
.kqlfiles cover the main hunts and detections parser/contains UAL parsing helpers
Open a query, swap in your entity or IP, adjust the time window, and run it in your hunting workspace.
