Skip to content

A comprehensive reference for detection engineers and threat hunters working with Microsoft Sentinel and M365 Defender. This repo combines field guide material (style, optimization, pivoting) with a curated Hunter’s Toolbox of queries, detections, and dashboards.

License

Notifications You must be signed in to change notification settings

juansasoc/KQL-Field-Guide

Repository files navigation

KQL Field Guide

Status MIT License Platform

🔍 KQL Field Guide

A comprehensive reference for detection engineers and threat hunters working with Microsoft Sentinel and M365 Defender. This repo combines field guide material (style, optimization, pivoting) with a curated Hunter’s Toolbox of queries, detections, and dashboards.

flowchart TD
  A[README.md] --> B[FieldGuide]
  A --> C[HuntersToolbox]
  A --> D[Detections]
  A --> E[Dashboards]
  A --> F[Watchlists]
  A --> G[References]
  C --> C1[2025 Threat Playbook]
  C --> C2[Persistence_LOLBAS]
  D --> D1[Persistence Rules]
  D --> D2[Identity & Cloud]
Loading

📖 Field Guide (Best Practices)


🔧 Hunter’s Toolbox

Hunter's Toolbox

2025 Threat Playbook

Persistence & LOLBAS


📊 Dashboards


⚡ Detections

Persistence Rules

Identity & Cloud


📂 Watchlists


📚 References

  • Microsoft Sentinel Documentation
  • M365 Defender Advanced Hunting Schema
  • MITRE ATT&CK Matrix
  • Kusto Detective Agency

🤝 Contributing

  • Fork → branch → PR
  • Add queries with:
    • let params for time/thresholds
    • Clear comments (intent, schema, expected output)
    • Performance notes & FP tuning guidance

📜 License

MIT

About

A comprehensive reference for detection engineers and threat hunters working with Microsoft Sentinel and M365 Defender. This repo combines field guide material (style, optimization, pivoting) with a curated Hunter’s Toolbox of queries, detections, and dashboards.

Resources

License

Contributing

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published