Skip to content

dstreefkerk/kql

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

33 Commits
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

KQL Query Collection

This repository contains various Sentinel/Log Analytics KQL queries that I’ve created for different tasks and projects. More will be added as and when I create them.

Overview

  • SentinelHealth - Queries for monitoring Sentinel health. For example, data connectors.
  • SigninLogs - Queries for investigating sign-in activity using the SigninLogs table. Useful for detecting suspicious logins, failed attempts, and geographic anomalies, etc.

AI/LLM Summary

If you'd prefer to pass all of the queries in this repo to a LLM or AI tool like Claude or ChatGPT, you can download the repository_context.md file. It's an auto-generated merged representation of all of the KQL queries within this repo.

About

Sentinel KQL queries that I've developed over time

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

 
 
 

Contributors