End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
-
Updated
Jul 29, 2026
End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
Awesome Kusto Query Language (KQL)
SOC Phishing Email Investigation & Automated Response using Microsoft Sentinel, KQL, MITRE ATT&CK and SOAR
Data Analyst
Information Security Analyst
Application of the HITS Threat Hunting Framework incorporating agentic AI for delivery across Sentinel, Defender and the wider Microsoft ecosystem
Add a description, image, and links to the kql-microsoft-sentinel topic page so that developers can more easily learn about it.
To associate your repository with the kql-microsoft-sentinel topic, visit your repo's landing page and select "manage topics."