Skip to content
#

microsoft-sentinel

Here are 360 public repositories matching this topic...

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

  • Updated Jun 3, 2026

32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more

  • Updated Aug 1, 2026

Improve this page

Add a description, image, and links to the microsoft-sentinel topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the microsoft-sentinel topic, visit your repo's landing page and select "manage topics."

Learn more