Skip to content
#

ms365

Here are 20 public repositories matching this topic...

A curated collection of Cloud DFIR and threat‑hunting resources focused on Microsoft Sentinel, Defender XDR, Azure, and Microsoft 365. Includes KQL hunting queries, Sentinel workbook JSONs, notebook configurations, SOAR automations, and practical detection engineering artifacts for real‑world investigations and SOC operations.

  • Updated Jan 30, 2026

Improve this page

Add a description, image, and links to the ms365 topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the ms365 topic, visit your repo's landing page and select "manage topics."

Learn more