A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
- 
            Updated
            
Aug 28, 2025  
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
KQL-Queries 🐙 provides ready KQL scripts for Microsoft Defender XDR threat hunting, helping security teams detect, investigate, and respond to threats.
🔍 Discover KQL queries designed for Microsoft Sentinel and Defender XDR to enhance your security monitoring and incident response capabilities.
Add a description, image, and links to the microsoft-365-defender topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-365-defender topic, visit your repo's landing page and select "manage topics."