+
Skip to content
View ep3p's full-sized avatar

Block or report ep3p

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don't include any personal information such as legal names or email addresses. Markdown supported. This note will be visible to only you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
Showing results

some KQL Queries for Advanced Hunting

PowerShell 20 1 Updated Oct 15, 2025

Advanced Wazuh Rules for more accurate threat detection. Feel free to implement within your own Wazuh environment, contribute, or fork!

Python 1,115 263 Updated Sep 30, 2025

KQLIntel is a browser-based tool that uses LLMs to convert threat intelligence reports into actionable Kusto Query Language (KQL) queries by extracting IOCs from URLs or raw text.

JavaScript 25 2 Updated Aug 4, 2025

Best known optimizations for the game Opus Magnum.

2 Updated Jul 17, 2022

KQL Sentinel and Defender Detection and Hunting Queries.

13 Updated Sep 10, 2025

KQL Queries

21 1 Updated Oct 3, 2025

This repository provides a complete solution for deploying and configuring an Azure Data Explorer (ADX) cluster designed specifically for security log centralisation, aligned with Microsoft's Advan…

Bicep 2 Updated Mar 22, 2025

sKaleQL is an opinionated template repository for managing, executing, and organizing Kusto Query Language (KQL) queries against Azure Log Analytics Workspaces.

19 1 Updated May 20, 2025

A list of Free Software network services and web applications which can be hosted on your own servers

252,834 11,718 Updated Oct 15, 2025

Public repository focused on Microsoft Sentinel, for sharing queries, detections, and other content that may be useful to someone.

3 Updated Mar 17, 2025
Python 745 109 Updated May 7, 2025

Advanced Threat Hunting: Ransomware Group

29 Updated Jul 9, 2025

Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)

PowerShell 76 4 Updated Sep 24, 2025

Online resources related to Detection Engineering. Detection rules, detection logic, attack samples, detection tests and emulation tools, logging configuration and best practices, event log refere…

HTML 120 16 Updated Sep 5, 2025

Conditional Access Reporting

PowerShell 27 1 Updated Apr 4, 2025

A collection of KQL queries for running security monitoring in Microsoft Azure using Azure Sentinel and 365 Defender Advanced Hunting.

5 Updated May 24, 2024

Collection of defensive KQL queries

9 Updated May 7, 2025

Azure Sentinel, geniş ölçekte tehditleri tespit etmek, izlemek, analiz etmek ve önlem almak için kullanılır. Hem Azure hizmetlerinden gelen verileri hem de çeşitli üçüncü taraf sistemlerden ve ciha…

24 Updated Oct 21, 2024

The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior

58 2 Updated Oct 6, 2025

Azure administrative tiering based on known attack paths

121 13 Updated Oct 16, 2025

Collection of scripts, will try keep them in order 😁

7 Updated Aug 4, 2025

Initial Access and Post-Exploitation Tool for AAD and O365 with a browser-based GUI

HTML 847 95 Updated May 10, 2025

Detection rules and threat hunting queries in Defender XDR and Azure Sentinel

14 Updated Oct 10, 2025

KQL Queries for Azure Sentinel

3 2 Updated Aug 13, 2021

A collection of PowerShell scripts for analyzing data from Microsoft 365 and Microsoft Entra ID

PowerShell 539 60 Updated Sep 18, 2025

Microsoft Logic Apps flows

Bicep 56 39 Updated May 16, 2025

A series of cloud focused KQL queries for threat hunting and DFIR

10 Updated May 24, 2025
Next
点击 这是indexloc提供的php浏览器服务,不要输入任何密码和下载