This is your work, valued
Cyber Security Specialist | Blue Team | KQL | Sentinel | XDR
Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
1.7kOpen-Source-Threat-Intel-Feeds. This repository contains Open Source freely usable Threat Intel feeds that can be used without additional requirements. Contains multiple types such as IP, URL, CVE and Hash.
867Incident-Response-Powershell. PowerShell Digital Forensics & Incident Response Scripts.
804KustoHawk. KustoHawk is a lightweight incident triage and response tool designed for effective incident response in Microsoft Defender XDR and Microsoft Sentinel environments.
157Sentinel-Automation. Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.
122SecScripts. Security Scripts and Sources for daily usage.
76Domain-Response. Domain Response is a tool that is designed to help you automate the investigation for a domain. This tool is specificly designed to automated phishing domain investigations. However it can be used for every domain to gather all domain information needed. This can help to classify if a domain is malicious.
53Sentinel-Queries. Collection of KQL queries
6AzSentinelQueries. Repository with Sentinel Analytics Rules and Hunting Queries
5Presentations.
4awesome-kql-sentinel. A curated list of blogs, videos, tutorials, queries and anything else valuable to help you learn and master KQL and Microsoft Sentinel
4awesome-detection-rules. This is a collection of threat detection rules / rules engines that I have come across.
4Azure-Sentinel. Cloud-native SIEM for intelligent security analytics for your entire enterprise.
4MDE-DFIR-Resources. A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
3KustoCon2025. Workshop notes KustoCon 2025
3Hunting-Queries-Detection-Rules-1. KQL Queries. Microsoft Defender, Microsoft Sentinel
2ms-sentinel-scout. HTML
1Sigma-AWS. This repository contains the research and components of our research into using Sigma for AWS Incident Response.
1Invictus-training. Repository with supporting materials for Invictus Academy/Training
1aws_dataset. A dataset with CloudTrail events from an attack simulation using Stratus.
1ALFA. ALFA stands for Automated Audit Log Forensic Analysis for Google Workspace. You can use this tool to acquire all Google Workspace audit logs and to perform automated forensic analysis on the audit logs using statistics and the MITRE ATT&CK Cloud Framework
1kql_queries. KQL queries for Incident Response
1