This is your work, valued
threathunting-spl. Splunk code (SPL) for serious threat hunters and detection engineers.
294spl-to-kql. The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects requiring both technologies (Splunk and Azure/Sentinel) or any other hybrid environments. Feel free to add/suggest entries.
45drape. Detection Reliability And Precision Efficiency (DRAPE) is an index used to assess detection performance
35Hunting-Queries-Detection-Rules. KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.
5KQL-threat-hunting-queries. A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
2