Azure-Sentinel/Hunting Queries/Microsoft 365 Defender/General queries
..
Alert Events from Internal IP Address.yaml
AppLocker Policy Design Assistant.yaml
Baseline Comparison.yaml
Crashing Applications.yaml
Detect Azure RemoteIP.yaml
Device Count by DNS Suffix.yaml
Device uptime calculation.yaml
Endpoint Agent Health Status Report.yaml
Endpoint Linux AV Signature and Platform Versions
Endpoint Linux Agent Health Status Report
Events surrounding alert (1).yaml
Events surrounding alert (2).yaml
Events surrounding alert (3).yaml
Events surrounding alert.yaml
Failed Logon Attempt.yaml
File footprint (1).yaml
File footprint.yaml
Firewall Policy Design Assistant.yaml
Linux Agent Age Report.yaml
MD AV Signature and Platform Version.yaml
MITRE - Suspicious Events.yaml
Machine info from IP address (1).yaml
Machine info from IP address (2).yaml
Machine info from IP address (3).yaml
Machine info from IP address.yaml
Network footprint (1).yaml
Network footprint (2).yaml
Network footprint (3).yaml
Network footprint.yaml
Network info of machine.yaml
Phish and Malware received by user vs total amount of email.yaml
Services.yaml
System Guard Security Level Baseline.yaml
System Guard Security Level Drop.yaml
Web Content Filtering Events.yml
insider-threat-detection-queries (1).yaml
insider-threat-detection-queries (2).yaml
insider-threat-detection-queries (3).yaml
insider-threat-detection-queries (4).yaml
insider-threat-detection-queries (5).yaml
insider-threat-detection-queries (6).yaml
insider-threat-detection-queries (7).yaml
insider-threat-detection-queries (8).yaml
insider-threat-detection-queries (9).yaml
insider-threat-detection-queries (10).yaml
insider-threat-detection-queries (11).yaml
insider-threat-detection-queries (12).yaml
insider-threat-detection-queries (13).yaml
insider-threat-detection-queries (14).yaml
insider-threat-detection-queries (15).yaml
insider-threat-detection-queries (16).yaml
insider-threat-detection-queries (17).yaml
insider-threat-detection-queries (18).yaml
insider-threat-detection-queries (19).yaml
insider-threat-detection-queries.yaml
wifikeys.yaml