Azure-Sentinel/Hunting Queries
dicolanl d92adfd80b Update O365 Playbook for teams 2020-05-15 23:30:51 +00:00
..
AWSCloudTrail PR review fixes 2020-05-01 16:09:07 -07:00
AuditLogs Documentation links should not include locale - fix and add validations (#678) 2020-05-13 15:07:12 +03:00
AzureActivity Rare Custom Script Extension 2020-04-11 18:44:28 -07:00
AzureDiagnostics Adding sysmon separate parser files 2019-12-09 13:14:51 -08:00
CustomLogs removed spaces and corrected connector 2019-12-17 14:10:51 -08:00
DnsEvents Makelist Update 2019-11-25 12:59:33 +00:00
MultipleDataSources Documentation links should not include locale - fix and add validations (#678) 2020-05-13 15:07:12 +03:00
OfficeActivity Merge pull request #649 from duzlov/master 2020-05-14 08:33:54 -07:00
SecurityAlert adding in some other entities 2019-09-04 09:10:05 -07:00
SecurityEvent Documentation links should not include locale - fix and add validations (#678) 2020-05-13 15:07:12 +03:00
SigninLogs Login attempt by Blocked MFA user 2020-04-06 04:39:03 -07:00
Syslog Small bug fix for when auditd is installed 2020-04-17 14:05:36 +00:00
TeamsLogs Update O365 Playbook for teams 2020-05-15 23:30:51 +00:00
ThreatIntelligenceIndicator Updating to include URLCustomEntity where available. 2019-12-23 10:38:26 -08:00
W3CIISLog Changing GUIDs of hunting queries that had duplicates from Detection queries 2020-04-13 10:52:12 -07:00
WireData Changing GUIDs of hunting queries that had duplicates from Detection queries 2020-04-13 10:52:12 -07:00
ZoomLogs formatting 2020-04-27 14:17:04 -07:00
QUERY_TEMPLATE.md pushing initial version of PrivAccountTracking and some minor fixes 2019-03-29 12:36:39 -07:00
readme.md update links in readme for Hunting queries 2019-11-25 13:25:24 -08:00

readme.md

About

  • This repo contains sample queries for Hunting to aid in the development of techniques for threat hunting leveraging logs from multiple sources.
  • With these sample queries, you can get a headstart in learning the Kusto Query Language (KQL) and understanding the different data sources.
  • To get started, simply paste a sample query into the user interface and run the query.

Resources

Contributing

  • The more queries and tools we add to the community the more effective we will be.
  • Utilize the QUERY_TEMPLATE format for Pull requests.

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com