Jump to: 🔥 Challenge News ⚡ Intel 🔬 Research Labs 📡 All News →
🔎 KQL Threat Hunt Library

Microsoft Sentinel KQL Hunting Queries

Ready-to-run threat hunting queries for proactive investigation in Microsoft Sentinel. Mapped to MITRE ATT&CK and CERT-In incident categories.

35
Hunt Queries
7
Categories
12
MITRE Tactics
100%
KQL Native
How to use: These queries run natively in Microsoft Sentinel > Logs or the Microsoft Defender XDR Advanced Hunting console. Adjust table names to match your workspace (e.g. SigninLogs vs AADSignInEventsBeta), set your time range, and substitute placeholder values (domain names, admin accounts, IP ranges) with your environment-specific values before running.
Showing 0 of 35 hunting queries