🔎 KQL Threat Hunt Library
Microsoft Sentinel KQL Hunting Queries
Ready-to-run threat hunting queries for proactive investigation in Microsoft Sentinel. Mapped to MITRE ATT&CK and CERT-In incident categories.
35
Hunt Queries
7
Categories
12
MITRE Tactics
100%
KQL Native
How to use: These queries run natively in Microsoft Sentinel > Logs or the Microsoft Defender XDR Advanced Hunting console. Adjust table names to match your workspace (e.g.
SigninLogs vs AADSignInEventsBeta), set your time range, and substitute placeholder values (domain names, admin accounts, IP ranges) with your environment-specific values before running.
Showing 0 of 35 hunting queries