KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Submit query
Device Query
CVE 2024 43452 Po C Detection
DeviceTvmSoftwareVulnerabilities
DeviceFileEvents
DeviceFileCertificateInfo
DeviceEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
January 7th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2024 49113 LDAP Nightmare
DeviceNetworkEvents
Author:
Bert-Jan Pals
Released:
January 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Resource Lock Deletion For Azure Monitor Rule
AzureActivity
Author:
Jay Kerai
Released:
January 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Machine Onboarded
AzureActivity
Author:
Bert-Jan Pals
Released:
January 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
LDAP Nightmare POC Detection
DnsEvents
Author:
Steven Lim
Released:
January 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Log Analytic Workspace Deletions
AzureActivity
Author:
Jay Kerai
Released:
January 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sentinel Incident Deletions
AzureActivity
Author:
Jay Kerai
Released:
January 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Monitor Rule Disabled
AzureActivity
Author:
Jay Kerai
Released:
January 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Bring Your Own Minifilter EDR Bypass
DeviceProcessEvents
DeviceRegistryEvents
Author:
Jay Kerai
Released:
December 31th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Living Off The Tunnels IOCS
DeviceNetworkEvents
Author:
Jay Kerai
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Security Event AD Unusual Operation
SecurityEvent
Author:
Jose Sebastián Canós
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Malicious Chrome Extension
DeviceFileEvents
Author:
Steven Lim
Released:
December 30th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Custom Detection Disabled
CloudAppEvents
Author:
Bert-Jan Pals
Released:
December 28th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
CVE 2024 3393 DDOS Detection
CommonSecurityLog
Author:
Steven Lim
Released:
December 27th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Malicious Senders Hidden Behind Anonymous Proxies
CloudAppEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Rating IS Ps To Detect Potential Malicious Domains Sending Threats
EmailEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detection Of OOF Message Delivered Externally
EmailEvents
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Spoofed Email Cases
EmailEvents
IdentityInfo
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
September Updates
DeviceTvmSoftwareVulnerabilities
DeviceTvmSoftwareVulnerabilitiesKB
Author:
Sergio Albea
Released:
December 26th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Anonymized Microsoft Graph Activity Logs
MicrosoftGraphActivityLogs
Author:
Bert-Jan Pals
Released:
December 23th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Monitor Exclusion Into Conditional Access Policies
AADSignInEventsBeta
Author:
Sergio Albea
Released:
December 23th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
TI Feed Tor Connections
DeviceNetworkEvents
Author:
Bert-Jan Pals
Released:
December 21th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Advanced Vishing KQL Detection
TeamsCallLog
Author:
Steven Lim
Released:
December 19th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Url Haus Abusech Hits In Microsoft Teams
CloudAppEvents
Author:
Sergio Albea
Released:
December 18th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Power Shell Self Pwn
IdentityInfo
DeviceEvents
DeviceProcessEvents
Author:
Steven Lim
Released:
December 17th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Ransomware Tool Matrix Defender Lookup
DeviceProcessEvents
Author:
Jay Kerai
Released:
December 16th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting For Registry Artifacts Of Service Creation
DeviceRegistryEvents
Author:
Sergio Albea
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting For Process Command Line Artifacts Of Service Creation
DeviceProcessEvents
Author:
Sergio Albea
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Old BIOS Versions
BiosInfo
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Top Disk IO Processes
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Flag Processes With Disproportionately Large Virtual Memory Usage
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Programs Set To Auto Run At Startup
WindowsRegistry
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Check If TPM 20 Is Available
Tpm
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Find Processes With Unusually High Thread Or Handle Counts
Process
Author:
Ugur Koc
Released:
December 13rd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Microsoft Graph Activity Logs Missing Logs
MicrosoftGraphActivityLogs
Author:
Jose Sebastián Canós
Released:
December 12nd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Docu Shield NRT Anti Impersonation Email Purge
EmailEvents
Author:
Steven Lim
Released:
December 12nd, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detecting Teams Red Team Tool Convo C2
CloudAppEvents
Author:
Steven Lim
Released:
December 11st, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Zloader DNS Tunneling
DeviceNetworkEvents
Author:
Steven Lim
Released:
December 11st, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Url Haus Abusech Hits In Microsoft Teams
CloudAppEvents
Author:
Sergio Albea
Released:
December 10th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Monitoring M Teams Activities Such As Shared UR Ls One To One Chats And Domains Participating Into Meetings
CloudAppEvents
Author:
Sergio Albea
Released:
December 10th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Enhanced Cloudflare Phishing Email Detections
EmailUrlInfo
EmailEvents
MaliciousDomainTable
Author:
Steven Lim
Released:
December 10th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Dev Ops Code Recommendations
securityresources
Author:
Alex Verboon
Released:
December 9th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Behaviour Suspicious Named Pipes
DeviceEvents
Author:
Bert-Jan Pals
Released:
December 9th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Black Basta Ransomware Campaign RMM Tools Deployment
CloudAppEvents
Author:
Steven Lim
Released:
December 9th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Defender XDR Services And Features Disabled On Devices
DeviceRegistryEvents
Author:
Sergio Albea
Released:
December 8th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Blue Alpha Gamma Drop Detection
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
December 7th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
New URL File NTLM Hash Disclosure Vulnerability Detection 0day
ExposureGraphEdges
DeviceFileEvents
DeviceNetworkEvents
Author:
Steven Lim
Released:
December 6th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Email Events From Email Providers
EmailEvents
Author:
Jay Kerai
Released:
December 6th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Malicious Oauth Grant By Phished User
IdentityInfo
CloudAppEvents
Author:
Steven Lim
Released:
December 5th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify And Summarize Processor Families In Your Environment
DeviceTvmHardwareFirmware
Author:
Michalis Michalos
Released:
December 5th, 2024
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X