Home
AI Tools
Device Query
Popular
Statistics
KQL Search
Search and discover KQL queries for Microsoft Sentinel, Defender, and Azure Monitor
Our Sponsors
❤️
Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
AADUserRiskEvents
EntraIdSignInEvents
IdentityInfo
User Risk Event Correlation With Historical Baseline And Account Age
Benjamin Zulliger
|
Jun 25, 2026
Copy Link
View
SecurityEvent
Security Event Unexpected NTLM Network Authentication
Jose Sebastián Canós
|
Jun 24, 2026
Copy Link
View
CloudAppEvents
Microsoft Dynamics 365 Privilege Escalation Via Role Or Team Modification
Benjamin Zulliger
|
Jun 24, 2026
Copy Link
View
IdentityInfo
MDI Service Accounts Without Service Principals And MS As
Jay Kerai
|
Jun 23, 2026
Copy Link
View
DeviceFileEvents
Executable Files Program Data Folder
Bert-Jan Pals
|
Jun 22, 2026
Copy Link
View
DeviceFileEvents
Executable Files Public Folder
Bert-Jan Pals
|
Jun 22, 2026
Copy Link
View
DeviceProcessEvents
DeviceRegistryEvents
Unofficial Win Get Source Added
Benjamin Zulliger
|
Jun 22, 2026
Copy Link
View
IdentityQueryEvents
Unusual LDAP Query Burst From New Or Known Device
Benjamin Zulliger
|
Jun 22, 2026
Copy Link
View
IdentityQueryEvents
LDAP Cross Domain Enumeration
Benjamin Zulliger
|
Jun 22, 2026
Copy Link
View
DeviceInfo
DeviceNetworkEvents
ThreatIntelligenceIndicator
MDE Internet Facing
Alex Verboon
|
Jun 20, 2026
Copy Link
View
AgentsInfo
MDE Local AI Agents
Alex Verboon
|
Jun 19, 2026
Copy Link
View
IdentityQueryEvents
IdentityLogonEvents
Correlating LDAP Reconnaissance With Kerberoasting And Sensitive Queries
Benjamin Zulliger
|
Jun 19, 2026
Copy Link
View
DeviceFileEvents
DeviceProcessEvents
Suspicious Oahd Activity On Mac OS
Benjamin Zulliger
|
Jun 19, 2026
Copy Link
View
DeviceProcessEvents
Mac OS Keychain Dump Via Security CLI
Benjamin Zulliger
|
Jun 19, 2026
Copy Link
View
DeviceProcessEvents
Suspicious Tool Accessing Browser Cookies On Mac OS
Benjamin Zulliger
|
Jun 19, 2026
Copy Link
View
DeviceTvmSecureConfigurationAssessment
Device Tvm Secure Configuration Assessment Enrichment With SCID Details
Benjamin Zulliger
|
Jun 19, 2026
Copy Link
View
AuditLogs
30 PIM Self Activation Tier0role
David Alonso
|
Jun 18, 2026
Copy Link
View
AuditLogs
29 Service Principal Self Privilege Escalation
David Alonso
|
Jun 18, 2026
Copy Link
View
ExposureGraphNodes
Windows Workstations With RDP Enabled And Allowed Connections
Benjamin Zulliger
|
Jun 18, 2026
Copy Link
View
ExposureGraphNodes
High Risk Vulnerabilities With Exploits Detected On Onboarded Devices
Benjamin Zulliger
|
Jun 18, 2026
Copy Link
View
AuditLogs
Removal Of Roles Post GDAP Relationship Ending
Jay Kerai
|
Jun 18, 2026
Copy Link
View
ADOAuditLogs_CL
Azure Dev Ops High Volume Search Activity
Benjamin Zulliger
|
Jun 18, 2026
Copy Link
View
ADOAuditLogs_CL
Azure Dev Ops Token Administration Activity From Non Corporate IP
Benjamin Zulliger
|
Jun 18, 2026
Copy Link
View
IdentityLogonEvents
Masking Account Names And UP Ns For Demos
Benjamin Zulliger
|
Jun 18, 2026
Copy Link
View
DeviceNetworkEvents
DeviceImageLoadEvents
Multiple Uncommon Loaded Image Connection To Suspicious Domain
Jose Sebastián Canós
|
Jun 17, 2026
Copy Link
View
DeviceNetworkEvents
Outbound Connection To Spydisec High Confidence Malicious IP
Benjamin Zulliger
|
Jun 16, 2026
Copy Link
View
SecurityAlert
SecurityIncident
SentinelHealth
+1
Sentinel Rule Tuning Queries
David Alonso
|
Jun 16, 2026
Copy Link
View
DeviceInfo
DeviceTvmSoftwareInventory
Identify Windows Devices Missing Defender For Endpoint WSL Plugin
Benjamin Zulliger
|
Jun 14, 2026
Copy Link
View
AADServicePrincipalSignInLogs
21 Service Principal Anomalous IP Spread
David Alonso
|
Jun 12, 2026
Copy Link
View
AADNonInteractiveUserSignInLogs
OfficeActivity
14 NI Auth Bulk Data Download
David Alonso
|
Jun 12, 2026
Copy Link
View
AADNonInteractiveUserSignInLogs
AuditLogs
10 Stale Token After Password Change
David Alonso
|
Jun 12, 2026
Copy Link
View
DeviceNetworkEvents
Device Network Events Uncommon Process Connection To Suspicious Domain
Jose Sebastián Canós
|
Jun 11, 2026
Copy Link
View
DeviceFileEvents
Detect Shebang Code Inside Files With Unusual Extensions
Sergio Albea
|
Jun 11, 2026
Copy Link
View
DeviceFileEvents
Detect Shebang Code Inside Device Files
Sergio Albea
|
Jun 11, 2026
Copy Link
View
DeviceFileEvents
EmailAttachmentInfo
Detect Shebang File Types Received Via Email
Sergio Albea
|
Jun 11, 2026
Copy Link
View
DeviceProcessEvents
DeviceRegistryEvents
DeviceFileEvents
Rogue Planet Defender TOCTOU LPE Detection
Benjamin Zulliger
|
Jun 10, 2026
Copy Link
View
DeviceEvents
ISO Virtual DVD ROM File Mount
Jay Kerai
|
Jun 9, 2026
Copy Link
View
DeviceFileEvents
Suspicious RDP Bitmap Cache Access
Benjamin Zulliger
|
Jun 9, 2026
Copy Link
View
DeviceEvents
Potential Azure VM Admin Password Reset Using VM Access Extension
Jay Kerai
|
Jun 9, 2026
Copy Link
View
DeviceInfo
DeviceTvmSoftwareVulnerabilities
DeviceTvmSoftwareVulnerabilitiesKB
Discovered Network Devices CVE CVSS
Benjamin Zulliger
|
Jun 9, 2026
Copy Link
View
AIAgentsInfo
AI Agent Third Party Plugin With Internal Data Access
Benjamin Zulliger
|
Jun 8, 2026
Copy Link
View
AIAgentsInfo
AI Agent With Weak Authentication Or Access Control
Benjamin Zulliger
|
Jun 8, 2026
Copy Link
View
DeviceEvents
RPC Attack Detection
Benjamin Zulliger
|
Jun 8, 2026
Copy Link
View
DeviceFileEvents
DeviceNetworkEvents
Hunting Uncommon VS Code Extensions
Benjamin Zulliger
|
Jun 8, 2026
Copy Link
View
DeviceProcessEvents
HEX And XOR Obfuscated Powershell Click Fix Attack
Benjamin Zulliger
|
Jun 8, 2026
Copy Link
View
EmailPostDeliveryEvents
EmailEvents
EmailAttachmentInfo
+3
Multiple Zapped Emails With Possibly Malicious Entities Unchecked
Jose Sebastián Canós
|
Jun 8, 2026
Copy Link
View
AppEvents
Agent Channel Distribution
David Alonso
|
Jun 8, 2026
Copy Link
View
AppEvents
Agent Topic Trigger Enumeration
David Alonso
|
Jun 8, 2026
Copy Link
View
AppEvents
Agent Indirect Injection In Response
David Alonso
|
Jun 8, 2026
Copy Link
View
AppEvents
Agent Prompt Injection Signals
David Alonso
|
Jun 8, 2026
Copy Link
View