CloudAppEvents
Search and discover KQL queries for Microsoft Sentinel, Defender, and Azure Monitor
EmailEventsEmailUrlInfo
Detect Microsoft Shared File Messages Via Internet Message Id Odspnotify Value
AlertInfoAlertEvidence
Detection Rule Usefulness Evaluation Based On DOVE Model
CloudAppEvents
Hunting One On One Chats By Domains
DeviceNetworkEvents
Hunting For Malicious Click Fix Cases From Airports
DeviceEvents
Detecting Windows Security Event Logs Cleaned
DeviceFileEvents
IC Catching Emojis Into File Names
DeviceTvmSoftwareVulnerabilitiesDeviceTvmSoftwareVulnerabilitiesKB
September Updates
DeviceProcessEvents
RDP Trace Removal Detection
AADSignInEventsBeta
Hunting For Malicious Login Attempts Based On Basic Authentication
EmailEventsUrlClickEventsEmailAttachmentInfo
IO Cs Associated With Apt41s Malware Delivery Via Google Calendar
DeviceTvmSoftwareInventory
Microsoft Office Security Feature Bypass Vulnerability CVE 2026 21509
DeviceProcessEvents
Detecting Execution Of Windows Security Audit Policy Auditpolexe
DeviceInfoDeviceNetworkEvents
New KSMBD Do S CVE 2025 38501 Can Exhaust SMB Connections Via Half Open TCP Handshakes
AADSignInEventsBeta
Sign In Attempts Using Deprecated TLS Versions
DeviceFileEvents
Detect Attempts To Modify Amcachehve Or SYSTEM File
DeviceProcessEvents
Detect Suspicious Actions To Change Desktop Background
DeviceInfoDeviceNetworkInfoDeviceNetworkEvents
LM Internal Threat Hunting Over Routers Devices
DeviceNetworkEvents
Detect Malicious URL Answers By DNS Queries
DeviceProcessEvents
Detect Bcedit Commands Related To Boot Configuration
DeviceProcessEvents
Potential Commands Executed By A Power Shellexe Renamed
DeviceNetworkEventsDeviceFileEventsDeviceImageLoadEvents
IO Cs For Smart Ape SG Fake Browser Update Leads To Net Support RAT And Steal C
DeviceFileEvents
Detecting Base64 Code In Commands
EmailAttachmentInfoEmailEvents
IC Catching Emojis Into Email Attachment Files Names
CIDRASNMalicious_ASNIdentityLogonEvents
Identities Bad Reputation ASN Activities
DeviceNetworkEvents
Detecting Abuse Of Sync Thing Tool To Steal Data
EmailEventsEmailUrlInfo
Applying Shanon Entropy To Sender Domains Via Kusto
DeviceProcessEventsIdentityInfo
Detecting Potential CA Policy Bypass By Privileged Accounts Via Private Browser Sessions
DeviceNetworkEvents
Extracting Bits Of TCP Flags
DeviceProcessEventsDeviceInfo
Windows File Explorer Elevation Of Privilege Vulnerability CVE 2024 38100 Exploited
EmailUrlInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On URL IO Cs
DeviceNetworkEvents
Detect Malicious Answers By DNS Queries
DeviceNetworkEvents
Identifying Devices By Vendor Based On Inbound Connections
UrlClickEventsEmailEvents
User Information Collected Externally When A URL Is Clicked
DeviceFileEventsDeviceEvents
Weaponized Files Extracting DLL Files After Execution
MispHashesbotvrijFH_TweetFeedYear+3
IA Threat Intelligence Feed Evaluation Based On File Hashes IO Cs
AADSignInEventsBeta
Detecting Connections Affected By The Blocking Legacy Authentication Enforcement Expected By July 2025
DeviceNetworkEvents
Review Required Outbound Connections To Work Wit Defender For Cloud Apps
EmailEvents
Detecting Onmicrosoft Domains Impacted By Email Exchange Restrictions With External Domains
IOCFeedEmailUrlInfoEmailEvents+5
Threat Hunting Based On IO Cs Extracted From Security News And Reports
DeviceProcessEvents
Detect The Removal Of Evidence On Executed Programs
EmailEventsIdentityInfo
Detect Spoofed Email Cases
BotvrijRAWmontysecurityPhishuntURLs+6
IA Threat Intelligence Feed Evaluation Based On Domains IO Cs
DeviceTvmSoftwareInventory
