Search and discover KQL queries for Microsoft Sentinel, Defender, and Azure Monitor

DeviceInfoDeviceNetworkEventsThreatIntelligenceIndicator

MDE Internet Facing

AADRiskyServicePrincipalsExposureGraphEdgesExposureGraphNodes+2

Workload Identity Info Xdr

IdentityInfo IdentityAccountInfo ExposureGraphNodes ExposureGraphEdges OAuthAppInfo

Unified Identity Info Xdr