KQL Search
Assistant
Generator
Lab
Our Sponsors
❤️
Show Advanced Filters
Table:
Select...
Author:
Select...
Keyword:
Select...
Operator:
Select...
Newsletter
Popular Queries
Statistics
Submit query
Device Query
AWS No Such Bucket Check
AWSCloudTrail
Author:
Steven Lim
Released:
February 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra QR Code Sign In KQL Detection
AuditLogs
Author:
Steven Lim
Released:
February 6th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Defender XDR Custom Detection Modifications
CloudAppEvents
Author:
Jay Kerai
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE MMA Agent Cleanup
DeviceNetworkEvents
DeviceProcessEvents
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Antivirus Domains MDE Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Windows11 Issues OS Build 26100 2033
DeviceTvmSoftwareVulnerabilities
DeviceInfo
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
MDE Usage Latest
Usage
DeviceFileEvents
DeviceProcessEvents
DeviceLogonEvents
DeviceRegistryEvents
DeviceNetworkEvents
DeviceNetworkInfo
DeviceInfo
DeviceImageLoadEvents
DeviceEvents
DeviceFileCertificateInfo
Author:
Alex Verboon
Released:
February 5th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Windows OLE Zero Click Vulnerability Let Attacker To Execute Arbitrary Code
EmailAttachmentInfo
EmailEvents
Author:
Sergio Albea
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Crowdstrike Impersonation During Global Outage
CrowdstrikeIOCs
EmailUrlInfo
EmailEvents
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Block List Project Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Adult Content MDE Device Network Events
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Sysinternals Tools Zero Day Vulnerability Detection
SysinternalsTools
DeviceEvents
Author:
Steven Lim
Released:
February 4th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Extracting Bits Of TCP Flags
DeviceNetworkEvents
Author:
Sergio Albea
Released:
February 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Audit Logs Azure RBAC Elevated Access
AuditLogs
Author:
Jose Sebastián Canós
Released:
February 3rd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Active Directory Domain Services Elevation Of Privilege Vulnerability CVE 2025 21293
DeviceInfo
DeviceEvents
DeviceRegistryEvents
Author:
Steven Lim
Released:
February 2nd, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ROSTI Repackaged Open Source Intelligence MDE Network Events IOC Hits
DeviceNetworkEvents
Author:
Jay Kerai
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
ROSTI Repackaged Open Source Intelligence MDE File Events IOC Hits
DeviceFileEvents
Author:
Jay Kerai
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Rogue Endpoints Via SMB Detection
DeviceEvents
Author:
Steven Lim
Released:
February 1st, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Anonymous Email Sending Domains MDE Traffic
DeviceNetworkEvents
Author:
Jay Kerai
Released:
January 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Global Admin Elevations To User Access Administrator At Root Level
AuditLogs
Author:
Jay Kerai
Released:
January 31th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Windows File Explorer Elevation Of Privilege Vulnerability CVE 2024 38100 Exploited
DeviceProcessEvents
DeviceInfo
Author:
Sergio Albea
Released:
January 30th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Malicious Impersonation Of Deepseek Domains In Email UR Ls
EmailUrlInfo
EmailEvents
Author:
Steven Lim
Released:
January 29th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect User Request Token For Admin App
SigninLogs
IdentityInfo
Author:
Robbe Van den Daele
Released:
January 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Securing Your Azure Cloud Finding The Weakest Link In Admin Endpoints
ExposureGraphEdges
ExposureGraphNodes
Author:
Steven Lim
Released:
January 28th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Token Stealing With Wdac
DeviceEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Suspicious Ca Changes
AuditLogs
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Nnr Health Issues
DeviceNetworkInfo
DeviceNetworkEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Devices Supporting Mde Containment
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Public Devices With Tag
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Organize Devices By Subnet
DeviceNetworkInfo
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Public Devices Without Tag
DeviceNetworkEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunt Public Devices Over Time
DeviceInfo
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Detect Cve Exploit For Vulnerable Device
DeviceTvmSoftwareVulnerabilities
DeviceNetworkEvents
Author:
Robbe Van den Daele
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
RID Hijacking Technique And Detection
DeviceEvents
DeviceRegistryEvents
Author:
Steven Lim
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Leveraging Spamhaus Drop List To Identify Suspicious Connections In Commonsecuritylog Table
CommonSecurityLog
Author:
Michalis Michalos
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Leveraging Spamhaus Drop List To Identify Delivered Emails From Suspicious Source Ips
EmailEvents
Author:
Michalis Michalos
Released:
January 26th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Cef To Common Security Log
source
Author:
Robbe Van den Daele
Released:
January 25th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure Subscription Budget Deletion
AzureActivity
Author:
Jay Kerai
Released:
January 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AAD Non Interactive User Sign In Logs Unexpected Failures In Non Interactive Authentications From An App
AADNonInteractiveUserSignInLogs
Author:
Jose Sebastián Canós
Released:
January 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Fake Reddit Sites Push Lumma Stealer Malware Part 2
FakeRedditLummaS
DeviceNetworkEvents
Author:
Steven Lim
Released:
January 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Hunting Fake Reddit Sites Push Lumma Stealer Malware Part 1
EmailUrlInfo
EmailEvents
Author:
Steven Lim
Released:
January 24th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
AAD Non Interactive User Sign In Logs Unexpected Authentication From Windows Azure Active Directory App
AADNonInteractiveUserSignInLogs
Author:
Jose Sebastián Canós
Released:
January 23th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID SSPR Configuration Changes
AuditLogs
Author:
Alex Verboon
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure AD Enterprise Apps Disabled
AuditLogs
Author:
Alex Verboon
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Azure AD PIM Group Members
IdentityInfo
Author:
Alex Verboon
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Entra ID Suspicious Activity Reported
AuditLogs
Author:
Alex Verboon
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Power Shell Executions From Clipboard
DeviceEvents
DeviceProcessEvents
Author:
Bert-Jan Pals
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Fortigate Belsen Leak KQL Check
CommonSecurityLog
Author:
Steven Lim
Released:
January 22th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Last Check In Arc Machines
Resources
Heartbeat
Author:
Bert-Jan Pals
Released:
January 20th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X
Identify Mail Items Accessed By A Specific IP Address CISA
AADSignInEventsBeta
CloudAppEvents
Author:
Jay Kerai
Released:
January 20th, 2025
Show Query
Show Explanation
Copy URL
Open on GitHub
Share on X