AzureActivity
Search and discover KQL queries for Microsoft Sentinel, Defender, and Azure Monitor
AuditLogs
HUNT 23 MFA Auth Method Changes
AADServicePrincipalSignInLogs
HUNT 18 SP Signin New Country
AzureActivity
HUNT 15 Identity Ops Anomaly Deep Dive
StorageBlobLogs
HUNT 03 Storage Blob Exfiltration
AzureActivity
HUNT 09 New SP Key Vault Access
AuditLogsAzureActivity
HUNT 06 Orphaned Privileged Roles
AzureActivity
HUNT 17 Key Vault Bulk Read
SigninLogsAADServicePrincipalSignInLogs
HUNT 26 Risky Anonymizer Signin Timeline
AuditLogs
HUNT 24 Guest Invite Privileged Role
AzureActivity
HUNT 25 Storage Data Protection Changes
AzureActivity
HUNT 16 First Seen Resource Provider Per Identity
AzureActivity
HUNT 12 NSG Firewall Change History
AzureActivity
HUNT 14 Sentinel Config Changes
AzureActivity
HUNT 21 Caller IP Concentration
SigninLogs
HUNT 20 Signin Anomalous ASN
AuditLogs
HUNT 19 Consent Grant Burst
AzureActivitySigninLogsAADServicePrincipalSignInLogs
RULE 11 Mass Resource Deletion
AzureActivity
RULE 15 VM Custom Script Extension
StorageBlobLogs
RULE 13 Storage Anonymous Public Access
AzureActivityStorageBlobLogs
RULE 04 Storage SAS Token Bulk Generation
AuditLogs
RULE 18 AAD Illicit Consent Grant
AzureActivity
RULE 03 Mass Privileged Role Assignments
AzureActivity
RULE 17 Anomalous Management Operations
AzureActivity
RULE 09 Privileged Ops New IP
AADServicePrincipalSignInLogsAzureActivity
RULE 10 SP CA Bypass Management Ops
AzureActivitySigninLogsAADServicePrincipalSignInLogs
RULE 12 Mass Resource Creation
AzureActivity
RULE 20 Storage Immutability Removed
SigninLogsAADServicePrincipalSignInLogsAzureActivity
RULE 19 Anonymizer Signin Priv Ops
AzureActivity
RULE 16 Sentinel Analytics Rule Deleted
AzureActivity
Azure Service Health Action Notifications
DeviceProcessEventsIdentityInfo
Detecting Potential CA Policy Bypass By Privileged Accounts Via Private Browser Sessions
EmailEventsEmailUrlInfo
Applying Shanon Entropy To Sender Domains Via Kusto
DeviceProcessEvents
Detecting Execution Of Windows Security Audit Policy Auditpolexe
DeviceNetworkEvents
Detecting Abuse Of Sync Thing Tool To Steal Data
DeviceProcessEvents
Detect Bcedit Commands Related To Boot Configuration
DeviceProcessEvents
Potential Commands Executed By A Power Shellexe Renamed
DeviceFileEvents
Detecting Base64 Code In Commands
DeviceNetworkEvents
Detect Malicious URL Answers By DNS Queries
DeviceTvmSoftwareInventory
Ivanti Vulnerabilities CVE 2025 0282 And CVE 2025 0283
DeviceInfoDeviceNetworkInfoDeviceNetworkEvents
LM Internal Threat Hunting Over Routers Devices
DeviceProcessEvents
RDP Trace Removal Detection
DeviceProcessEvents
Detect The Removal Of Evidence On Executed Programs
IOCFeedEmailUrlInfoEmailEvents+5
Threat Hunting Based On IO Cs Extracted From Security News And Reports
EmailEvents
Detecting Onmicrosoft Domains Impacted By Email Exchange Restrictions With External Domains
DeviceFileEvents
IC Catching Emojis Into File Names
AADSignInEventsBeta
Detecting Connections Affected By The Blocking Legacy Authentication Enforcement Expected By July 2025
MispHashesbotvrijFH_TweetFeedYear+3
