MDATP
-
Updated
Jul 20, 2024 - PowerShell
MDATP
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
Maps Microsoft Defender XDR Schemas to a local Kustainer Data Explorer instance
Microsoft Defender XDR Advanced Hunting extension and investigation skills for pi
SOC-style cyber incident investigation using KQL, Microsoft Defender XDR, and threat intelligence to analyze phishing, malware execution, data exfiltration, and nation-state threat actors.
Rust MCP server for Microsoft Defender XDR and Defender for Endpoint: 88 tools for hunting, threat intelligence, vulnerability management, and gated response.
SOC Analyst Portfolio | Microsoft Defender XDR | Threat Hunting | Incident Response | Active Directory | Entra ID
Generate production-like Microsoft Defender XDR telemetry based on a YAML profile
Microsoft Security | Entra ID | Defender XDR | Security Operations
A collection of my KQL queries
Detection-as-Code threat-hunting framework for Microsoft Defender XDR & Sentinel
Cloud-native identity compromise hunt in Microsoft Entra ID and Microsoft 365. Reconstructed a patient operator's session from a Low-rated anonymous IP alert through internal spearphishing, inbox rule persistence, and credential theft using Sentinel KQL.
A curated list of high-quality resources focused on securing Microsoft cloud environments, including Identity (Entra ID), Microsoft 365, Microsoft Defender, Sentinel and Microsoft Purview.
Microsoft Defender XDR
Microsoft Defender XDR Action Types
This repository contains demos and guides on how to setup Defender for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.
To associate your repository with the microsoft-defender-xdr topic, visit your repo's landing page and select "manage topics."