KQL Security Sources - 2024 Update

It is great to see that more and more repositories, blogs and other sources share security related KQL content. Therefore this post provides an updated list of KQL Security Sources to start the new year. These sources can help you to kickstart your KQL knowledge for the upcoming year, by providing learning material, detection rules, hunting queries and many more.

The image below shows the increase in KQL repositories and the adoption from the community, they are becoming more and more popular, due to companies shifting to Microsoft Security solutions. Those KQL repositories can provide advanced detections, visualisations and hunting queries to detect the bad. I am very curious how this will develop in 2024. You can follow the changes live by following this link.

/images/kql-sources-2024/star-history-202411.png
GitHub Star History 200+ star repositories (moment of writing)

KQL Sources

LinkDescription
kqlsearch.comKQL Search Engine
Kusto Insights NewsletterKusto Insights newsletter
The Definitive Guide to KQLUsing Kusto Query Language for Operations, Defending, and Threat Hunting
Kusto Query InternalsHunting TTPs with Azure Sentinel

GitHub Repositories

LinkDescriptionStars
Azure Sentinel Repository - AzureCloud-native SIEM for intelligent security analytics for your entire enterprisehttps://img.shields.io/github/stars/Azure/Azure-Sentinel?style=flat-square&labelColor=343b41
Sentinel-Queries - reprise99Collection of KQL querieshttps://img.shields.io/github/stars/reprise99/Sentinel-Queries?style=flat-square&labelColor=343b41
Falcon Friday - FalconForceTeamHunting queries and detectionshttps://img.shields.io/github/stars/FalconForceTeam/FalconFriday?style=flat-square&labelColor=343b41
Threat-Hunting-and-Detection - Cyb3r-MonkRepository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).https://img.shields.io/github/stars/Cyb3r-Monk/Threat-Hunting-and-Detection?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - Bert-JanPKQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.https://img.shields.io/github/stars/Bert-JanP/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
AzSentinelQueries - f-baderRepository with Sentinel Analytics Rules and Hunting Querieshttps://img.shields.io/github/stars/f-bader/AzSentinelQueries?style=flat-square&labelColor=343b41
KQL-threat-hunting-queries - cyb3rmik3A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).https://img.shields.io/github/stars/cyb3rmik3/KQL-threat-hunting-queries?style=flat-square&labelColor=343b41
KQL - WortellKQL queries for Advanced Huntinghttps://img.shields.io/github/stars/wortell/KQL?style=flat-square&labelColor=343b41
SentinelKQL - rod-trentAzure Sentinel KQLhttps://img.shields.io/github/stars/rod-trent/SentinelKQL?style=flat-square&labelColor=343b41
Sentinel_KQL - ep3pIn this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).https://img.shields.io/github/stars/ep3p/Sentinel_KQL?style=flat-square&labelColor=343b41
AdvancedHuntingQueries - lawndocMicrosoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenanthttps://img.shields.io/github/stars/lawndoc/AdvancedHuntingQueries?style=flat-square&labelColor=343b41
MDATP AdvancedHunting - JesseEsquivelMicrosoft Defender Advanced Threat Protectionhttps://img.shields.io/github/stars/JesseEsquivel/MDATP?style=flat-square&labelColor=343b41
KQL - mjmeloneMichael Melone’s Kusto Query libraryhttps://img.shields.io/github/stars/mjmelone/KQL?style=flat-square&labelColor=343b41
AzureSentinel - Cloud-ArchitektSharing my KQL queries for Azure Sentinelhttps://img.shields.io/github/stars/Cloud-Architekt/AzureSentinel?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - alexverboonKQL Queries. Microsoft 365 Defender, Microsoft Sentinelhttps://img.shields.io/github/stars/alexverboon/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL Security Queries - ShivammalaviyaKQL Security Querieshttps://img.shields.io/badge/Gist-No%20Stars-lightgrey?style=flat-square&labelColor=343b41
Invictus-training - KQL-QueryPack - invictus-irInvictus: Cloud Incident Response Query Packhttps://img.shields.io/github/stars/invictus-ir/Invictus-training?style=flat-square&labelColor=343b41
DefenderATPQueries - 0xAnalystHunting Queries for Defender ATPhttps://img.shields.io/github/stars/0xAnalyst/DefenderATPQueries?style=flat-square&labelColor=343b41
LearningKijo/KQLThreat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.https://img.shields.io/github/stars/LearningKijo/KQL?style=flat-square&labelColor=343b41
awesomekql - awesomekqlMicrosoft Sentinel, Defender for Endpoint - KQL Detection Packshttps://img.shields.io/github/stars/cylaris/awesomekql?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - KustoKingKQL Detections for Microsoft Sentinel and Microsoft 365 Defenderhttps://img.shields.io/github/stars/KustoKing/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL- mr-r3b00tThis is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanethttps://img.shields.io/github/stars/mr-r3b00t/KQL?style=flat-square&labelColor=343b41
MustLearnKQL - rod-trentCode included as part of the MustLearnKQL blog serieshttps://img.shields.io/github/stars/rod-trent/MustLearnKQL?style=flat-square&labelColor=343b41
kql-for-dfir - reprise99A guide to using Azure Data Explorer and KQL for DFIRhttps://img.shields.io/github/stars/reprise99/kql-for-dfir?style=flat-square&labelColor=343b41

If you have additions please let me know!

Questions? Feel free to reach out to me on any of my socials.