KQL Sources - 2025 Update

What started as a single blog is now becoming a yearly trend. More and more KQL related repositories are created, not only with a focus on security but also Intune, Entra and Azure Monitor related queries. Dive in and discover how these new additions can help you tackle challenges or give you new ideas for the new year.

Happy New Year to all of you!

KQL Sources

LinkDescription
kqlsearch.comKQL Search Engine
Kusto Insights NewsletterKusto Insights newsletter
The Definitive Guide to KQLUsing Kusto Query Language for Operations, Defending, and Threat Hunting
Kusto Query InternalsHunting TTPs with Azure Sentinel
Microsoft Sentinel Analytics Rules ExchangeMicrosoft Sentinel Analytics Rules

GitHub Repositories

KQL Community Repositories

LinkDescriptionStars
Azure Sentinel Repository - AzureCloud-native SIEM for intelligent security analytics for your entire enterprisehttps://img.shields.io/github/stars/Azure/Azure-Sentinel?style=flat-square&labelColor=343b41
Sentinel-Queries - reprise99Collection of KQL querieshttps://img.shields.io/github/stars/reprise99/Sentinel-Queries?style=flat-square&labelColor=343b41
Falcon Friday - FalconForceTeamHunting queries and detectionshttps://img.shields.io/github/stars/FalconForceTeam/FalconFriday?style=flat-square&labelColor=343b41
Threat-Hunting-and-Detection - Cyb3r-MonkRepository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).https://img.shields.io/github/stars/Cyb3r-Monk/Threat-Hunting-and-Detection?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - Bert-JanPKQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.https://img.shields.io/github/stars/Bert-JanP/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
AzSentinelQueries - f-baderRepository with Sentinel Analytics Rules and Hunting Querieshttps://img.shields.io/github/stars/f-bader/AzSentinelQueries?style=flat-square&labelColor=343b41
KQL-threat-hunting-queries - cyb3rmik3A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).https://img.shields.io/github/stars/cyb3rmik3/KQL-threat-hunting-queries?style=flat-square&labelColor=343b41
KQL - WortellKQL queries for Advanced Huntinghttps://img.shields.io/github/stars/wortell/KQL?style=flat-square&labelColor=343b41
SentinelKQL - rod-trentAzure Sentinel KQLhttps://img.shields.io/github/stars/rod-trent/SentinelKQL?style=flat-square&labelColor=343b41
Sentinel_KQL - ep3pIn this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).https://img.shields.io/github/stars/ep3p/Sentinel_KQL?style=flat-square&labelColor=343b41
AdvancedHuntingQueries - lawndocMicrosoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenanthttps://img.shields.io/github/stars/lawndoc/AdvancedHuntingQueries?style=flat-square&labelColor=343b41
MDATP AdvancedHunting - JesseEsquivelMicrosoft Defender Advanced Threat Protectionhttps://img.shields.io/github/stars/JesseEsquivel/MDATP?style=flat-square&labelColor=343b41
KQL - mjmeloneMichael Melone’s Kusto Query libraryhttps://img.shields.io/github/stars/mjmelone/KQL?style=flat-square&labelColor=343b41
AzureSentinel - Cloud-ArchitektSharing my KQL queries for Azure Sentinelhttps://img.shields.io/github/stars/Cloud-Architekt/AzureSentinel?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - alexverboonKQL Queries. Microsoft 365 Defender, Microsoft Sentinelhttps://img.shields.io/github/stars/alexverboon/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL Security Queries - ShivammalaviyaKQL Security Querieshttps://img.shields.io/badge/Gist-No%20Stars-lightgrey?style=flat-square&labelColor=343b41
Invictus-training - KQL-QueryPack - invictus-irInvictus: Cloud Incident Response Query Packhttps://img.shields.io/github/stars/invictus-ir/Invictus-training?style=flat-square&labelColor=343b41
DefenderATPQueries - 0xAnalystHunting Queries for Defender ATPhttps://img.shields.io/github/stars/0xAnalyst/DefenderATPQueries?style=flat-square&labelColor=343b41
LearningKijo/KQLThreat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.https://img.shields.io/github/stars/LearningKijo/KQL?style=flat-square&labelColor=343b41
awesomekql - awesomekqlMicrosoft Sentinel, Defender for Endpoint - KQL Detection Packshttps://img.shields.io/github/stars/cylaris/awesomekql?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - KustoKingKQL Detections for Microsoft Sentinel and Microsoft 365 Defenderhttps://img.shields.io/github/stars/KustoKing/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL- mr-r3b00tThis is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanethttps://img.shields.io/github/stars/mr-r3b00t/KQL?style=flat-square&labelColor=343b41
MustLearnKQL - rod-trentCode included as part of the MustLearnKQL blog serieshttps://img.shields.io/github/stars/rod-trent/MustLearnKQL?style=flat-square&labelColor=343b41
kql-for-dfir - reprise99A guide to using Azure Data Explorer and KQL for DFIRhttps://img.shields.io/github/stars/reprise99/kql-for-dfir?style=flat-square&labelColor=343b41
Invictus-training - InvictusCloud Incident Response Query Packhttps://img.shields.io/github/stars/invictus-ir/Invictus-training?style=flat-square&labelColor=343b41
MDATP - JesseEsquivelMicrosoft Defender Advanced Threat Protectionhttps://img.shields.io/github/stars/JesseEsquivel/MDATP?style=flat-square&labelColor=343b41
DefenderATPQueries - 0xAnalystHunting Queries for Defender ATPhttps://img.shields.io/github/stars/0xAnalyst/DefenderATPQueries?style=flat-square&labelColor=343b41
KQL - LearningKijoThreat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.https://img.shields.io/github/stars/LearningKijo/KQL?style=flat-square&labelColor=343b41
KQL - KostasKoutrouKQL Queries for Advanced Hunting / Log Analyticshttps://img.shields.io/github/stars/KostasKoutrou/KQL?style=flat-square&labelColor=343b41
Sentinel-queries - samilamppuSentinel-querieshttps://img.shields.io/github/stars/samilamppu/Sentinel-queries?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - SlimKQLKQL Queries. Microsoft Defender, Microsoft Sentinelhttps://img.shields.io/github/stars/SlimKQL/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KustQueryLanguage_kql - m4nbatCyber Defence related kusto queries for use in Azure Sentinel and Defender advanced huntinghttps://img.shields.io/github/stars/m4nbat/KustQueryLanguage_kql?style=flat-square&labelColor=343b41
DE-TH-Aura - SecurityAuraRepository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration).https://img.shields.io/github/stars/SecurityAura/DE-TH-Aura?style=flat-square&labelColor=343b41
Threat-Hunting-KQL-QueriesThreat-Hunting-KQL-Querieshttps://img.shields.io/github/stars/Sergio-Albea-Git/Threat-Hunting-KQL-Queries?style=flat-square&labelColor=343b41
KustonomiconThe Kustonomicon is your reference companion for navigating the depths of Kusto Query Language (KQL).https://img.shields.io/github/stars/KernelCaleb/Kustonomicon?style=flat-square&labelColor=343b41
KQL_IntuneKQL_Intunehttps://img.shields.io/github/stars/ugurkocde/KQL_Intune?style=flat-square&labelColor=343b41

If you have additions please let me know!

Questions? Feel free to reach out to me on any of my socials.

You can now buy me a coffee!