Contents

KQL Sources: 2026 Update

What started as a single blog in 2023 is now becoming a yearly tradition. Each year, the KQL community expands with new repositories and queries. The list does not cover just security, but also Intune, Entra, and Azure Monitor.

This year, an extra step is taken to remove some AI generated slop repositories from the list to share correct example repositories.

Happy New Year to all of you!

Highlights

#100DaysOfKQL

Starting the highlights of this year with the #100DaysOfKQL series done by SecurityAura. From January 1, 2025, to April 12, 2025 he has posted some awesome content every day. All KQL queries are stored in the 100DaysOfKQL folder in his query repository.

LinkDescriptionStars
DE-TH-Aura - SecurityAuraRepository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration).https://img.shields.io/github/stars/SecurityAura/DE-TH-Aura?style=flat-square&labelColor=343b41

Graph Queries

In 2025 more graph based queries started to be shared on GitHub, one of the people who contributed multiple graph based detections is Thomas Verheyden. He has shared multiple graph based queries for Microsoft Exporsure Management in his repository. The queries can both be used as example to lean more about graph semantics and get valuable insights from the shared queries.

LinkDescriptionStars
Microsoft-Exposure-management - v3rthoThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/v3rtho/Microsoft-Exposure-management-?style=flat-square&labelColor=343b41

HybridBrothers

Last but not least, the repository of the HybridBrothers is part of the highlighted Kusto content of 2025. They already started posting in 2024, but they leveled up their game in the last year by adding valuable queries for the community.

LinkDescriptionStars
Hunting-Queries-Detection-Rules - HybridBrothersThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/HybridBrothers/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41

GitHub Repositories

New GitHub Repositories

Listing the repositories that were added to the list in 2025.

LinkDescriptionStars
Azure-SecOps - AttacktheSOCCollection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)https://img.shields.io/github/stars/AttacktheSOC/Azure-SecOps?style=flat-square&labelColor=343b41
Hunting-Queries-and-Detection-Rule-Microsoft-Sentinel-Defender - SubashGhimireKQL Sentinel and Defender Detection and Hunting Queries.https://img.shields.io/github/stars/SubashGhimire/Hunting-Queries-and-Detection-Rule-Microsoft-Sentinel-Defender?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - HybridBrothersThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/HybridBrothers/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQLAdvancedHunting - benschaThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/benscha/KQLAdvancedHunting?style=flat-square&labelColor=343b41
Defender-for-endpoint - v3rthoGuidance scripts related to Defender For Endpoint: installation, prereq check, configuration etchttps://img.shields.io/github/stars/v3rtho/Defender-for-endpoint?style=flat-square&labelColor=343b41
Microsoft-Exposure-management - v3rthoThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/v3rtho/Microsoft-Exposure-management-?style=flat-square&labelColor=343b41

KQL Community Repositories

LinkDescriptionStars
Azure Sentinel Repository - AzureCloud-native SIEM for intelligent security analytics for your entire enterprisehttps://img.shields.io/github/stars/Azure/Azure-Sentinel?style=flat-square&labelColor=343b41
Sentinel-Queries - reprise99Collection of KQL querieshttps://img.shields.io/github/stars/reprise99/Sentinel-Queries?style=flat-square&labelColor=343b41
Falcon Friday - FalconForceTeamHunting queries and detectionshttps://img.shields.io/github/stars/FalconForceTeam/FalconFriday?style=flat-square&labelColor=343b41
Threat-Hunting-and-Detection - Cyb3r-MonkRepository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).https://img.shields.io/github/stars/Cyb3r-Monk/Threat-Hunting-and-Detection?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - Bert-JanPKQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules.https://img.shields.io/github/stars/Bert-JanP/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
AzSentinelQueries - f-baderRepository with Sentinel Analytics Rules and Hunting Querieshttps://img.shields.io/github/stars/f-bader/AzSentinelQueries?style=flat-square&labelColor=343b41
KQL-threat-hunting-queries - cyb3rmik3A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).https://img.shields.io/github/stars/cyb3rmik3/KQL-threat-hunting-queries?style=flat-square&labelColor=343b41
KQL - WortellKQL queries for Advanced Huntinghttps://img.shields.io/github/stars/wortell/KQL?style=flat-square&labelColor=343b41
SentinelKQL - rod-trentAzure Sentinel KQLhttps://img.shields.io/github/stars/rod-trent/SentinelKQL?style=flat-square&labelColor=343b41
Sentinel_KQL - ep3pIn this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).https://img.shields.io/github/stars/ep3p/Sentinel_KQL?style=flat-square&labelColor=343b41
AdvancedHuntingQueries - lawndocMicrosoft 365 Advanced Hunting Queries with hotlinks that plug the query right into your tenanthttps://img.shields.io/github/stars/lawndoc/AdvancedHuntingQueries?style=flat-square&labelColor=343b41
MDATP AdvancedHunting - JesseEsquivelMicrosoft Defender Advanced Threat Protectionhttps://img.shields.io/github/stars/JesseEsquivel/MDATP?style=flat-square&labelColor=343b41
KQL - mjmeloneMichael Melone’s Kusto Query libraryhttps://img.shields.io/github/stars/mjmelone/KQL?style=flat-square&labelColor=343b41
AzureSentinel - Cloud-ArchitektSharing my KQL queries for Azure Sentinelhttps://img.shields.io/github/stars/Cloud-Architekt/AzureSentinel?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - alexverboonKQL Queries. Microsoft 365 Defender, Microsoft Sentinelhttps://img.shields.io/github/stars/alexverboon/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL Security Queries - ShivammalaviyaKQL Security Querieshttps://img.shields.io/badge/Gist-No%20Stars-lightgrey?style=flat-square&labelColor=343b41
Invictus-training - KQL-QueryPack - invictus-irInvictus: Cloud Incident Response Query Packhttps://img.shields.io/github/stars/invictus-ir/Invictus-training?style=flat-square&labelColor=343b41
DefenderATPQueries - 0xAnalystHunting Queries for Defender ATPhttps://img.shields.io/github/stars/0xAnalyst/DefenderATPQueries?style=flat-square&labelColor=343b41
LearningKijo/KQLThreat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.https://img.shields.io/github/stars/LearningKijo/KQL?style=flat-square&labelColor=343b41
awesomekql - awesomekqlMicrosoft Sentinel, Defender for Endpoint - KQL Detection Packshttps://img.shields.io/github/stars/cylaris/awesomekql?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - KustoKingKQL Detections for Microsoft Sentinel and Microsoft 365 Defenderhttps://img.shields.io/github/stars/KustoKing/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQL- mr-r3b00tThis is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanethttps://img.shields.io/github/stars/mr-r3b00t/KQL?style=flat-square&labelColor=343b41
MustLearnKQL - rod-trentCode included as part of the MustLearnKQL blog serieshttps://img.shields.io/github/stars/rod-trent/MustLearnKQL?style=flat-square&labelColor=343b41
kql-for-dfir - reprise99A guide to using Azure Data Explorer and KQL for DFIRhttps://img.shields.io/github/stars/reprise99/kql-for-dfir?style=flat-square&labelColor=343b41
Invictus-training - InvictusCloud Incident Response Query Packhttps://img.shields.io/github/stars/invictus-ir/Invictus-training?style=flat-square&labelColor=343b41
MDATP - JesseEsquivelMicrosoft Defender Advanced Threat Protectionhttps://img.shields.io/github/stars/JesseEsquivel/MDATP?style=flat-square&labelColor=343b41
DefenderATPQueries - 0xAnalystHunting Queries for Defender ATPhttps://img.shields.io/github/stars/0xAnalyst/DefenderATPQueries?style=flat-square&labelColor=343b41
KQL - LearningKijoThreat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.https://img.shields.io/github/stars/LearningKijo/KQL?style=flat-square&labelColor=343b41
KQL - KostasKoutrouKQL Queries for Advanced Hunting / Log Analyticshttps://img.shields.io/github/stars/KostasKoutrou/KQL?style=flat-square&labelColor=343b41
Sentinel-queries - samilamppuSentinel-querieshttps://img.shields.io/github/stars/samilamppu/Sentinel-queries?style=flat-square&labelColor=343b41
KustQueryLanguage_kql - m4nbatCyber Defence related kusto queries for use in Azure Sentinel and Defender advanced huntinghttps://img.shields.io/github/stars/m4nbat/KustQueryLanguage_kql?style=flat-square&labelColor=343b41
DE-TH-Aura - SecurityAuraRepository where I hold random detection and threat hunting queries that I come up with based on different sources of information (or even inspiration).https://img.shields.io/github/stars/SecurityAura/DE-TH-Aura?style=flat-square&labelColor=343b41
Threat-Hunting-KQL-QueriesThreat-Hunting-KQL-Querieshttps://img.shields.io/github/stars/Sergio-Albea-Git/Threat-Hunting-KQL-Queries?style=flat-square&labelColor=343b41
KustonomiconThe Kustonomicon is your reference companion for navigating the depths of Kusto Query Language (KQL).https://img.shields.io/github/stars/KernelCaleb/Kustonomicon?style=flat-square&labelColor=343b41
KQL_IntuneKQL_Intunehttps://img.shields.io/github/stars/ugurkocde/KQL_Intune?style=flat-square&labelColor=343b41
Azure-SecOps - AttacktheSOCCollection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)https://img.shields.io/github/stars/AttacktheSOC/Azure-SecOps?style=flat-square&labelColor=343b41
Hunting-Queries-and-Detection-Rule-Microsoft-Sentinel-Defender - SubashGhimireKQL Sentinel and Defender Detection and Hunting Queries.https://img.shields.io/github/stars/SubashGhimire/Hunting-Queries-and-Detection-Rule-Microsoft-Sentinel-Defender?style=flat-square&labelColor=343b41
Hunting-Queries-Detection-Rules - HybridBrothersThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/HybridBrothers/Hunting-Queries-Detection-Rules?style=flat-square&labelColor=343b41
KQLAdvancedHunting - benschaThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/benscha/KQLAdvancedHunting?style=flat-square&labelColor=343b41
Defender-for-endpoint - v3rthoGuidance scripts related to Defender For Endpoint: installation, prereq check, configuration etchttps://img.shields.io/github/stars/v3rtho/Defender-for-endpoint?style=flat-square&labelColor=343b41
Microsoft-Exposure-management - v3rthoThe purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behaviorhttps://img.shields.io/github/stars/v3rtho/Microsoft-Exposure-management-?style=flat-square&labelColor=343b41

In case you cannot wait for new updates until next year, I keep track of the list during the year on GitHub: KQL Community Repositories

KQL Sources

LinkDescription
kqlsearch.comKQL Search Engine
Kusto Insights NewsletterKusto Insights newsletter
The Definitive Guide to KQLUsing Kusto Query Language for Operations, Defending, and Threat Hunting
Kusto Query InternalsHunting TTPs with Azure Sentinel
Microsoft Sentinel Analytics Rules ExchangeMicrosoft Sentinel Analytics Rules

If you have additions, please let me know!

Questions? Feel free to reach out to me on any of my socials.