Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
-
Updated
Feb 11, 2025 - PowerShell
Defender XDR Advanced Hunting Queries (MDE, MDAV, Device Discovery)
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Sam's notes about enterprise IT with a focus on automation, design, and security. Frequent topics will include Microsoft Active Directory, Microsoft Defender XDR, Entra ID, Intune, Microsoft 365, PowerShell, and Windows Server.
Senior solutions analyst / engineer focused on Microsoft Active Directory, Entra ID, Defender XDR, Microsoft 365, and PowerShell. Always learning!
Add a description, image, and links to the defender-xdr topic page so that developers can more easily learn about it.
To associate your repository with the defender-xdr topic, visit your repo's landing page and select "manage topics."