A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
-
Updated
Jun 3, 2026
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
Optimize system performance, clean unnecessary files, and manage Windows maintenance from one desktop application.
Project-SABER: A repository of KQL queries and parsers for threat hunting, threat detection, and log parsing in Microsoft Sentinel & Microsoft XDR (formerly Microsoft 365 Defender)
KQL-Queries 🐙 provides ready KQL scripts for Microsoft Defender XDR threat hunting, helping security teams detect, investigate, and respond to threats.
Disable Windows Defender real-time protection, tamper protection, and security components with this portable utility.
Disable Windows Defender Real-Time and Tamper Protection with this portable utility for troubleshooting and software installation.
Add a description, image, and links to the microsoft-xdr topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-xdr topic, visit your repo's landing page and select "manage topics."