MDATP
-
Updated
Jul 20, 2024 - PowerShell
MDATP
Assess, convert and deploy Microsoft Sentinel analytics rules as Defender XDR custom detections
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
M365 PowerShell scripts for Microsoft 365 administration: Intune, Entra ID, Defender, Exchange Online, Purview, Teams, SharePoint and tenant management. Microsoft Graph and modern modules only, read-only by default, -WhatIf on every change, full comment-based help.
Maps Microsoft Defender XDR Schemas to a local Kustainer Data Explorer instance
Generate production-like Microsoft Defender XDR telemetry based on a YAML profile
A collection of my KQL queries
SOC-style cyber incident investigation using KQL, Microsoft Defender XDR, and threat intelligence to analyze phishing, malware execution, data exfiltration, and nation-state threat actors.
Microsoft Defender XDR Advanced Hunting extension and investigation skills for pi
SOC Analyst Portfolio | Microsoft Defender XDR | Threat Hunting | Incident Response | Active Directory | Entra ID
Rust MCP server for Microsoft Defender XDR and Defender for Endpoint: 88 tools for hunting, threat intelligence, vulnerability management, and gated response.
Microsoft Security | Entra ID | Defender XDR | Security Operations
Detection-as-Code threat-hunting framework for Microsoft Defender XDR & Sentinel
Cloud-native identity compromise hunt in Microsoft Entra ID and Microsoft 365. Reconstructed a patient operator's session from a Low-rated anonymous IP alert through internal spearphishing, inbox rule persistence, and credential theft using Sentinel KQL.
This repository contains demos and guides on how to setup Defender for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.
A curated list of high-quality resources focused on securing Microsoft cloud environments, including Identity (Entra ID), Microsoft 365, Microsoft Defender, Sentinel and Microsoft Purview.
Microsoft Defender XDR
Microsoft Defender XDR Action Types
To associate your repository with the microsoft-defender-xdr topic, visit your repo's landing page and select "manage topics."