End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
-
Updated
Jul 29, 2026
End-to-end Microsoft Sentinel SOC lab: KQL detections and threat hunts for SSH brute force (T1110) and malicious PowerShell (T1059.001).
Awesome Kusto Query Language (KQL)
SOC Phishing Email Investigation & Automated Response using Microsoft Sentinel, KQL, MITRE ATT&CK and SOAR, N8N
Hybrid SIEM evaluation — Microsoft Sentinel + KQL, live-compared against an existing Wazuh SOC lab
Data Analyst
Information Security Analyst
Application of the HITS Threat Hunting Framework incorporating agentic AI for delivery across Sentinel, Defender and the wider Microsoft ecosystem
Microsoft Sentinel KQL detection rules — MITRE ATT&CK for Cloud IaaS
To associate your repository with the kql-microsoft-sentinel topic, visit your repo's landing page and select "manage topics."