{"adoption": {"forks": 326, "observed_at": "2026-08-28T04:05:28.833750+00:00", "stars": 1732}, "canonical_url": "https://ross.abutalabs.com/products/hunting-queries-detection-rules", "card": {"archived": false, "artifact_type": "dataset", "description": "KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. ", "domain": ["security", "cloud-computing", "developer-tools"], "enriched": true, "function": ["security", "monitoring", "alerting", "developer-tools"], "health_score": 76, "homepage": "https://kqlquery.com", "language": "Python", "license": "BSD-3-Clause", "license_family": "permissive", "maturity": "active", "member_repos": ["Bert-JanP/Hunting-Queries-Detection-Rules"], "name": "Bert-JanP/Hunting-Queries-Detection-Rules", "platform": ["cloud", "self-hosted"], "pushed_at": "2026-07-23T17:56:56+00:00", "repo": "Bert-JanP/Hunting-Queries-Detection-Rules", "stars": 1732, "tags": ["kql", "microsoft-sentinel", "defender-for-endpoint", "threat-hunting", "detection-engineering", "dfir", "blue-team", "detection-rules"], "topics": ["azure", "defender-for-endpoint", "dfir", "kql", "sentinel", "threat-hunting", "vulnerability-management", "zero-day", "blueteam", "cybersecurity", "mde", "mdi", "infosec", "security", "misp"], "urls": [], "use_cases": ["find kql queries for microsoft sentinel hunting", "create custom detection rules in defender for endpoint", "improve soc detection coverage with out-of-the-box kql queries", "hunt for suspicious activity in mde logs", "write analytics rules for azure sentinel", "threat hunt for zero-day exploitation techniques", "build visualizations for security logs in kql"], "what_it_is": "A curated collection of KQL queries for Microsoft Defender for Endpoint and Azure Sentinel, covering advanced hunting, custom detections, analytics rules, and hunting rules. It is a community-maintained rule/query library aimed at increasing detection coverage from Microsoft security logs.", "when_to_avoid": ["you use SIEM/EDR products other than Microsoft's (e.g., Splunk, Elastic)", "you need a runnable tool or service rather than a query collection", "you need Sigma or YARA rules instead of KQL"], "when_to_choose": ["you use Microsoft Sentinel or Defender for Endpoint/XDR and need ready-made KQL detections", "you are a blue teamer or detection engineer expanding coverage beyond default alerts", "you need reference queries for incident response in Microsoft security products"]}, "data_as_of": "2026-08-30T08:39:29.467469+00:00", "members": [{"path": "/products/hunting-queries-detection-rules", "repo": "Bert-JanP/Hunting-Queries-Detection-Rules", "role": "main", "score": 75}], "provenance": {"archived": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "artifact_type": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "description": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "domain": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "enriched": {"inputs": [], "kind": "computed", "method": "enrichment_status"}, "function": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "health_score": {"inputs": ["days_since_push", "days_since_release", "archived"], "kind": "computed", "method": "health_v1"}, "homepage": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "language": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "license": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "license_family": {"inputs": ["license"], "kind": "computed", "method": "license_family"}, "maturity": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "member_repos": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "name": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "platform": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "pushed_at": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "repo": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "stars": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "tags": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "topics": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "urls": {"kind": "observed", "observed_at": "2026-08-28T04:05:28.833750+00:00", "source": "github"}, "use_cases": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "what_it_is": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "when_to_avoid": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}, "when_to_choose": {"confidence": null, "enriched_at": "2026-08-30T03:31:29.281933+00:00", "kind": "inferred", "prompt_version": 1, "sources": [{"content_hash": "b2b16108ed2ce42ee9965235e2ba9a59d48a4d79d9dd7605f15baf2860b1d025", "fetched_at": "2026-08-28T04:05:28.833750+00:00", "kind": "readme", "missing": false, "url": "https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules"}, {"content_hash": "47512d86cadafe04980696da37d056e9fe0ff80bc27a8f3fc34845dadfc7c1f4", "fetched_at": "2026-08-29T11:08:18.475802+00:00", "kind": "homepage", "missing": false, "url": "https://kqlquery.com"}], "taxonomy_version": 1}}, "score": {"components": {"activity": 94, "longevity": 100, "rhythm": 35}, "computed_at": "2026-09-03T02:20:16.233290+00:00", "flags": ["no_releases"], "formula": "round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)", "inputs": {"age_days": 1556, "days_push": 41, "days_rel": null, "gap_med": null, "n_releases_24m": 0}, "score": 75, "version": 2}, "staleness": {"enrichment_outdated": false, "low_confidence": false, "scrape_days": 9, "stale_scrape": false}}