microsoft/Microsoft-365-Defender-Hunting-Queries resource
Sample queries for Advanced hunting in Microsoft 365 Defender observed · 2026-08-28
Health v2 · maintenance only
10/100
- Activity 0
- Release rhythm 8
- Longevity 100
Flags: archived
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 3090
- days_rel: n/a
- days_push: 1658
- n_releases_24m: 0
Adoption not part of the score
2087 stars · 570 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A collection of sample Kusto Query Language (KQL) hunting queries for Microsoft 365 Defender's Advanced Hunting feature, contributed by Microsoft and the community. The repository is deprecated and its content has moved to the unified Microsoft Sentinel / Microsoft 365 Defender community repo (Azure/Azure-Sentinel).
Use cases
- find kql queries to hunt for threats in microsoft 365 defender
- learn advanced hunting query syntax for defender
- detect suspicious activity in m365 telemetry with ready-made queries
- get example hunting queries for a security operations team
- bootstrap threat hunting queries for microsoft sentinel
When to choose
- you need reference KQL hunting queries for Microsoft 365 Defender or Sentinel
- you want to learn advanced hunting query patterns from real examples
When to avoid
- you want actively maintained queries - use the Azure/Azure-Sentinel community repo instead
- you need hunting queries for non-Microsoft security products
- you expect new releases or updates - this repo is deprecated
Facets
dataset · maturity abandoned
security search-engine developer-tools security developer-tools cloud self-hosted threat-hunting kusto-queries microsoft-365-defender deprecated sample-queries siem
1 source
- readme: https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries · fetched 2026-08-28 · 03a480aa0de3
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| microsoft/Microsoft-365-Defender-Hunting-Queries | main | 10 |
For agents
markdown · JSON · MCP: product_card(name="microsoft/Microsoft-365-Defender-Hunting-Queries")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem