Ross ROSS = Recommend OSS · open-source software intelligence for agents

microsoft/Microsoft-365-Defender-Hunting-Queries resource

Sample queries for Advanced hunting in Microsoft 365 Defender observed · 2026-08-28

github.com/microsoft/Microsoft-365-Defender-Hunting-Queries · Jupyter Notebook · MIT (permissive) · archived observed · 2026-08-28

Health v2 · maintenance only

10/100

  • Activity 0
  • Release rhythm 8
  • Longevity 100

Flags: archived

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-02. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 3090
  • days_rel: n/a
  • days_push: 1658
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

2087 stars · 570 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A collection of sample Kusto Query Language (KQL) hunting queries for Microsoft 365 Defender's Advanced Hunting feature, contributed by Microsoft and the community. The repository is deprecated and its content has moved to the unified Microsoft Sentinel / Microsoft 365 Defender community repo (Azure/Azure-Sentinel).

Use cases

  • find kql queries to hunt for threats in microsoft 365 defender
  • learn advanced hunting query syntax for defender
  • detect suspicious activity in m365 telemetry with ready-made queries
  • get example hunting queries for a security operations team
  • bootstrap threat hunting queries for microsoft sentinel

When to choose

  • you need reference KQL hunting queries for Microsoft 365 Defender or Sentinel
  • you want to learn advanced hunting query patterns from real examples

When to avoid

  • you want actively maintained queries - use the Azure/Azure-Sentinel community repo instead
  • you need hunting queries for non-Microsoft security products
  • you expect new releases or updates - this repo is deprecated

Facets

dataset · maturity abandoned

security search-engine developer-tools security developer-tools cloud self-hosted threat-hunting kusto-queries microsoft-365-defender deprecated sample-queries siem

1 source

Member repositories

For agents

markdown · JSON · MCP: product_card(name="microsoft/Microsoft-365-Defender-Hunting-Queries")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem