# microsoft/Microsoft-365-Defender-Hunting-Queries

Sample queries for Advanced hunting in Microsoft 365 Defender

Repository: https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries
Canonical: https://ross.abutalabs.com/products/microsoft-365-defender-hunting-queries
Language: Jupyter Notebook
License: MIT
License Family: permissive
Topics: hunting, cybersecurity, sample-code
Archived: true
Last push: 2022-02-17T08:59:26+00:00

## Health v2 (maintenance only)
Score: 10/100 (v2, computed 2026-09-02T17:46:02.011165+00:00)
- activity 0, release rhythm 8, longevity 100
- inputs: {"age_days": 3090, "days_push": 1658, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: archived
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 2087, forks 570 (observed 2026-08-28T04:06:12.039189+00:00)

## What it is
A collection of sample Kusto Query Language (KQL) hunting queries for Microsoft 365 Defender's Advanced Hunting feature, contributed by Microsoft and the community. The repository is deprecated and its content has moved to the unified Microsoft Sentinel / Microsoft 365 Defender community repo (Azure/Azure-Sentinel).

## Use cases
- find kql queries to hunt for threats in microsoft 365 defender
- learn advanced hunting query syntax for defender
- detect suspicious activity in m365 telemetry with ready-made queries
- get example hunting queries for a security operations team
- bootstrap threat hunting queries for microsoft sentinel

## When to choose
- you need reference KQL hunting queries for Microsoft 365 Defender or Sentinel
- you want to learn advanced hunting query patterns from real examples

## When to avoid
- you want actively maintained queries - use the Azure/Azure-Sentinel community repo instead
- you need hunting queries for non-Microsoft security products
- you expect new releases or updates - this repo is deprecated

## Facets
- artifact type: dataset
- maturity: abandoned
- function: security, search-engine, developer-tools
- domain: security, developer-tools
- platform: cloud, self-hosted
- tags: threat-hunting, kusto-queries, microsoft-365-defender, deprecated, sample-queries, siem

## Member repositories
- microsoft/Microsoft-365-Defender-Hunting-Queries (main) score 10

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:06:12.039189+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T02:55:45.743893+00:00, confidence not recorded.
  - readme: https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries (fetched 2026-08-28T04:06:12.039189+00:00, sha 03a480aa0de3)
- Data as of 2026-08-30T08:39:29.467469+00:00.
