reprise99/Sentinel-Queries resource
Collection of KQL queries observed · 2026-08-28
Health v2 · maintenance only
61/100
- Activity 64
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 1851
- days_rel: n/a
- days_push: 217
- n_releases_24m: 0
Adoption not part of the score
1645 stars · 382 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded
A curated collection of KQL (Kusto Query Language) queries, tips, and tutorials for Microsoft Sentinel. It teaches how to write queries for threat hunting, detections, and anomaly analysis across Sentinel, Azure Monitor, and Log Analytics.
Use cases
- learn KQL for Microsoft Sentinel
- find threat hunting queries for Azure sign-in logs
- write detection queries for security incidents
- query Azure AD sign-in logs for anomalies
- learn KQL where, project, and summarize operators
- build SIEM detection rules with KQL
When to choose
- you use Microsoft Sentinel or Azure Log Analytics and need example KQL queries
- you are learning KQL syntax from basics to advanced
- you need ready-made queries for threat hunting or detections
When to avoid
- you use a SIEM other than Microsoft Sentinel
- you need a runnable tool or application rather than query examples
- you work with non-Azure log sources
Facets
learning-resource · maturity active
search-engine monitoring security developer-tools security developer-tools tutorials monitoring cloud self-hosted kql microsoft-sentinel siem threat-hunting query-collection azure
1 source
- readme: https://github.com/reprise99/Sentinel-Queries · fetched 2026-08-28 · 02ee6aae642d
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| reprise99/Sentinel-Queries | main | 61 |
For agents
markdown · JSON · MCP: product_card(name="reprise99/Sentinel-Queries")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem