Ross ROSS = Recommend OSS · open-source software intelligence for agents

reprise99/Sentinel-Queries resource

Collection of KQL queries observed · 2026-08-28

github.com/reprise99/Sentinel-Queries · MIT (permissive) observed · 2026-08-28

Health v2 · maintenance only

61/100

  • Activity 64
  • Release rhythm 35
  • Longevity 100

Flags: no_releases

How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: n/a
  • age_days: 1851
  • days_rel: n/a
  • days_push: 217
  • n_releases_24m: 0

Full methodology

Adoption not part of the score

1645 stars · 382 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-30, confidence not recorded

A curated collection of KQL (Kusto Query Language) queries, tips, and tutorials for Microsoft Sentinel. It teaches how to write queries for threat hunting, detections, and anomaly analysis across Sentinel, Azure Monitor, and Log Analytics.

Use cases

  • learn KQL for Microsoft Sentinel
  • find threat hunting queries for Azure sign-in logs
  • write detection queries for security incidents
  • query Azure AD sign-in logs for anomalies
  • learn KQL where, project, and summarize operators
  • build SIEM detection rules with KQL

When to choose

  • you use Microsoft Sentinel or Azure Log Analytics and need example KQL queries
  • you are learning KQL syntax from basics to advanced
  • you need ready-made queries for threat hunting or detections

When to avoid

  • you use a SIEM other than Microsoft Sentinel
  • you need a runnable tool or application rather than query examples
  • you work with non-Azure log sources

Facets

learning-resource · maturity active

search-engine monitoring security developer-tools security developer-tools tutorials monitoring cloud self-hosted kql microsoft-sentinel siem threat-hunting query-collection azure

1 source

Member repositories

RepositoryRoleHealth v2
reprise99/Sentinel-Queriesmain61

For agents

markdown · JSON · MCP: product_card(name="reprise99/Sentinel-Queries")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem