# reprise99/Sentinel-Queries

Collection of KQL queries

Repository: https://github.com/reprise99/Sentinel-Queries
Canonical: https://ross.abutalabs.com/products/sentinel-queries
License: MIT
License Family: permissive
Last push: 2026-01-29T01:28:08+00:00

## Health v2 (maintenance only)
Score: 61/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 64, release rhythm 35, longevity 100
- inputs: {"age_days": 1851, "days_push": 217, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1645, forks 382 (observed 2026-08-28T04:05:16.232562+00:00)

## What it is
A curated collection of KQL (Kusto Query Language) queries, tips, and tutorials for Microsoft Sentinel. It teaches how to write queries for threat hunting, detections, and anomaly analysis across Sentinel, Azure Monitor, and Log Analytics.

## Use cases
- learn KQL for Microsoft Sentinel
- find threat hunting queries for Azure sign-in logs
- write detection queries for security incidents
- query Azure AD sign-in logs for anomalies
- learn KQL where, project, and summarize operators
- build SIEM detection rules with KQL

## When to choose
- you use Microsoft Sentinel or Azure Log Analytics and need example KQL queries
- you are learning KQL syntax from basics to advanced
- you need ready-made queries for threat hunting or detections

## When to avoid
- you use a SIEM other than Microsoft Sentinel
- you need a runnable tool or application rather than query examples
- you work with non-Azure log sources

## Facets
- artifact type: learning-resource
- maturity: active
- function: search-engine, monitoring, security, developer-tools
- domain: security, developer-tools, tutorials, monitoring
- platform: cloud, self-hosted
- tags: kql, microsoft-sentinel, siem, threat-hunting, query-collection, azure

## Member repositories
- reprise99/Sentinel-Queries (main) score 61

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:16.232562+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:45:25.783277+00:00, confidence not recorded.
  - readme: https://github.com/reprise99/Sentinel-Queries (fetched 2026-08-28T04:05:16.232562+00:00, sha 02ee6aae642d)
- Data as of 2026-08-30T08:39:29.467469+00:00.
