Thank you for taking the time to contribute to Awesome Microsoft Security! Please read through these guidelines before submitting a pull request.
- Search existing entries and open issues before submitting to avoid duplicates.
- Only suggest resources you have personally used or can vouch for. This is a curated list, not a directory.
- Resources should be actively maintained. Avoid linking to archived repos, deprecated tools, or documentation that is no longer updated.
- Official Microsoft documentation is welcome, but community resources (blogs, tools, repos, videos) must bring clear practical value beyond what the docs already cover.
All entries must follow this format:
- [Resource Name](https://example.com) - A concise description of what it is and why it is valuable.
- The link and description are separated by a dash and a space.
- The description starts with an uppercase letter and ends with a period.
- Keep descriptions concise — one sentence is usually enough.
- Use the official, canonical name of the resource (e.g.
Microsoft Defender for Endpoint, notMDEorDefender EP).
- The resource fits an existing section, or you have included a clearly justified new section.
- The entry follows the format above.
- The description starts with an uppercase letter and ends with a period.
- There are no spelling or grammar errors.
- The linked resource is accessible, in English, and not behind a paywall or login wall.
- The resource has been available and stable for at least 30 days.
- To confirm you have read these guidelines, include the word
unicornsomewhere in your pull request description.
If you find a broken link, outdated resource, or entry that no longer meets the quality bar, please open an issue with the title [fix] <resource name> and a short explanation.
Be respectful and constructive. Contributions that are disrespectful, spam, or promotional will be closed without review.