Skip to content
#

microsoft-defender-xdr

Here are 15 public repositories matching this topic...

10 hands-on Microsoft Security Operations Analyst SC-200 labs covering Defender XDR, Sentinel, Defender for Endpoint, data connectors, detections, analytics rules, MITRE ATT&CK, incident response, Purview, Entra ID, Graph logs, KQL threat hunting, playbooks, SOC metrics, and exam readiness.

  • Updated Jul 6, 2026

This repository contains demos and guides on how to setup Defender for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.

  • Updated Aug 3, 2026

A curated list of high-quality resources focused on securing Microsoft cloud environments, including Identity (Entra ID), Microsoft 365, Microsoft Defender, Sentinel and Microsoft Purview.

  • Updated May 24, 2026

Cloud-native identity compromise hunt in Microsoft Entra ID and Microsoft 365. Reconstructed a patient operator's session from a Low-rated anonymous IP alert through internal spearphishing, inbox rule persistence, and credential theft using Sentinel KQL.

  • Updated Jun 23, 2026

Improve this page

Add a description, image, and links to the microsoft-defender-xdr topic page so that developers can more easily learn about it.

Curate this topic

Add this topic to your repo

To associate your repository with the microsoft-defender-xdr topic, visit your repo's landing page and select "manage topics."

Learn more