MDATP
-
Updated
Jul 20, 2024 - PowerShell
MDATP
Microsoft Defender XDR KQL detections for RedSun, BlueHammer, UnDefend, and CVE-2026-33825-related Defender abuse behaviors.
Maps Microsoft Defender XDR Schemas to a local Kustainer Data Explorer instance
10 hands-on Microsoft Security Operations Analyst SC-200 labs covering Defender XDR, Sentinel, Defender for Endpoint, data connectors, detections, analytics rules, MITRE ATT&CK, incident response, Purview, Entra ID, Graph logs, KQL threat hunting, playbooks, SOC metrics, and exam readiness.
Generate production-like Microsoft Defender XDR telemetry based on a YAML profile
SOC Analyst Portfolio | Microsoft Defender XDR | Threat Hunting | Incident Response | Active Directory | Entra ID
This repository contains demos and guides on how to setup Defender for Cloud. These demos are intended as a guide. For official guidance, support, or more detailed information, please refer to Microsoft's official documentation or contact Microsoft directly.
SOC-style cyber incident investigation using KQL, Microsoft Defender XDR, and threat intelligence to analyze phishing, malware execution, data exfiltration, and nation-state threat actors.
A collection of my KQL queries
Microsoft Security | Entra ID | Defender XDR | Security Operations
A curated list of high-quality resources focused on securing Microsoft cloud environments, including Identity (Entra ID), Microsoft 365, Microsoft Defender, Sentinel and Microsoft Purview.
Microsoft Defender XDR Advanced Hunting extension and investigation skills for pi
Detection-as-Code threat-hunting framework for Microsoft Defender XDR & Sentinel
Cloud-native identity compromise hunt in Microsoft Entra ID and Microsoft 365. Reconstructed a patient operator's session from a Low-rated anonymous IP alert through internal spearphishing, inbox rule persistence, and credential theft using Sentinel KQL.
Microsoft Defender XDR Action Types
Add a description, image, and links to the microsoft-defender-xdr topic page so that developers can more easily learn about it.
To associate your repository with the microsoft-defender-xdr topic, visit your repo's landing page and select "manage topics."