MDATP
-
Updated
Jul 20, 2024 - PowerShell
MDATP
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
A collection of Mitre ATT&CK aligned KQL detection, hunting, and audit queries for Defender XDR.
Add a description, image, and links to the defender-for-cloud-apps topic page so that developers can more easily learn about it.
To associate your repository with the defender-for-cloud-apps topic, visit your repo's landing page and select "manage topics."