<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en-GB">
	<id>https://act.gcai.dev/index.php?action=history&amp;feed=atom&amp;title=KQL_Hunting_Queries_Detection_Rules</id>
	<title>KQL Hunting Queries Detection Rules - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://act.gcai.dev/index.php?action=history&amp;feed=atom&amp;title=KQL_Hunting_Queries_Detection_Rules"/>
	<link rel="alternate" type="text/html" href="https://act.gcai.dev/index.php?title=KQL_Hunting_Queries_Detection_Rules&amp;action=history"/>
	<updated>2026-05-08T06:17:53Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.3</generator>
	<entry>
		<id>https://act.gcai.dev/index.php?title=KQL_Hunting_Queries_Detection_Rules&amp;diff=13164&amp;oldid=prev</id>
		<title>Globalcyberalliance: Created via script</title>
		<link rel="alternate" type="text/html" href="https://act.gcai.dev/index.php?title=KQL_Hunting_Queries_Detection_Rules&amp;diff=13164&amp;oldid=prev"/>
		<updated>2024-07-04T03:00:33Z</updated>

		<summary type="html">&lt;p&gt;Created via script&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;=Description=&lt;br /&gt;
&lt;br /&gt;
The purpose of this repository is to share KQL queries that can be used by anyone and are understandable. These queries are intended to increase detection coverage through the logs of Microsoft Security products. Not all suspicious activities generate an alert by default, but many of those activities can be made detectable through the logs. These queries include Detection Rules, Hunting Queries and Visualisations. Anyone is free to use the queries. If you have any questions feel free to reach out to me on Twitter @BertJanCyber.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Presenting this material as your own is illegal and forbidden. A reference to Twitter @BertJanCyber or Github @Bert-JanP is much appreciated when sharing or using the content.&lt;br /&gt;
&lt;br /&gt;
=More Information=&lt;br /&gt;
&lt;br /&gt;
&amp;lt;b&amp;gt;URL:&amp;lt;/b&amp;gt; https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules/tree/main/Threat%20Hunting&lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Maintenance Status:&amp;lt;/b&amp;gt; Active &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Last Updated Date:&amp;lt;/b&amp;gt; &amp;lt; 1 year &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Formats Available:&amp;lt;/b&amp;gt; TXT &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Social Media Links:&amp;lt;/b&amp;gt; https://twitter.com/BertJanCyber | https://linkedin.com/in/bert-janpals &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Contact Information:&amp;lt;/b&amp;gt; Unknown &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;Single or Multiple:&amp;lt;/b&amp;gt; Multiple &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;b&amp;gt;License Information:&amp;lt;/b&amp;gt; BSD-3-Clause License - https://opensource.org/license/bsd-3-clause &lt;br /&gt;
&amp;lt;br&amp;gt;&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Feeds &amp;amp; Sources - T3C]]&lt;br /&gt;
[[Category:KQL]]&lt;br /&gt;
[[Category:Microsoft]]&lt;br /&gt;
[[Category:Threat Detection]]&lt;br /&gt;
[[Category:Threat Hunting]]&lt;br /&gt;
[[Category:Threat Visualization]]&lt;/div&gt;</summary>
		<author><name>Globalcyberalliance</name></author>
	</entry>
</feed>