MDATP
- 
            Updated
            Jul 20, 2024 
- PowerShell
MDATP
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Bunch of Powershell scripts and tools
A collection of Mitre ATT&CK aligned KQL detection, hunting, and audit queries for Defender XDR.
Add a description, image, and links to the defender-for-identity topic page so that developers can more easily learn about it.
To associate your repository with the defender-for-identity topic, visit your repo's landing page and select "manage topics."