🔏
RootGuard
Ctrlk
HomeSOC OperationsIncident ResponseWindows ForensicsLinux ForensicsKQL Investigations
  • Welcome
    • RootGuard
  • Resources Hub
    • Blogs
  • Learning Hub
    • Learning & Development
  • Defensive Security
    • Digital Forensics & Incident Response (DFIR)
    • DFIR Runbooks
    • DFIR Playbooks
      • PowerShell
      • Velociraptor
      • Zimmerman Tools
      • Volatility Vol3
      • Magnet AXIOM Cyber
      • KQL - Defender & Sentinel
        • MDO (Office)
        • MDI (Identity)
        • MDE (Endpoint)
        • Windows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheet
    • Malware Analysis Workflow & Cheatsheet for SOC Analysts
  • Detection Engineering
    • SOC Detection Engineer
  • Offensive Security
    • Penetration Testing (Pentesting)
Powered by GitBook
On this page
Edit
  1. Defensive Security
  2. DFIR Playbooks

KQL - Defender & Sentinel

MDO (Office)MDI (Identity)MDE (Endpoint)Windows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheet
PreviousAxiom Cyber ExaminerNextMDO (Office)