🔏
RootGuard
Ctrlk
HomeDFIRThreat DetectionHackingAI PromptsBlogs
  • Welcome
    • RootGuard
  • Resources Hub
    • Blogs
  • Learning Hub
    • Junior Analyst Skills
    • MITRE-Aligned Threat Dectection
    • Tools How-To
    • AI Prompts
  • Detection Engineering
    • Threat Detection
  • Defensive Security
    • DFIR
      • Initial Triage & Response
      • Window Forensics
      • Linux Forensics
      • Runbooks
      • Playbooks
        • PowerShell
        • Velociraptor
        • Zimmerman Tools
        • Volatility Vol3
        • Magnet AXIOM Cyber
        • KQL - Defender & Sentinel
          • MDO (Office)
          • MDI (Identity)
          • MDE (Endpoint)
          • Windows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheet
      • Malware Analysis
  • Offensive Security
    • Hacking
    • Attacking Active Directory (AD)
  • Prompt Engineering
Powered by GitBook
On this page
Edit
  1. Defensive Security
  2. DFIR
  3. Playbooks

KQL - Defender & Sentinel

MDO (Office)MDI (Identity)MDE (Endpoint)Windows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheet
PreviousAxiom Cyber ExaminerNextMDO (Office)