🔏
RootGuard
search
⌘Ctrlk
Defensive Securitychevron-downDetection Engineeringchevron-downOffensive Securitychevron-downAI Securitychevron-downResource Basechevron-downAbout Uschevron-down
🔏
RootGuard
  • Welcome
    • RootGuard
  • Resources Hub
    • Blogs
    • Tool Arsenal
  • Knowledge Base
    • Junior Analyst Skills
    • MITRE-Aligned Threat Dectection
    • Tools How-To
  • Detection Engineering
    • Threat Detection
  • Defensive Security
    • DFIR
      • Initial Triage & Response
      • Window Forensics
      • Linux Forensics
      • Runbooks
      • Playbooks
        • PowerShell
        • Velociraptor
        • Zimmerman Tools
        • Volatility Vol3
        • Magnet AXIOM Cyber
        • KQL - Defender & Sentinel
          • MDO (Office)
          • MDI (Identity)
          • MDE (Endpoint)
          • Windows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheet
      • Malware Analysis
  • Offensive Security
    • Hacking
    • Attacking Active Directory (AD)
  • AI Security
    • AI Security & Governance
    • Prompt Engineering
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
githubEdit
  1. Defensive Securitychevron-right
  2. DFIRchevron-right
  3. Playbooks

KQL - Defender & Sentinel

MDO (Office)chevron-rightMDI (Identity)chevron-rightMDE (Endpoint)chevron-rightWindows AD Attack Investigation – Defender & Sentinel KQL Cheat Sheetchevron-right
PreviousAxiom Cyber Examinerchevron-leftNextMDO (Office)chevron-right