Threat hunting on Microsoft Defender XDR mapped to MITRE ATT&CK
I put together a collection of practical threat hunting and detection queries for:
- Microsoft Defender XDR (KQL)
The queries focus on real-world behaviors: LOLBins, suspicious process chains, persistence, credential access, lateral movement, C2 patterns, and some APT-style activity. Most are mapped to MITRE ATT&CK techniques and include short comments + tunable parameters.
Actively adding queries based on recent threat intel and campaigns. Feedback, suggestions for missing coverage, or contributions are very welcome.