SecLists, but for M365 defenders — paste-ready, ATT&CK-mapped KQL threat-hunting queries + IOC lists for Entra ID, Intune & Microsoft 365 (Defender XDR & Sentinel).

advanced-hunting bec blue-team detection-as-code detection-engineering dfir entra-id incident-response intune kql m365 microsoft-365 microsoft-defender microsoft-sentinel mitre-attack powershell security soc threat-hunting
4 Open Issues Need Help Last updated: Aug 4, 2026

Open Issues Need Help

View All on GitHub
documentation good first issue

SecLists, but for M365 defenders — paste-ready, ATT&CK-mapped KQL threat-hunting queries + IOC lists for Entra ID, Intune & Microsoft 365 (Defender XDR & Sentinel).

#advanced-hunting#bec#blue-team#detection-as-code#detection-engineering#dfir#entra-id#incident-response#intune#kql#m365#microsoft-365#microsoft-defender#microsoft-sentinel#mitre-attack#powershell#security#soc#threat-hunting

SecLists, but for M365 defenders — paste-ready, ATT&CK-mapped KQL threat-hunting queries + IOC lists for Entra ID, Intune & Microsoft 365 (Defender XDR & Sentinel).

#advanced-hunting#bec#blue-team#detection-as-code#detection-engineering#dfir#entra-id#incident-response#intune#kql#m365#microsoft-365#microsoft-defender#microsoft-sentinel#mitre-attack#powershell#security#soc#threat-hunting
help wanted detection

SecLists, but for M365 defenders — paste-ready, ATT&CK-mapped KQL threat-hunting queries + IOC lists for Entra ID, Intune & Microsoft 365 (Defender XDR & Sentinel).

#advanced-hunting#bec#blue-team#detection-as-code#detection-engineering#dfir#entra-id#incident-response#intune#kql#m365#microsoft-365#microsoft-defender#microsoft-sentinel#mitre-attack#powershell#security#soc#threat-hunting
help wanted good first issue ioc

SecLists, but for M365 defenders — paste-ready, ATT&CK-mapped KQL threat-hunting queries + IOC lists for Entra ID, Intune & Microsoft 365 (Defender XDR & Sentinel).

#advanced-hunting#bec#blue-team#detection-as-code#detection-engineering#dfir#entra-id#incident-response#intune#kql#m365#microsoft-365#microsoft-defender#microsoft-sentinel#mitre-attack#powershell#security#soc#threat-hunting