Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

NVISOsecurity/Detection-and-Hunting-Queries

Open more actions menu

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

52 Commits
52 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Detection and Hunting Queries

This repository contains detection and threat hunting queries created by NVISO’s CSIRT & SOC team. The queries are derived from handled incidents, threat hunts, trending threats, and other noteworthy activities observed in real-world investigations. While the queries currently focus on Microsoft Sentinel and Defender for Endpoint, the underlying platforms may change in the future. The primary goal is to share a core detection logic that you can fine tune or extend to your own unique environment.

The content can be used in any way you like, although a reference to @NVISO_Labs (X) or NVISOsecurity (GitHub) would be much appreciated.

License

Distributed under the MIT License. See LICENSE for more information.

Morty Proxy This is a proxified and sanitized view of the page, visit original site.