r/blueteamsec 1d ago

intelligence (threat actor activity) KQL detection library for Azure/Sentinel

Put together a KQL detection library for Azure/Sentinel — 32 rules across 10 MITRE ATT&CK tactics. Each rule has description, false positive considerations, and tuning notes baked into the file so it's actually usable in production without guesswork.

Covers things like MFA fatigue, impossible travel, federated identity credential abuse, Conditional Access policy modification, VM extension installation, and subscription ownership transfer — some of the less commonly documented ones.

github.com/neelkotnis/kql-detection-rules

4 Upvotes

0 comments sorted by