32 production-quality KQL detection rules for Microsoft Sentinel, mapped to MITRE ATT&CK for Cloud, credential access, lateral movement, exfiltration, defense evasion, and more
azure threat-modeling devsecops threat-intelligence detection-rules blue-team mitre-attack threat-detection kql detection-engineering mitre-attack-framework microsoft-sentinel mitre-attack-cloud-security microsoft-sentinel-workbook microsoft-sentinel-kql
-
Updated
Aug 1, 2026