MDATP
-
Updated
Jul 20, 2024 - PowerShell
MDATP
The purpose of this repository is to share KQL queries to help identify security misconfigurations, hunt for specific patterns, or detect malicious behavior
Automated daily Microsoft Defender XDR security briefing delivered to Microsoft Teams using Azure Logic Apps, KQL Advanced Hunting, and Microsoft Graph.
Extended version of Test-MdiReadiness.ps1 for Microsoft Defender for Identity: forest-wide scanning, required network port and NNR validation, sensor v3.x upgrade readiness, capacity estimation and a redesigned HTML report. Personal project, not an official Microsoft product.
Enterprise hybrid identity, endpoint management, and cloud security lab using Entra ID, Intune, Defender for Endpoint, AD DS, and Microsoft 365 E5.
Hands-on hybrid IAM lab covering the full identity lifecycle Entra Connect, JML automation, PIM, access governance, Zero Trust, ITDR with attack simulations, Application Proxy, Private Access, and workload identity federation.
A collection of Mitre ATT&CK aligned KQL detection, hunting, and audit queries for Defender XDR.
Bunch of Powershell scripts and tools
To associate your repository with the defender-for-identity topic, visit your repo's landing page and select "manage topics."