A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
-
Updated
Feb 18, 2026
A curated list of resources for DFIR through Microsoft Defender for Endpoint leveraging kusto queries, powershell scripts, tools such as KAPE and THOR Cloud and more.
Random Powershell scripts
A browser-based Microsoft Defender for Endpoint audit tracker for MSSP security engineers, mapping ~270 tasks across multiple frameworks including — NIST CSF 2.0, Cyber Essentials, SOC 2, and NIST 800-53. Features per-task status, notes, live progress metrics, framework switching, dark/light mode, and CSV, HTML, and JSON export.
Hands-on threat hunting and SOC investigations using Microsoft Defender for Endpoint and KQL. Real scenarios covering brute force detection, lateral movement, and IOC analysis mapped to MITRE ATT&CK.
A parser for Microsoft Defender for Endpoint (MDE) Investigation Packages.
Enterprise Microsoft Purview Data Loss Prevention implementation — standard and custom Sensitive Information Types, Endpoint DLP via Microsoft Defender, Generative AI site restriction, and Simulation-to-Enforcement rollout.
Continuous Threat & Vulnerability Management (TVM) using Microsoft Defender for Endpoint — risk-based exposure scoring, CVE prioritisation, ASR rule deployment, and PUA protection via Intune.
A collection of hands‑on labs demonstrating real-world threat hunting with Microsoft Defender for Endpoint (MDE)
Jamf Pro Extension Attributes and shell scripts for macOS fleet management — MDE health monitoring, app lifecycle, user permissions, LDAP lookups, system configuration, and more.
Enterprise integration of Microsoft Defender for Cloud Apps (MDCA) with Microsoft Defender for Endpoint (MDE) — Shadow IT detection, OAuth app governance, and SaaS security posture management across a 31,000+ app catalogue.
Threat hunt for unauthorized TOR browser installation and use on a workstation using Microsoft Defender for Endpoint and KQL. Traces file, process, and network evidence with a full timeline, mapped to MITRE ATT&CK.
Threat hunt for brute force login attempts against internet-exposed VMs using Microsoft Defender for Endpoint and KQL. Maps findings to MITRE ATT&CK T1110.
A curated list of high-quality resources focused on securing Microsoft cloud environments, including Identity (Entra ID), Microsoft 365, Microsoft Defender, Sentinel and Microsoft Purview.
Public branch of Atea Ansible module, soon to be available from the Atea GitHub organization
Find potential local privilege escalation on windows with KQL
Generate production-like Microsoft Defender XDR telemetry based on a YAML profile
A browser-based Microsoft Defender for Endpoint deployment tracker for MSSP security engineers, mapping 57 actionable tasks across all 6 NIST CSF 2.0 functions. Features per-task status tracking, notes, live progress metrics, dark/light mode, and full export support in CSV, HTML report, and JSON config formats.
The server team reported network performance degradation on older devices in the internal network.
Detection queries, OAuth permission risk matrix, and AI tool risk assessment checklist for measuring shadow AI and approved-software risk in enterprise environments. Validated on Microsoft Defender for Endpoint (KQL) and Rapid7 InsightIDR (LEQL). Released alongside DEF CON 34 talk "The Software Request Trap."
Threat hunt for insider data exfiltration on a corporate endpoint using Microsoft Defender for Endpoint and KQL. Traces archive activity to file and network events, mapped to MITRE ATT&CK.
To associate your repository with the microsoft-defender-for-endpoint topic, visit your repo's landing page and select "manage topics."