Security Analytics

KQL Search

KQL Search is a curated, searchable database of Kusto Query Language (KQL) queries specifically designed for cybersecurity professionals and threat hunters. It provides ready-to-use queries for Azure, Microsoft Defender, Entra ID, and other Microsoft security services, helping security teams quickly find and implement the queries they need.

Key Features
Everything this tool offers to make your Intune management easier
Extensive collection of curated security queries
Filter by table, author, category, and keywords
Covers Azure, Defender, Entra ID, and more
Copy queries with one click
Community contributions welcome
Regular updates with new queries
Common Use Cases
Real-world scenarios where this tool can help

Threat Hunting

Quickly find and execute pre-built KQL queries to hunt for specific threats or suspicious activities in your environment.

Security Investigation

Access proven queries for investigating security incidents across Azure, Defender, and Entra ID logs.

Learning KQL

Learn KQL syntax and best practices by studying and modifying real-world security queries.

Requirements
What you need to get started with this tool
  • 1
    Web browser
  • 2
    Access to Microsoft security services (for query execution)
  • 3
    Basic understanding of KQL

Platform

Web

Hosting

Web

Status

Actively Maintained

Ready to get started?

Download or access KQL Search and start optimizing your Intune management today.