This repository contains a comprehensive KQL library for Azure/M365, plus a ResourceScoped/ duplicate for every .kql that adds optional filtering by Azure resource (ResourceId, Name, Type, RG, Subscription, Location).
Generated: 20250826_121742
- Use Run-KQL-Library.ps1 to run:
- Normal Log Analytics/Sentinel queries (pick/search)
- Microsoft 365 Defender Advanced Hunting (Graph)
- Azure Resource Graph
.arg - Resource-Scoped KQL: pick a resource first, runner auto-fills tokens in
*.resource.kql
KQL-Library/<Pack>/*.kql– normal queriesKQL-Library/<Pack>/ResourceScoped/*.resource.kql– resource-scoped variantsRun-KQL-Library.ps1– interactive runnerPull-Library.ps1– update/pull script (git or zip)LICENSE– MITREADME.md/README.html.gitignorePacksIndex.json