
Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK techniques to surface APT behaviors, persistence, lateral movement, and C2 activity.
Collection of threat hunting and detection queries for:
Aimed at surfacing suspicious processes, anomalous network behaviors, living-off-the-land binaries (LOLBins), persistence mechanisms, credential access, lateral movement, C2 activity, and potential APT behaviors. All mapped to MITRE ATT&CK techniques where applicable.
Queries are updated based on recent threat intelligence reports, emerging campaigns, and real-world observations.
/CrowdStrike/ → CQL queries for Falcon Insight / LogScale / Next-Gen SIEM hunting/KQL/ → KQL queries for Microsoft Defender for Endpoint, Defender XDR, and SentinelMost queries include:
Free to use/modify/share (attribution appreciated).
Made with ❤️ by Awais Munir
Questions? Open an issue or reach out on LinkedIn.