Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Threat-Hunting — Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK techniques to surface APT behaviors, persistence, lateral movement, and C2 activity. | Kitploit
Tools/GitHubGitHub/a2awais/threat-hunting
ReconnaissanceInformation GatheringThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseLog Analysis
GitHuba2awais/threat-hunting

Threat-Hunting

Curated collection of threat hunting and detection queries for CrowdStrike Falcon (CQL) and Microsoft Defender XDR (KQL), mapped to MITRE ATT&CK techniques to surface APT behaviors, persistence, lateral movement, and C2 activity.

View Repository
8097 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

Threat-Hunting | Detection Engineering

Collection of threat hunting and detection queries for:

  • CrowdStrike Falcon (using CQL – CrowdStrike Query Language)
  • Microsoft Defender XDR (using KQL – Kusto Query Language)

Aimed at surfacing suspicious processes, anomalous network behaviors, living-off-the-land binaries (LOLBins), persistence mechanisms, credential access, lateral movement, C2 activity, and potential APT behaviors. All mapped to MITRE ATT&CK techniques where applicable.

Queries are updated based on recent threat intelligence reports, emerging campaigns, and real-world observations.

What's Inside

  • /CrowdStrike/ → CQL queries for Falcon Insight / LogScale / Next-Gen SIEM hunting
  • /KQL/ → KQL queries for Microsoft Defender for Endpoint, Defender XDR, and Sentinel

Most queries include:

  • MITRE ATT&CK mapping
  • Brief comments for use-case
  • Tunable parameters (time windows, thresholds, exclusions)

License

Free to use/modify/share (attribution appreciated).

Made with ❤️ by Awais Munir

Questions? Open an issue or reach out on LinkedIn.

Download Tool