Skip to content
#

microsoft-security

Here are 51 public repositories matching this topic...

A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).

  • Updated Oct 8, 2026

Open test set of .eml emails for checking how email security controls and AI mailbox assistants handle indirect prompt injection. It crosses three intents (system-prompt disclosure, data exfiltration, tool discovery) with three delivery methods (plaintext, hidden HTML, Base64), plus a benign control. All content is fictional and non-routable.

  • Updated Oct 2, 2026
  • Python

AD April ’26 Check0r is a read-only PowerShell tool to assess on-prem AD for the April 2026 Kerberos RC4→AES change. It inventories SPN accounts, flags risky msDS-SupportedEncryptionTypes/KDC overrides, and collects DC System readiness events (201–209) to predict breakage and guide fixes.

  • Updated Mar 19, 2026
  • PowerShell

MCADDF - A holistic operational framework bridging the gap between on-prem Active Directory and Cloud-native (Entra ID/Azure) security. This repository provides a structured library of verified attack vectors and detection logic, organized via the SERVTEP ID system and mapped to the current MITRE ATT&CK landscape. Curated by Pchelnikau Artur.

  • Updated Mar 2, 2026

Automated daily Microsoft Defender XDR security briefing delivered to Microsoft Teams using Azure Logic Apps, KQL Advanced Hunting, and Microsoft Graph.

  • Updated Aug 5, 2026

Add this topic to your repo

To associate your repository with the microsoft-security topic, visit your repo's landing page and select "manage topics."

Learn more