Skip to content
Back to the resource library
Free direct downloadMicrosoft 365Security

Microsoft Sentinel Detection Starter

Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.

No account and no email required. The optional email copy is available below.

How to use it

A working starting point, with the limits stated.

The useful part of a detection is not only the query. This pack pairs three KQL samples with the catalogue, tuning workflow, threat-hunt procedure and monthly review record needed to manage their lifecycle.

  1. Copy the files into an organisation-owned repository.
  2. Replace placeholders and name accountable owners.
  3. Review permissions, thresholds and approval points.
  4. Test in a controlled window and retain the evidence.

Scope note

Validate schemas, thresholds, data coverage and response ownership before enabling alerts.

Templates are operating aids. They are not certification, legal advice or a claim that a target environment is secure.

Want a copy in your inbox?

Optional email delivery makes the link easy to recover. You can download above without submitting anything.

This request does not subscribe you to the Ops Log newsletter.

Used only to fulfil this request. Read the privacy notice.

Published by Michal Jatczak under the ITSailor trading brand.Verify the ZIP manifest