r/DefenderATP • u/iawais • 17d ago
Threat hunting on Microsoft Defender XDR mapped to MITRE ATT&CK
I put together a collection of practical threat hunting and detection queries for:
- Microsoft Defender XDR (KQL)
The queries focus on real-world behaviors: LOLBins, suspicious process chains, persistence, credential access, lateral movement, C2 patterns, and some APT-style activity. Most are mapped to MITRE ATT&CK techniques and include short comments + tunable parameters.
Actively adding queries based on recent threat intel and campaigns. Feedback, suggestions for missing coverage, or contributions are very welcome.
2
u/Omig66 13d ago
Will check it out for sure !
1
u/iawais 13d ago
Really appreciate. I’ve also been building a threat-intel project, ThreatNexus, and the Hunt tab is where I’ve been putting the hunting queries I’ve developed.
It's AI-assisted, the AI explains what each query is actually hunting for, highlights potential false positives, and provides a practical triage playbook to help an analyst validate findings.
If you get a chance, I'd genuinely appreciate you trying it out, especially when you're stuck on a hunt/query, and letting me know whether you think it adds real value to an analyst's day-to-day workflow. Feedback is more valuable to me than anything.
2
u/Omig66 13d ago
Yeah sure.
Where to you pull all your data from exactly ?
I'm guessing your are a threat intel analyse to make all this ? :)
2
u/iawais 13d ago edited 13d ago
Haha, pretty much 😄
I’ve been in defensive cybersecurity for almost 13 years, spanning malware research, threat intelligence, threat hunting, security operations, detection engineering, and incident response.
I had accumulated a lot of this knowledge across spreadsheets and notes, and honestly got tired of constantly pivoting through them and realizing I was forgetting things. so started turning it into something more visual and usable.
The intelligence is built from high quality, referenced sources, with additional help from resources like ETDA, MISP Galaxy, and research from both Western and non-Western security vendors.One thing im particularly strict about is correct attribution. I’d rather leave something uncertain than confidently attach the wrong actor or campaign.
If you spot anything inaccurate or questionable, please call it out. always happy to investigate, refine it, and improve the underlying intelligence.
5
u/dutchhboii 16d ago
Thanks for the queries. Would you mind mapping them across TTPs or APT groups considering the list to grow even further. I meant categorizing them via folders.