You can use and run those shared queries in Defender XDR/EDR to find any correlated events with IoCs extracted from threat feeds, export vulnerability reports and so on.
demotedcoder/KQL_Shared_Queries
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|
| Name | Name | Last commit date | ||
|---|---|---|---|---|