Project-SABER: A repository of KQL queries and parsers for threat hunting, threat detection, and log parsing in Microsoft Sentinel & Microsoft XDR (formerly Microsoft 365 Defender)
-
Updated
Mar 18, 2026
Project-SABER: A repository of KQL queries and parsers for threat hunting, threat detection, and log parsing in Microsoft Sentinel & Microsoft XDR (formerly Microsoft 365 Defender)
Curated CTI investigations and queries
This repo contains, KQL, YARA, Sigma hunting and detection rules
Add a description, image, and links to the hunting-queries topic page so that developers can more easily learn about it.
To associate your repository with the hunting-queries topic, visit your repo's landing page and select "manage topics."