#
leql
Here are 2 public repositories matching this topic...
Detection queries, OAuth permission risk matrix, and AI tool risk assessment checklist for measuring shadow AI and approved-software risk in enterprise environments. Validated on Microsoft Defender for Endpoint (KQL) and Rapid7 InsightIDR (LEQL). Released alongside DEF CON 34 talk "The Software Request Trap."
oauth threat-hunting defcon soc mde security-tools detection-rules blue-team rapid7 mitre-attack ai-security insightidr kql detection-engineering microsoft-defender-for-endpoint shadow-ai defcon34 leql
-
Updated
Apr 30, 2026
Improve this page
Add a description, image, and links to the leql topic page so that developers can more easily learn about it.
Add this topic to your repo
To associate your repository with the leql topic, visit your repo's landing page and select "manage topics."