XQL queries I use daily as an MDR analyst. Everything here is tested on live multi-tenant XSIAM environments.
threat-hunting/- endpoint and network hunting queriescve/- detections for specific CVEs and campaignsinventory/- AD profiles, host inventory, risky account scannersaudit/- case reports, permission audits, correlation rule viewsuncategorized/- everything else
Every query here is tested against real logs in live XSIAM environments. For detection queries (CVEs, campaigns, techniques) I reproduce the attack in a lab - run the exploit, execute the technique, then validate that the query catches it properly before publishing.
Some queries use $variables - XSIAM will prompt you to fill them in.
Feel free to grab whatever you need.