ml58158 / defender-xdr-advanced-hunting
PublicA schema-aware dataset and Claude AI skill for Microsoft Defender XDR Advanced Hunting.
This repository provides a complete schema dataset for Microsoft Defender XDR Advanced Hunting tables, including undocumented ActionType enumerations and sample queries extracted from internal portal APIs and supplemented by public documentation.
How It Works
While searching for complete details on Microsoft Defender security tables, you find this helpful project that fills in the missing pieces.
You read how it uncovers hidden action types and full field lists that Microsoft doesn't share publicly, making threat hunting easier.
Log into your Defender dashboard, open the browser tools, and copy the full session details that prove you're actively signed in.
Paste your session details and team ID into the simple extraction tool and run it to pull everything from the portal.
Get ready-to-use files with every field, action type, sample searches, and retention info for all 61 tables.
Now craft precise security queries, guide AI helpers accurately, or train teams without guessing or hallucinations.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.