KQL Library / Posture
Posture
Attack-surface and asset-posture queries — the inventory-style queries that hand you a finite, closable list rather than an infinite stream of adversary telemetry.
-
Inventory Exposed Spring Boot Actuator Endpoints
inventory-exposed-spring-boot-actuator-endpoints.kqlInventory of Spring Boot Actuator endpoints that answer 200 anywhere in your estate — flips the entity from "who scanned us" (infinite) to "which of my services answer" (finite and fixable). Recovers the real management base path from traffic.
-
Inventory Installed Npm Packages With Lifecycle Scripts
inventory-installed-npm-packages-with-lifecycle-scripts.kqlInventory of npm packages installed across your fleet that carry postinstall / preinstall / install lifecycle scripts — the finite, closable population for sins-of-the-grandfather class attacks.
-
Which Devices Are Internet Facing
which-devices-are-internet-facing.kqlIdentify internet-facing devices — walks through what "public" actually means for both IPv4 and IPv6 before matching.
-
Which Devices Or Software Are EOL
which-devices-or-software-are-eol.kqlDevices running at least one end-of-support / end-of-life software title or version, from `DeviceTvmSoftwareInventory`.