Every query in the library indexed by MITRE ATT&CK tactic and technique, by actor / malware family (where the write-up named one), by platform and data source, and by whether a KQL Detection of the Week Deep Dive article walks through its design. Pills are sorted by how many queries carry them.
MITRE Tactics 13
MITRE Techniques 54
T10786
T10055
T1110.0035
T11904
T15674
T1195.0023
T1552.0013
T1562.0083
T1566.0023
T10272
T1036.0052
T10592
T1059.0012
T10712
T1071.0012
T1071.0042
T1078.0042
T1098.0032
T11052
T15312
T15462
T15502
T1550.0012
T1552.0052
T1566.0012
T1574.0022
T1021.0011
T1021.0021
T1027.0011
T1027.0041
T1027.0101
T10291
T1048.0031
T10831
T10981
T11021
T11101
T1110.0011
T1110.0041
T1132.0011
T1137.0061
T12041
T1204.0021
T15281
T15391
T15471
T15561
T15661
T1566.0031
T1567.0021
T1583.0061
T1590.0051
T1595.0021
T16511
Actors 9
Platforms 14
Data Sources 29
SecurityEvent18
Usage15
CommonSecurityLog9
DeviceProcessEvents9
SigninLogs8
pihole_CL8
DeviceFileEvents7
DeviceNetworkEvents7
EmailEvents6
OfficeActivity6
SecurityAlert6
AuditLogs4
_Im_WebSession4
AzureActivity3
Syslog3
AADNonInteractiveUserSignInLogs2
AzureDiagnostics2
DeviceImageLoadEvents2
DnsEvents2
WindowsEvent2
AutoGenStudio_CL1
DeviceInfo1
DeviceLogonEvents1
DeviceNetworkInfo1
DeviceTvmSoftwareInventory1
DeviceTvmSoftwareVulnerabilities1
EmailAttachmentInfo1
SecurityIncident1
UrlClickEvents1