Skip to main content
MS Defender Advanced Hunting app icon

MS Defender Advanced Hunting

This add-on enables Microsoft Defender Advanced Hunting (KQL) queries directly from Splunk search commands.Built by Masaki Yoshikawa
splunk product badge

Default Version 0.2.6

August 8, 2026

Compatibility

Splunk Enterprise, Splunk Cloud

Platform Version: 10.2, 10.1, 10.0, 9.4, 9.3

Rating
5
(5)

Log in to rate this app

Support
Developer Supported
Ranking

#24 in Investigative

This add-on enables Advanced Hunting queries (KQL) against Microsoft Defender APIs directly from Splunk search commands. Microsoft provides three APIs for Advanced Hunting: - Microsoft Defender for Endpoint - Microsoft Defender XDR - Microsoft Graph REST API This add-on automatically detects which API endpoint your credentials are authorized to access. If credentials for multiple APIs are available, **Microsoft Defender for Endpoint** is prioritized. - [Microsoft Defender for Endpoint](https://learn.microsoft.com/en-us/defender-endpoint/microsoft-defender-endpoint?view=o365-worldwide)