Open Source · MIT License

KQL query library for SOC teams

Centralized KQL management with MITRE ATT&CK mapping, PICERL phases, team sharing, and passkey authentication. Built for Microsoft Defender and Azure Sentinel analysts.

detect-pass-spray.kql
T1110.003 Identify High
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType == "50126"
| summarize
    FailedAttempts = count(),
    TargetedUsers  = dcount(UserPrincipalName),
    Locations      = make_set(Location)
    by IPAddress
| where TargetedUsers > 5
      and FailedAttempts > 20
| order by FailedAttempts desc
// Password spray pattern detected
14
MITRE ATT&CK Tactics
6
PICERL Phases
3
Role Levels
0
Passwords Required
Capabilities

Everything a SOC team needs

Built for analysts who live in KQL. Not a generic note app — purpose-built for detection engineering.

🎯

MITRE ATT&CK Mapping

Tag queries with tactics and techniques. Filter your library by ATT&CK coverage gaps.

🔍

PICERL Framework

Map queries to Prepare, Identify, Contain, Eradicate, Recover, Lessons Learned phases.

👥

Team Sharing

Scoped to teams. Personal and shared folders. Three roles: Admin, Analyst, Viewer.

🔑

Passkey Auth

WebAuthn/FIDO2 only — no passwords, no OAuth dependencies. Works offline once enrolled.

✏️

Monaco KQL Editor

Full KQL syntax highlighting powered by Monaco (VS Code's editor). Auto-complete, bracket matching.

📦

Docker Ready

Multi-stage Dockerfile included. Single docker compose up to deploy.

📊

Severity Tracking

Critical / High / Medium / Low / Info severity per query. Filter by severity in the library.

🔐

Encrypted at Rest

AES-256-GCM on all sensitive fields. scrypt key derivation. Session tokens stored as HMAC hashes.

📁

Folder Organization

Hierarchical folders, personal vs team scope. Bulk JSON import for migrating existing libraries.

ATT&CK Coverage

Map detection gaps visually

See at a glance which ATT&CK tactics your query library covers — and where you have blind spots.

TA0001 · Initial Access TA0002 · Execution TA0003 · Persistence TA0004 · Privilege Escalation TA0005 · Defense Evasion TA0006 · Credential Access TA0007 · Discovery TA0008 · Lateral Movement TA0009 · Collection TA0010 · Exfiltration TA0011 · Command & Control TA0040 · Impact
Live Demo

Try it without installing anything

Public demo instance with pre-loaded sample queries. No sign-up required — use the demo login button.

Demo data resets periodically. Do not store real queries or credentials.
🚀
Public Demo Instance
Hosted on Railway · Free tier · Resets on restart · HTTPS

Click the button below to open the live demo. On the login page, click "Demo Login" to access with a pre-seeded analyst account. Free tier may take ~30s to wake up on first visit.

Open Live Demo Hosted on Railway · Free tier
Self-Host

Deploy in minutes

Docker Compose or bare Node.js. SQLite included — no external database required.

🐳

Docker Compose

Recommended
# Clone and configure
$ git clone https://github.com/vinsk0h/KQLab
$ cd KQLab
$ cp .env.example .env

# Generate secrets (run twice)
$ npm run keygen

# Start production instance
$ docker compose up -d
# → http://localhost:3000

Node.js Direct

# Requirements: Node.js ≥ 18
$ git clone https://github.com/vinsk0h/KQLab
$ cd KQLab
$ npm install
$ cp .env.example .env

# Fill .env then start
$ npm start
# → http://localhost:3000

Ready to centralize your KQL library?

Open source, MIT license. No telemetry, no cloud dependencies, no vendor lock-in.