Microsoft Sentinel & Defender KQL queries aligned to CMMC 2.0 practices build 2026-02-26 03:02 UTC
Four-step closed loop: generate the check query, run it in Sentinel, paste the results back here, and get a full coverage dashboard with Power BI & CSV exports.
This query checks all 25 tables referenced by the framework. It reports each table as Present or Missing along with the NIST controls that depend on it.
Open Microsoft Sentinel → Logs blade → paste the query → click Run.
Once results appear, click Export (top-right of results) → Export to CSV - All columns.
Upload the CSV file, drag-and-drop it onto the box below, or paste the contents directly.
Your environment coverage report, generated from the Sentinel results.
How is coverage calculated? Active + Configured = Covered. Only "Not Found" tables count as gaps.
Each row is one NIST control. Covered = at least one data source is active or configured. The columns show which tables are working and which need attention.
| Control | Name | Family | Status | ● Active Tables | ● Configured Tables | ● Not Found |
|---|
Add, edit, or remove KQL alignments. When you submit, GitHub auto-forks the repo and creates a pull request for review — all in the browser.
Fill in all required fields (*) to see the YAML preview...
Select the alignment to edit:
Select the alignment to remove: