EQL (Event Query Language) Python Library

JSON →
library 1.0.0 ·python
verified May 26, 2026

EQL (Event Query Language) is a high-level query language from Microsoft for expressing relationships between events, primarily used in security analytics and threat hunting contexts. The Python library provides tools to parse, validate, and transform EQL queries into an Abstract Syntax Tree (AST). The current stable version is 1.0.0, with releases typically tied to feature enhancements or bug fixes, maintaining a stable API.

total hits 16
actors 7 distinct systems
last hit 3d ago ChatGPT-User
MetaBot
4
GPTBot
2
Script
2
ChatGPT-User
1
Search engines
1
Humans
1

top countries 🇺🇸 United States · 🇫🇷 France · 🇨🇦 Canada · 🇸🇬 Singapore · 🇩🇪 Germany