EQL (Event Query Language) Python Library
JSON →EQL (Event Query Language) is a high-level query language from Microsoft for expressing relationships between events, primarily used in security analytics and threat hunting contexts. The Python library provides tools to parse, validate, and transform EQL queries into an Abstract Syntax Tree (AST). The current stable version is 1.0.0, with releases typically tied to feature enhancements or bug fixes, maintaining a stable API.
Traffic · last 30 days ↑100% vs prev 7d
total hits 16
actors 7 distinct systems
last hit 3d ago ChatGPT-User
top countries 🇺🇸 United States · 🇫🇷 France · 🇨🇦 Canada · 🇸🇬 Singapore · 🇩🇪 Germany
API endpoints
full doc /v1/registry/eql
install /v1/registry/eql/install
compatibility /v1/registry/eql/compatibility