Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
-
Updated
Nov 28, 2024
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
Microsoft Sentinel SOC Operations
Repository with Sample KQL Query examples for Threat Hunting
Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.
A collection of things I've created or found that I think is useful for Azure Sentinel.
Detection rules and threat hunting queries in Defender XDR and Azure Sentinel
AI-powered SOC analyst for Azure Sentinel threat hunting with GPT and VirusTotal integration.
A technical blog about Kusto
Collection of Azure Monitor or Sentinel Kusto Queries
A modular AI-powered CLI for Azure Sentinel threat hunting & remediation. Features strict guardrails, cost-aware routing, and automated SOAR workflows (VM isolation, rule creation).
This terraform module is designed to create azure Sentinel resources. Microsoft Sentinel natively incorporates proven Azure services, like Log Analytics and Logic Apps. Microsoft Sentinel enriches your investigation and detection with AI. It provides Microsoft's threat intelligence stream and enables you to bring your own threat intelligence
Production-validated detection queries and hunting artifacts across 9 platforms (KQL, Sigma, Splunk, Athena, PowerShell, Velociraptor, YARA, Suricata, osquery). Each with triggers, false positives, tuning guidance, and validation steps.
Microsoft Sentinel / Azure Open AI 演習のレポジトリです。
Collection of Azure Sentinel - Playbook | Logic App (Template)
Azure ARM (bicep) template for deploying a high availability syslog/CEF forwarder setup using Azure VMs.
MaxMind Geo and ASN Data for Kusto
9 MITRE ATT&CK-mapped KQL detections on a live Microsoft Sentinel + Defender XDR environment (control-plane, endpoint, identity), with a PR-gated Detection-as-Code pipeline (GitHub Actions, OIDC), SOAR playbooks, and a SOC 2 control mapping.
A containerized Logstash ready to send data to Log Analytics or Event Hub
This project used for convert azure sentinel rules to excel
To associate your repository with the azure-sentinel topic, visit your repo's landing page and select "manage topics."