JonCyberGuy / SIEM-HomeLabLinks
A walkthrough of creating and using the Azure environment and Microsoft Sentinel to track attacks and plot attacks on a live map.
☆22Updated 2 years ago
Alternatives and similar repositories for SIEM-HomeLab
Users that are interested in SIEM-HomeLab are comparing it to the libraries listed below
Sorting:
- ☆22Updated 2 years ago
- ☆36Updated 2 months ago
- Extensible Azure Security Tool - Documentation☆83Updated 2 years ago
- Collection of different Azure/Entra focused solutions (Deployable templates, Function Apps, etc)☆78Updated 2 weeks ago
- ☆30Updated 8 months ago
- Automation around Entra ID☆38Updated 5 months ago
- Microsoft Sentinel related content☆38Updated 11 months ago
- ☆45Updated last year
- ☆31Updated 2 years ago
- M365 Defender SOC Playbooks☆24Updated 2 years ago
- ☆50Updated last month
- KQL example queries for working in Azure☆35Updated last month
- ☆41Updated 2 years ago
- A series of PowerShell scripts to automate the assessment of Azure IaaS security☆21Updated last year
- Microsoft Entra ID App Audit Solution (AADAppAudit)☆84Updated last year
- CIS & Azure Security Center Hardening recommendations implemented in PowerShell DSC from Azure Automation☆34Updated 4 years ago
- Links and guidance related to the return on mitigation report in the Microsoft Digital Defense Report☆28Updated 2 years ago
- ☆80Updated this week
- Misc. content for Microsoft Sentinel☆18Updated last year
- ☆11Updated 3 years ago
- Solution to deploy a Sentinel playground demo environment☆57Updated 2 years ago
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆112Updated last week
- The Invoke-TrimarcADChecks.ps1 PowerShell script is designed to gather data from a single domain AD forest based on our similar checks pe…☆60Updated 2 years ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆40Updated last year
- MDE Quickstart is a battle-tested MDE policy set designed to be restored with Intune Backup & Restore☆65Updated 3 years ago
- KQL queries for cyber defense and for solving daily issues☆54Updated 5 months ago
- Conditional Access Reporting☆28Updated 9 months ago
- Azure AD Incident Response☆27Updated 4 years ago
- Automatic Microsoft Sentinel Deployment☆16Updated 9 months ago
- Reportly is an AzureAD user activity report tool.☆95Updated 2 years ago