☆30May 1, 2025Updated 9 months ago
Alternatives and similar repositories for Sentinel
Users that are interested in Sentinel are comparing it to the libraries listed below
Sorting:
- An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bice…☆22Jul 31, 2025Updated 6 months ago
- This script will pull and analyze syscalls in given application(s) allowing for easier security research purposes☆21Mar 11, 2021Updated 4 years ago
- Rules I have researched for Sentinel in my spare time. If someone wants to offer me a job I am open. Anyone can use this. Please credit m…☆17Jan 24, 2025Updated last year
- Cheatsheets and other Yealink Phone information.☆17Apr 13, 2018Updated 7 years ago
- Utilities for Microsoft Sentinel☆20Dec 7, 2025Updated 2 months ago
- Collections of way to evade normal detection events.☆23Sep 13, 2020Updated 5 years ago
- Export Microsoft Sentinel artifacts like Analytical Rules, Hunting Queries, Workbooks in order to support new feature Repositories CI/CD …☆59Sep 15, 2022Updated 3 years ago
- ☆67Jan 20, 2026Updated last month
- Sigma Queries turned into KQL for Defender using pysigma☆12Jun 20, 2024Updated last year
- Content Repo for Demystifying KQL Tutorial Series☆72Sep 1, 2024Updated last year
- A collection of Microsoft Sentinel workbooks and analytics rules.☆111Feb 8, 2024Updated 2 years ago
- Automated security investigation tool using Microsoft MCP Servers, GitHub Copilot, Python Modules and custom copilot-instructions.☆41Updated this week
- This PowerShell module allows you to create Microsoft Word documents without Word being installed on the machine☆13Oct 7, 2022Updated 3 years ago
- Parse pfSense/OPNSense logs using Logstash, GeoIP tag entities, add additional context to logs, then send to Azure Sentinel for analysis.☆31Feb 28, 2022Updated 4 years ago
- ☆14Feb 20, 2026Updated last week
- Integration tools for TheHive and Azure Sentinel☆13Sep 23, 2020Updated 5 years ago
- Model Context Protocol (MCP) server that provides access to Azure Resource Graph queries. It allows you to retrieve information about Azu…☆16May 6, 2025Updated 9 months ago
- The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel☆277Jan 2, 2026Updated last month
- Microsoft Endpoint Manager related resources☆39Updated this week
- This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup…☆15Sep 5, 2020Updated 5 years ago
- KQL Detections for Microsoft Sentinel and Microsoft 365 Defender☆21Nov 15, 2024Updated last year
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆51Sep 22, 2025Updated 5 months ago
- A collection of various SIEM rules relating to malware family groups.☆70Jun 18, 2024Updated last year
- ☆36Updated this week
- Sentinel Threat Intelligence Upload Toolkit☆18Jul 15, 2024Updated last year
- ☆18Oct 16, 2025Updated 4 months ago
- In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (…☆134Dec 18, 2025Updated 2 months ago
- KQL Queries☆33Feb 17, 2026Updated last week
- Cyber Threat Intelligence☆77Dec 7, 2025Updated 2 months ago
- Abusing Reddit API to host the C2 traffic, since most of the blue-team members use Reddit, it might be a great way to make the traffic lo…☆24Jan 23, 2023Updated 3 years ago
- A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 D…☆758Aug 28, 2025Updated 6 months ago
- A repository dedicated to tracking ransomware families based on leaked builders.☆22Apr 17, 2024Updated last year
- Sentinel Logic Apps, Playbooks and Workbooks to automate enrichment, incident analysis and more.☆115Jan 18, 2026Updated last month
- ☆34Nov 11, 2025Updated 3 months ago
- ☆36Feb 12, 2026Updated 2 weeks ago
- Bicep examples repo for log analytics, azure monitor and sentinel☆26Mar 16, 2023Updated 2 years ago
- FTA as a Service☆25Apr 3, 2025Updated 10 months ago
- Advanced Threat Hunting: Ransomware Group☆29Jul 9, 2025Updated 7 months ago
- Ian Hanley's deceptively simple KQL queries.☆68Dec 27, 2025Updated 2 months ago