Programming Microsoft Sentinel book
☆24Dec 13, 2023Updated 2 years ago
Alternatives and similar repositories for ProgrammingMicrosoftSentinel
Users that are interested in ProgrammingMicrosoftSentinel are comparing it to the libraries listed below
Sorting:
- Create a Word document showing your Sentinel configuration☆14Nov 7, 2023Updated 2 years ago
- Sentinel BEC IR☆14Aug 18, 2022Updated 3 years ago
- The collateral repository for The KQL Mysteries series☆26Mar 8, 2024Updated 2 years ago
- Misc. content for Microsoft Sentinel☆17Apr 12, 2024Updated last year
- Queries from the blog posts.☆15Oct 6, 2024Updated last year
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆63Jul 27, 2025Updated 7 months ago
- ☆43Oct 11, 2023Updated 2 years ago
- Sentinel Analytics Rule converter PowerShell module☆67Feb 24, 2026Updated 3 weeks ago
- Azure OpenAI Playbook created for Microsoft Sentinel☆13May 2, 2024Updated last year
- The EPSS Calculator is a user-friendly web application that calculates the EPSS (Exploit Prediction Scoring System) score based on a prov…☆17Nov 11, 2024Updated last year
- MCP Server that integrates with Security Copilot, Sentinel and other tools (in the future). It enhance the process of developing , testin…☆20Oct 8, 2025Updated 5 months ago
- Copilot for Security Tools☆18Apr 19, 2024Updated last year
- Content Repo for Demystifying KQL Tutorial Series☆73Sep 1, 2024Updated last year
- ☆30Nov 11, 2024Updated last year
- Ian Hanley's deceptively simple KQL queries.☆67Dec 27, 2025Updated 2 months ago
- AzLogDcrIngestPS - Unleashing the power of Log Ingestion API with Azure LogAnalytics custom table v2, Azure Data Collection Rules and Azu…☆32Jan 26, 2025Updated last year
- PowerShell commands to export the Azure Sentinel Rule Templates to a CSV and to create the Rules from selected entries in the CSV file☆17Oct 31, 2024Updated last year
- Utilities for Microsoft Sentinel☆20Dec 7, 2025Updated 3 months ago
- ☆56Mar 3, 2026Updated 2 weeks ago
- US Government controls formatted for usability☆16Jul 21, 2021Updated 4 years ago
- Logstash output for Kusto☆14Feb 26, 2026Updated 3 weeks ago
- Content and collateral for the Microsoft Sentinel SOC 101 series☆207Feb 12, 2024Updated 2 years ago
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆44Nov 7, 2020Updated 5 years ago
- ☆67Mar 9, 2026Updated last week
- The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel☆276Jan 2, 2026Updated 2 months ago
- Report Generation from the Carbon Black REST API☆15Mar 24, 2022Updated 3 years ago
- Microsoft Graph API post-exploitation toolkit☆95Jul 13, 2024Updated last year
- Export Microsoft Sentinel artifacts like Analytical Rules, Hunting Queries, Workbooks in order to support new feature Repositories CI/CD …☆59Sep 15, 2022Updated 3 years ago
- Rapid Azure Diagnostic deployments☆27Jan 1, 2024Updated 2 years ago
- ☆100Oct 22, 2025Updated 4 months ago
- ☆15Dec 20, 2022Updated 3 years ago
- KQL queries for cyber defense and for solving daily issues☆55Jul 28, 2025Updated 7 months ago
- This TA takes Suricata5 data from your port mirrored Suricata server and makes it readable within Splunk. See Cheatsheets on how to setup…☆15Sep 5, 2020Updated 5 years ago
- Threat Hunting query in Microsoft 365 Defender, XDR. Provide out-of-the-box KQL hunting queries - App, Email, Identity and Endpoint.☆486Nov 22, 2024Updated last year
- Publicly-listed AWS account IDs for easy lookup. Great for cleaning up false positives from unknown Account IDs in Cloudtrail☆38May 23, 2024Updated last year
- These are tools I cheated with the help of ChatGPT to help me with Penetration Testing and Red Teaming☆15Feb 24, 2024Updated 2 years ago
- ☆34May 30, 2023Updated 2 years ago
- A dataset with CloudTrail events from an attack simulation using Stratus.☆25Jul 12, 2023Updated 2 years ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆51Sep 22, 2025Updated 5 months ago