microsoft / msticpy-training
Training and support materials for MSTICPy
☆17Updated last year
Alternatives and similar repositories for msticpy-training:
Users that are interested in msticpy-training are comparing it to the libraries listed below
- A lab environment for learning about MSTICPy☆36Updated 2 years ago
- A few scripts I put together to send and receive data from an Azure Log Analytics workspace leveraging the Azure Monitor HTTP Data Collec…☆23Updated last year
- ☆72Updated 6 months ago
- REST server that can analyze Kusto KQL queries against the Sentinel and Microsoft 365 Defender schemas.☆32Updated 3 months ago
- MSTIC Notebook Components☆31Updated 3 weeks ago
- ☆30Updated last year
- The idea is simply to save some quick notes that will make it easier for Splunk users to leverage KQL (Kusto), especially giving projects…☆41Updated 4 years ago
- Cloud-native SIEM for intelligent security analytics for your entire enterprise.☆19Updated 2 years ago
- Hunting Queries for Microsoft Defender Security Center https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defe…☆39Updated 4 years ago
- ADXFlowmaster helps SecOps teams Threat Hunt suspicious network traffic inside & outside of Azure.☆36Updated 5 months ago
- Links and guidance related to the return on mitigation report in the Microsoft Digital Defense Report☆27Updated last year
- Cloud Analytics helps defenders detect attacks to their cloud infrastructure by developing behavioral analytics for cloud platforms as we…☆53Updated 2 years ago
- ☆17Updated 3 years ago
- ☆41Updated 2 years ago
- A collection of tips for using MISP.☆74Updated 4 months ago
- ☆16Updated 2 years ago
- Remote access and Antivirus Logging Database☆42Updated last year
- Azure Sentinel Template parser☆16Updated 4 years ago
- Repository to publish sample use cases, templates, solutions, automations for Microsoft Defender Threat Intelligence (MDTI) product☆79Updated 7 months ago
- Microsoft 365 Defender Hunting via PowerShell.☆13Updated 3 years ago
- An automated deployment tool that creates instrumented Azure environments with vulnerable systems for simulating attacks and testing Micr…☆29Updated this week
- Automation around Entra ID☆36Updated 4 months ago
- Microsoft Sentinel, Defender for Endpoint - KQL Detection Packs☆53Updated last year
- A WDAC configuration repository with the sole intention of enriching MDE☆28Updated 2 years ago
- ☆36Updated 4 months ago
- This is for my crappy (but hopefully useful) MDE and Sentinel KQL queries! #KQLThePlanet☆12Updated 2 months ago
- Ingesting Shodan Monitor Alerts to Microsoft Sentinel☆34Updated last year
- Defender Resource Hub☆21Updated 3 weeks ago
- Provides detection capabilities and log conversion to evtx or syslog capabilities☆53Updated 2 years ago
- MISP to Sentinel integration☆64Updated 2 weeks ago