| netevert/sentinel-attack |
1,029 |
|
0 |
0 |
over 2 years ago |
0 |
|
12 |
mit |
HCL |
| Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK |
| Bert-JanP/Hunting-Queries-Detection-Rules |
865 |
|
0 |
0 |
about 2 years ago |
0 |
|
0 |
bsd-3-clause |
Python |
| KQL Queries. Defender For Endpoint and Azure Sentinel Hunting and Detection Queries in KQL. Out of the box KQL queries for: Advanced Hunting, Custom Detection, Analytics Rules & Hunting Rules. |
| darkquasar/AzureHunter |
626 |
|
0 |
0 |
over 3 years ago |
0 |
|
3 |
mit |
PowerShell |
| A Cloud Forensics Powershell module to run threat hunting playbooks on data from Azure and O365 |
| christophetd/Adaz |
391 |
|
0 |
0 |
over 2 years ago |
0 |
|
16 |
|
HCL |
| :wrench: Deploy customizable Active Directory labs in Azure - automatically. |
| eshlomo1/Microsoft-Sentinel-SecOps |
266 |
|
0 |
0 |
almost 2 years ago |
0 |
|
0 |
mit |
PowerShell |
| Microsoft Sentinel SOC Operations |
| ashwin-patil/blue-teaming-with-kql |
125 |
|
0 |
0 |
over 3 years ago |
0 |
|
0 |
mit |
|
| Repository with Sample KQL Query examples for Threat Hunting |
| ashwin-patil/threat-hunting-with-notebooks |
47 |
|
0 |
0 |
over 3 years ago |
0 |
|
0 |
|
Jupyter Notebook |
| Repository with Sample threat hunting notebooks on Security Event Log Data Sources |