sentinel-attack icon indicating copy to clipboard operation
sentinel-attack copied to clipboard

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK

Results 13 sentinel-attack issues
Sort by recently updated
recently updated
newest added

Hello! So I am deploying this to an instance of Sentinel I already have up and running. I added the parser, created the storage container, and uploaded the whitelists. I...

From any tab in the dashboard, I can see that it can reach the CSV files, but it returns no results. When I look at the prerequisite section it says:...

Maybe something has changed in Azure, but the guide in https://github.com/BlueTeamLabs/sentinel-attack/wiki/Sysmon-Threat-Hunting-workbook---post-deployment-configuration can no longer be followed. Azure does not allow me to use the exact workspace name as the underlying...