sentinel-attack
sentinel-attack copied to clipboard
Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
Hello! So I am deploying this to an instance of Sentinel I already have up and running. I added the parser, created the storage container, and uploaded the whitelists. I...
From any tab in the dashboard, I can see that it can reach the CSV files, but it returns no results. When I look at the prerequisite section it says:...
Maybe something has changed in Azure, but the guide in https://github.com/BlueTeamLabs/sentinel-attack/wiki/Sysmon-Threat-Hunting-workbook---post-deployment-configuration can no longer be followed. Azure does not allow me to use the exact workspace name as the underlying...