MicrosoftSentinelStuff icon indicating copy to clipboard operation
MicrosoftSentinelStuff copied to clipboard

Misc. content for Microsoft Sentinel

trafficstars

Microsoft Sentinel Stuff

Various content for Microsoft Sentinel

Workbooks

  • Conditional-Access-Review - a workbook for reviewing Conditional Access events

Playbooks

  • BlockIP-Namedlocation - take IP addresses from a Microsoft Sentinel incident and add them to a Conditional Access named location for blocking
  • Watchlist-Backup - make copies of your watchlists and store them in Azure blob storage