microsoft-sentinel topic
Microsoft-Sentinel-SecOps
Microsoft Sentinel SOC Operations
Threat-Hunting-and-Detection
Repository for threat hunting and detection queries, etc. for Defender for Endpoint and Microsoft Sentinel in KQL(Kusto Query Language).
Sentinel_KQL
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
SentinelAutomationModules
The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
KQL-Queries
Ian Hanley's deceptively simple KQL queries.
KQL-threat-hunting-queries
A repository of KQL queries focused on threat hunting and threat detecting for Microsoft Sentinel & Microsoft XDR (Former Microsoft 365 Defender).
reversinglabs-siem-rules
A collection of various SIEM rules relating to malware family groups.
MicrosoftSentinelStuff
Misc. content for Microsoft Sentinel