Skip to content

This repository contains some custom queries for Azure Sentinel in relation to hunting for threats and the creation of alerts.

Notifications You must be signed in to change notification settings

yves001/Azure-Sentinel-Queries

 
 

Repository files navigation

Azure Sentinel Queries

This repo contains some custom queries that I wrote for Azure Sentinel in relation to threat hunting. The alerts will end with "extend IPCustomEntity = IPAddress", the others are base queries that are tested manually.

About

This repository contains some custom queries for Azure Sentinel in relation to hunting for threats and the creation of alerts.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published