Azure-Sentinel/Hunting Queries
Anki Narravula 4aa81e622c
Merge pull request #6492 from Azure/feature/StandaloneContentMigration
Standalone content tagging for few files
2022-10-27 15:43:18 +05:30
..
ASimProcess
ASimRegistry
AWSCloudTrail Skip validations for hunting Queries and Analytic Rules 2022-10-13 16:28:02 +05:30
AWSS3 Fixing missing day due to midtime usage 2022-05-09 16:02:13 -07:00
AuditLogs Merge pull request #4756 from jocarolo/jocarolo-2022 2022-09-12 07:40:21 -07:00
AzureActivity Fixing typos 2022-05-20 17:34:53 -07:00
AzureDevOpsAuditing skip validations 2022-09-22 19:24:32 +05:30
AzureDiagnostics Solution migration changes for Apache Log4j Vulnerability Detection (#5994) 2022-09-05 15:18:08 +05:30
AzureStorage
BehaviorAnalytics Removed unwanted sections from source 2022-08-16 18:18:38 +05:30
CommonSecurityLog Solution migration changes for Apache Log4j Vulnerability Detection (#5994) 2022-09-05 15:18:08 +05:30
DnsEvents Update Skip validation 2022-09-19 19:17:12 +05:30
GitHub
LAQueryLogs Update CrossServiceADXQueries.yaml 2022-06-10 09:55:36 +02:00
Microsoft 365 Defender Merge pull request #5795 from mjmelone/patch-5 2022-10-12 10:55:38 -07:00
MultipleDataSources Solution migration changes for Apache Log4j Vulnerability Detection (#5994) 2022-09-05 15:18:08 +05:30
OfficeActivity Adding additional entity outputs as needed by other tooling and to support future automap of entities similar to Detections 2022-05-20 15:23:48 -07:00
ProofpointPOD
SQLServer
SecurityAlert discard source.name field in contents 2022-10-18 12:48:41 -07:00
SecurityEvent Skip Validation 2022-10-03 22:32:14 +05:30
SigninLogs discard source.name field in contents 2022-10-18 12:48:41 -07:00
Syslog Solution migration changes for Apache Log4j Vulnerability Detection (#5994) 2022-09-05 15:18:08 +05:30
ThreatIntelligenceIndicator
W3CIISLog discard source.name field in contents 2022-10-18 12:48:41 -07:00
WireData
ZoomLogs
QUERY_TEMPLATE.md
readme.md

readme.md

About

This folder contains Hunting Queries based on different types of data sources that you can leverage in order to perform broad threat hunting in your environment.

For general information please start with the Wiki pages.

More Specific to Hunting Queries:

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com