Azure-Sentinel/Hunting Queries
v-atulyadav 7e0c50c538
Standalone metadata updates (#7914)
* Standalone metadata updates

* Update WorkbooksMetadata.json

* Updated kind

* Update kind
2023-04-28 10:10:42 +05:30
..
ASimProcess Remaining tagging 2022-11-01 18:42:28 +05:30
ASimRegistry Remaining tagging 2022-11-01 18:42:28 +05:30
AWSCloudTrail Skip validations for hunting Queries and Analytic Rules 2022-10-13 16:28:02 +05:30
AWSS3 Update AWSBucketAPILogs-SuspiciousDataAccessToS3BucketsfromUnknownIP.yaml 2023-02-08 13:40:51 +08:00
AuditLogs Merge branch 'master' into v-vdixit/KQL-hunting-queries-validation-tests 2023-03-27 12:37:37 +05:30
AzureActivity updating path1 2023-03-01 13:55:05 +05:30
AzureDevOpsAuditing skip validations 2022-09-22 19:24:32 +05:30
AzureDiagnostics updating whitespaces 2023-02-28 19:31:27 +05:30
AzureStorage Updating connector to MicrosoftThreatProtection 2022-03-07 09:52:34 -08:00
BehaviorAnalytics Removed unwanted sections from source 2022-08-16 18:18:38 +05:30
CommonSecurityLog updating whitespaces 2023-02-28 19:31:27 +05:30
DnsEvents File path update hunting queries 2023-02-23 14:55:16 +05:30
Dynamics365Activity Duplicate Content (#7786) 2023-04-12 10:04:25 +05:30
GitHub Standalone metadata updates (#7914) 2023-04-28 10:10:42 +05:30
LAQueryLogs Hunting Queries KQL Validations 2023-02-07 16:48:24 +05:30
Microsoft 365 Defender Merge branch 'master' into v-vdixit/KQL-hunting-queries-validation-tests 2023-03-27 12:37:37 +05:30
MultipleDataSources Moved to use inbuilt query 2023-03-27 15:12:12 -07:00
OfficeActivity Repackaging Microsoft 365 2023-03-20 19:18:16 +05:30
ProofpointPOD Updating description 2023-02-28 18:46:12 +05:30
SQLServer updating commas 2023-02-28 16:37:12 +05:30
SecurityAlert Remaining tagging 2022-11-01 18:42:28 +05:30
SecurityEvent updating whitespaces 2023-02-28 19:31:27 +05:30
SigninLogs Hunting Queries files path update 2023-02-23 15:10:55 +05:30
Syslog Hunting Queries files path update 2023-02-23 15:10:55 +05:30
ThreatIntelligenceIndicator Merge branch 'master' into v-vdixit/file-path-update3 2023-02-28 18:54:19 +05:30
W3CIISLog Standalone content tagging Hunting Queries (#6702) 2022-11-24 13:16:00 +05:30
WireData Remaining tagging 2022-11-01 18:42:28 +05:30
ZoomLogs Remaining tagging 2022-11-01 18:42:28 +05:30
QUERY_TEMPLATE.md Couple additional fixes 2021-02-01 08:22:36 -08:00
readme.md Updating the name from “Azure Sentinel” to “Microsoft Sentinel” for Detection and Hunting Queries. 2021-11-09 18:41:23 -08:00

readme.md

About

This folder contains Hunting Queries based on different types of data sources that you can leverage in order to perform broad threat hunting in your environment.

For general information please start with the Wiki pages.

More Specific to Hunting Queries:

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com