Azure-Sentinel/Hunting Queries
Pete Bryan ba2dc07d54 PR comment 2021-08-30 10:24:33 -07:00
..
ASimProcess Fix DvcHostName -> DvcHostName 2021-07-05 13:57:52 +03:00
AWSCloudTrail more fixes 2021-08-06 14:29:41 -07:00
AWSS3 Fixes 2021-08-06 14:12:37 -07:00
AuditLogs more fixes 2021-08-06 17:15:28 -07:00
AzureActivity Update Granting_Permissions_to_Account.yaml 2021-08-30 08:32:58 -07:00
AzureDevOpsAuditing Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
AzureDiagnostics fixed CriticalPortsOpened 2021-05-12 14:12:09 +03:00
AzureStorage Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
BehaviorAnalytics updated empty connector, moved Teams queries into OfficeActivity, updated some entity mappings 2021-02-04 15:31:02 -08:00
CommonSecurityLog Swap join legs to improve perf 2021-05-06 10:46:33 -07:00
DnsEvents Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
GitHub Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
LAQueryLogs Merge pull request #2803 from Azure/pebryan/2021-8-9_Watchlists 2021-08-19 13:13:18 -07:00
MultipleDataSources Merge pull request #2892 from Azure/ReconactivitywithInteractivelogon 2021-08-27 08:53:05 -07:00
OfficeActivity Fixes 2021-08-06 14:12:37 -07:00
ProofpointPOD Fixes 2021-08-06 14:12:37 -07:00
SQLServer Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
SecurityAlert DNS to Syslog changes 2021-08-04 15:49:57 -07:00
SecurityEvent Fixes 2021-08-06 14:12:37 -07:00
SigninLogs DNS to Syslog changes 2021-08-04 15:49:57 -07:00
Syslog Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
ThreatIntelligenceIndicator Sylog to Zoom 2021-08-06 13:39:23 -07:00
W3CIISLog PR comment 2021-08-30 10:24:33 -07:00
WireData Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
ZoomLogs Removed the deprecated MITRE techniques from hunting and detection queries and updating them with the latest ones that seem most appropriate. 2021-08-12 10:58:18 -07:00
QUERY_TEMPLATE.md Couple additional fixes 2021-02-01 08:22:36 -08:00
readme.md Update readme.md 2020-06-26 11:47:58 -07:00

readme.md

About

This folder contains Hunting Queries based on different types of data sources that you can leverage in order to perform broad threat hunting in your environment.

For general information please start with the Wiki pages.

More Specific to Hunting Queries:

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com