Azure-Sentinel/Hunting Queries
Shain 2cad1a602c
Merge pull request #2281 from t-shaviv/shaharBranch2
Azure Activity columns alignments
2021-06-13 09:57:18 -07:00
..
AWSCloudTrail Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
AWSS3 updated empty connector, moved Teams queries into OfficeActivity, updated some entity mappings 2021-02-04 15:31:02 -08:00
AuditLogs Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
AzureActivity Merge branch 'master' into shaharBranch2 2021-05-13 11:10:21 +03:00
AzureDevOpsAuditing Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
AzureDiagnostics fixed CriticalPortsOpened 2021-05-12 14:12:09 +03:00
AzureStorage Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
BehaviorAnalytics updated empty connector, moved Teams queries into OfficeActivity, updated some entity mappings 2021-02-04 15:31:02 -08:00
CommonSecurityLog Swap join legs to improve perf 2021-05-06 10:46:33 -07:00
DnsEvents Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
GitHub Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
LAQueryLogs Hunting query timeframe updates 2021-04-12 14:15:43 -07:00
MultipleDataSources fixed content 2021-06-02 13:46:36 +03:00
OfficeActivity Update NewBotAddedToTeams.yaml 2021-05-14 01:32:47 +02:00
ProofpointPOD Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
SQLServer Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
SecurityAlert Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
SecurityEvent Merge pull request #2134 from chihebchebbi/master 2021-06-13 09:12:15 -07:00
SigninLogs Fixed queries that had leftover variables 2021-05-25 13:10:40 -07:00
Syslog Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
ThreatIntelligenceIndicator Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
W3CIISLog updates 2021-06-08 00:05:13 +01:00
WireData Changing GUIDs of hunting queries that had duplicates from Detection queries 2020-04-13 10:52:12 -07:00
ZoomLogs Hunting Query TimeFrame Updates 2021-04-15 17:52:25 -07:00
QUERY_TEMPLATE.md Couple additional fixes 2021-02-01 08:22:36 -08:00
readme.md Update readme.md 2020-06-26 11:47:58 -07:00

readme.md

About

This folder contains Hunting Queries based on different types of data sources that you can leverage in order to perform broad threat hunting in your environment.

For general information please start with the Wiki pages.

More Specific to Hunting Queries:

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com