Azure-Sentinel/Hunting Queries
aprakash13 da3b384cb1
Update Hunting Queries/MultipleDataSources/NetworkConnectionldap_log4j.yaml
Co-authored-by: sergevanhaag <84989429+sergevanhaag@users.noreply.github.com>
2021-12-29 15:25:01 -08:00
..
ASimProcess corrected missing mapping keys 2021-12-08 17:56:35 -08:00
AWSCloudTrail
AWSS3
AuditLogs Merge pull request #1605 from setprice2245/patch-1 2021-11-21 11:51:53 -08:00
AzureActivity Removing comments & minor fixes 2021-11-22 16:03:12 +00:00
AzureDevOpsAuditing updating Tactics to match with standrd values 2021-09-01 12:51:38 -07:00
AzureDiagnostics Update WAF_log4j_vulnerability.yaml 2021-12-16 13:44:53 -08:00
AzureStorage Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
BehaviorAnalytics Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
CommonSecurityLog Added missing KQL statement 2021-12-17 09:46:36 -08:00
DnsEvents Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
GitHub
LAQueryLogs
MultipleDataSources Update Hunting Queries/MultipleDataSources/NetworkConnectionldap_log4j.yaml 2021-12-29 15:25:01 -08:00
OfficeActivity Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
ProofpointPOD
SQLServer Updating the name from “Azure Sentinel” to “Microsoft Sentinel” for Detection and Hunting Queries. 2021-11-09 18:41:23 -08:00
SecurityAlert
SecurityEvent Merge branch 'master' into ashwin/connector-fixes 2021-12-08 17:45:20 -08:00
SigninLogs add missing id to rule 2021-12-22 12:04:23 -06:00
Syslog Adding query for review 2021-12-17 08:55:38 -08:00
ThreatIntelligenceIndicator Updating TI queries based on feedback and discussions on this PR - #3477 - and I don't want preferences for a specific environment to be included. This includes generic changes that need to be done. 2021-11-29 13:58:28 -08:00
W3CIISLog Updating queries with common timestamp param to support future features. 2021-09-10 10:10:13 -07:00
WireData
ZoomLogs
QUERY_TEMPLATE.md
readme.md Updating the name from “Azure Sentinel” to “Microsoft Sentinel” for Detection and Hunting Queries. 2021-11-09 18:41:23 -08:00

readme.md

About

This folder contains Hunting Queries based on different types of data sources that you can leverage in order to perform broad threat hunting in your environment.

For general information please start with the Wiki pages.

More Specific to Hunting Queries:

Feedback

For questions or feedback, please contact AzureSentinel@microsoft.com