Update: Log Horizon
Log Horizon 0.5.0 adds self-contained HTML export, deeper transform analysis, stronger hardening, and improved CI-friendly reporting for Microsoft Sentinel.
Log Horizon 0.5.0 adds self-contained HTML export, deeper transform analysis, stronger hardening, and improved CI-friendly reporting for Microsoft Sentinel.
How to classify security logs into primary and secondary data, use Sentinel tiers pragmatically, and keep cost aligned with detection value.
A PowerShell module that connects to your Sentinel workspace and tells you if your logs are earning their keep.
Diving into some of the recent RSAC announcements
Microsoft Sentinel SIEM log source analyzer. Classifies tables, scores cost-vs-detection value, and generates recommendations.
Repository for publishing scripts related to Microsoft Sentinel.
Proof of concept PowerShell functions for sending TI from MISP to SentinelOne.
Simple tool to detect Azure Lighthouse delegations and automate persistence setup.
Rust tool for sending threat intelligence from MISP to Microsoft Sentinel.
Module for interacting with a MISP server using PowerShell.
PowerShell module for sending indicators of compromise to the Upload Indicators API (Microsoft Sentinel).
Collection of ARM and other templates for Microsoft Sentinel.