Microsoft Sentinel Tools
A collection of KQL queries and Azure Workbooks for Microsoft Sentinel.
-
Workbooks
Pre-built Azure Workbooks for security monitoring, MFA analysis, sign-in investigation, and more.
-
KQL Queries
Ready-to-use Kusto Query Language queries for alerting and hunting in Microsoft Sentinel.
Quick Start
Installing a Workbook
- Navigate to Microsoft Sentinel > Workbooks > Add workbook
- Click Edit then Advanced editor
- Copy the contents of the desired
template.jsonfile - Paste into the editor and click Apply
- Save the workbook
Using a KQL Query
- Navigate to Investigation & response > Hunting > Advanced hunting
- Copy the desired
.kqlquery - Paste into the query editor
- Adjust parameters as needed and run query
License
This project is licensed under the MIT License.