Description
Simplify your threat hunts using Sysmon data mapped to MITRE ATT&CK data. This workbook gives you the ability to drilldown into system activity based on known ATT&CK techniques as well as other threat hunting entry points such as user activity, network connections or virtual machine Sysmon events.
Please note that for this workbook to work you must have deployed Sysmon on your virtual machines in line with the instructions at https://github.com/BlueTeamLabs/sentinel-attack/wiki/Onboarding-sysmon-data-to-Azure-Sentinel
- Version
- 1.4.0
- Declared author / publisher
- Microsoft Sentinel community
Declared sources
Metadata from the source file. No dependencies inferred from KQL.
Data types
Source provenance
GitHubDisplayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.
- Commit
629d1d3↗- Source identifier
SysmonThreatHuntingWorkbook
Additional source files 2
Workbooks/SysmonThreatHunting.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗GSTEP / CATALOG TRACKING
Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 17:57 UTC