↳ GitHub sourceWorkbook

Sysmon Threat Hunting

Description

Simplify your threat hunts using Sysmon data mapped to MITRE ATT&CK data. This workbook gives you the ability to drilldown into system activity based on known ATT&CK techniques as well as other threat hunting entry points such as user activity, network connections or virtual machine Sysmon events. Please note that for this workbook to work you must have deployed Sysmon on your virtual machines in line with the instructions at https://github.com/BlueTeamLabs/sentinel-attack/wiki/Onboarding-sysmon-data-to-Azure-Sentinel
Version
1.4.0
Declared author / publisher
Microsoft Sentinel community

Declared sources

Metadata from the source file. No dependencies inferred from KQL.

Data types

Source provenance

GitHub

Displayed values come from files in Azure/Azure-Sentinel. They describe the published template, not your workspace configuration.

Source identifier
SysmonThreatHuntingWorkbook
Additional source files 2Workbooks/SysmonThreatHunting.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗
GSTEP / CATALOG TRACKING

Added to catalog : 16 Sept 2026 · 05:49 UTC
Last change observed : 16 Sept 2026 · 17:57 UTC

GSTEP sync dates, separate from the source content’s publication dates.