Description
Simplify your threat hunts using Sysmon data mapped to MITRE ATT&CK data. This workbook gives you the ability to drilldown into system activity based on known ATT&CK techniques as well as other threat hunting entry points such as user activity, network connections or virtual machine Sysmon events.
Please note that for this workbook to work you must have deployed Sysmon on your virtual machines in line with the instructions at https://github.com/BlueTeamLabs/sentinel-attack/wiki/Onboarding-sysmon-data-to-Azure-Sentinel
- Version
- 1.4.0
- Auteur / éditeur déclaré
- Microsoft Sentinel community
Sources déclarées
Métadonnées du fichier source. Aucune dépendance déduite du KQL.
Types de données
Traçabilité de la source
GitHubLes valeurs affichées proviennent des fichiers du dépôt Azure/Azure-Sentinel. Elles décrivent le modèle publié, pas la configuration de votre workspace.
- Commit
629d1d3↗- Identifiant source
SysmonThreatHuntingWorkbook
Autres fichiers source 2
Workbooks/SysmonThreatHunting.jsonsource ↗Workbooks/WorkbooksMetadata.jsonworkbook-metadata ↗GSTEP / SUIVI DU CATALOGUE
Ajouté au catalogue : 16 sept. 2026 · 05:49 UTC
Dernier changement observé : 16 sept. 2026 · 17:57 UTC