My stuff for Microsoft Sentinel.
๐๐๐ง๐ญ๐ข๐ง๐๐ฅ๐๐ง๐๐ฅ๐ฒ๐ญ๐ข๐๐๐ฎ๐ฅ๐๐ฌ๐๐๐ง๐๐ ๐๐ฆ๐๐ง๐ญ๐๐๐ซ๐ข๐ฉ๐ญ.๐ฉ๐ฌ1 is a script containing cmdlets that automates the massive creation, backup, deletion and update of Analytic Rules in Microsoft Sentinel. Ideas for its improvement / evolution:
- Change the authentication flow (do not use Device Code flow)
 - Export as json ARM template files any kind of rule - Not only the rules related to the templates installed from Content Hub solutions
 - Restore rules from their json ARM template files
 - Update installed solutions in Content Hub
 - Install specified solutions in Content Hub
 
...
๐๐๐ซ๐ข๐๐ฒ๐๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐๐ฅ๐๐๐๐๐ฌ๐ฌ๐๐ฆ๐ฉ๐๐๐ญ is a KQL query to list which Conditional Access Policies in "Report-only" mode would have forced MFA or blocked the sign-ins if they were set to "On". It requires the SigninLogs from Microsoft Entra to be collected in Sentinel