Skip to content

stefanpems/sentinel-utilities

Folders and files

NameName
Last commit message
Last commit date

Latest commit

ย 

History

50 Commits
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 
ย 

Repository files navigation

My stuff for Microsoft Sentinel.

๐’๐ž๐ง๐ญ๐ข๐ง๐ž๐ฅ๐€๐ง๐š๐ฅ๐ฒ๐ญ๐ข๐œ๐‘๐ฎ๐ฅ๐ž๐ฌ๐Œ๐š๐ง๐š๐ ๐ž๐ฆ๐ž๐ง๐ญ๐’๐œ๐ซ๐ข๐ฉ๐ญ.๐ฉ๐ฌ1 is a script containing cmdlets that automates the massive creation, backup, deletion and update of Analytic Rules in Microsoft Sentinel. Ideas for its improvement / evolution:

  1. Change the authentication flow (do not use Device Code flow)
  2. Export as json ARM template files any kind of rule - Not only the rules related to the templates installed from Content Hub solutions
  3. Restore rules from their json ARM template files
  4. Update installed solutions in Content Hub
  5. Install specified solutions in Content Hub

...

๐•๐ž๐ซ๐ข๐Ÿ๐ฒ๐‚๐จ๐ง๐๐ข๐ญ๐ข๐จ๐ง๐š๐ฅ๐€๐œ๐œ๐ž๐ฌ๐ฌ๐ˆ๐ฆ๐ฉ๐š๐œ๐ญ is a KQL query to list which Conditional Access Policies in "Report-only" mode would have forced MFA or blocked the sign-ins if they were set to "On". It requires the SigninLogs from Microsoft Entra to be collected in Sentinel

About

Utilities for Microsoft Sentinel

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published