Skip to content

Updated Sigma2KQL script written by @CodeByHarri + Generating Analytics & Hunting Rules ready for Sentinel Deployment

Notifications You must be signed in to change notification settings

Khaled6120/Sentinel-Rules

Repository files navigation

Sentinel-Rules

Updated Sigma2KQL script written by CodeByHarri

- Clone this repo

git clone https://github.com/SigmaHQ/sigma.git

- Install pysigma-backend-microsoft365defender package

pip install pysigma-backend-microsoft365defender

- Create a folder named "KQL"

- Output format - Analytics Rule

image

- Workflow - Analytics Rule

The workflow is responsible for converting the generated YAML files into ARM files ready for sentinel deployment. image

About

Updated Sigma2KQL script written by @CodeByHarri + Generating Analytics & Hunting Rules ready for Sentinel Deployment

Topics

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published