About this project
This repository is the community content hub for Microsoft Sentinel and Microsoft 365 Defender. It collects out-of-the-box detections, exploration queries, hunting queries, workbooks, playbooks and other security content intended to help teams ramp up with Microsoft Sentinel and secure their environments. Hunting queries also cover advanced hunting scenarios in Microsoft 365 Defender and Microsoft Sentinel.
The README points to official documentation for Microsoft Sentinel and Microsoft 365 Defender, security community webinars, and GitHub getting-started material. It lists feedback channels: Tech Community conversations for SIEM/SOAR and XDR, product feedback forums, GitHub bug and feature-request templates, and an email contact for questions.
Contribution guidance covers the Contributor License Agreement, forking and cloning the repo, creating a branch, pushing changes, and opening a pull request with enough detail for reviewers. It describes automated pull request checks: a detection template structure validation that requires sections such as entityMappings, and a KQL syntax validation for queries defined in templates. Custom log tables must have their schema defined in a JSON file under the KQL validation tests folder. Both validations can be run locally with the .NET Core 3.1 SDK by executing dotnet test in the relevant test directories. A separate detection schema validation checks frequency, period, trigger type, threshold and connector IDs.
The repository also references the Microsoft Open Source Code of Conduct and a wiki for contribution details.
Comments
0 people shared their preference · Deer Point appears after 10 participants
Sign in to join the discussion.