I am developing threat detections in KQL for Microsoft Sentinel.
Block or Report
Block or report ep3p
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
Sentinel_KQL Public
In this repository you may find KQL (Kusto Query Language) queries and Watchlist schemes for data sources related to Microsoft Sentinel (a SIEM tool).
-
Azure/Azure-Sentinel Public
Cloud-native SIEM for intelligent security analytics for your entire enterprise.
-
-
bot-unico Public
A simple twitter bot in Python for replying spanish questions like "am I the only one ... ?"
Python
-
-
1,312 contributions in the last year
Less
More
Activity overview
Contributed to
ep3p/Sentinel_KQL,
ep3p/Security_Links,
Azure/Azure-Sentinel
and 20 other
repositories
Contribution activity
May 2023
Created 53 commits in 3 repositories
Created 2 repositories
Created a pull request in reprise99/Sentinel-Queries that received 1 comment
Interchange difference times in Identity-SSPRfollowedbyRiskySignin.kql
I believe the current version is looking for SSPR events that happen until 2 hours after the risk event, instead of what is stated in the first lin…
+2
−2
•
1
comment



