Azure-Sentinel-Notebooks
Interactive Azure Sentinel Notebooks provides security insights and actions to investigate anomalies and hunt for malicious behaviors.
File Explorer
Download Latest Version (.zip)- metadata.yml
- Azure Kubernetes Service Guided Hunting.ipynb
- Guided Hunting - Anomalous Process Network Connections.ipynb
- Guided Hunting - Anomaly detection with Isolation Forest on Windows Logon data For Data Scientist .ipynb
- Guided Investigation - Anomalous users generated by Isolation Forest Model for SOC Analysts.ipynb
- MasqueradingProcessNameAnomaly.ipynb
- input_1.png
- input_2.png
- mitre_map.png
- output_1.png
- output_2.png
- MitreMap - Infer MITRE technique from Threat Intel Data.ipynb
- model.ps1
- model.sh
- README.md
- requirements-stable.txt
- requirements.txt
- utils-1.0-py3-none-any.whl
- Authoring automated notebooks.md
- AutomationGallery-CredentialScanOnAzureBlobStorage.ipynb
- AutomationGallery-CredentialScanOnAzureDataExplorer.ipynb
- AutomationGallery-CredentialScanOnAzureLogAnalytics.ipynb
- autonb-requirements.txt
- DeploymentTemplate.json
- AIO_Hunting-AutomatedDataQueryAndIngestionToCustomTable.ipynb
- AutomateTools_ParquetGenerator.ipynb
- Hunting-AutomatedDataQueryAndIngestionToCustomTable.ipynb
- Hunting-AzureResourceProvisioning.ipynb
- Hunting-QueryParquetFilesAndIngestionToCustomTable.ipynb
- LogAnalytics-CustomTableSetup.ipynb
- requirements.txt
- Scheduled_Hunting-AutomatedDataQueryAndMDTIAPIAndIngestionToCustomTable.ipynb
- PerfTools_Log Analytics Query.ipynb
- PerfTools_Log Analytics_CustomTable_Setup.ipynb
- __init__.py
- Entities.py
- graph.html.template
- GraphVis.py
- Guided Analysis - User Security Metadata.ipynb
- NodeEdge.py
- README.md
- Utils.py
- AffectedKeyCredentials-CVE-2021-42306.ipynb
- AutomatedNotebooks-IncidentTriage.ipynb
- AutomatedNotebooks-Manager.ipynb
- Export Historical Log Data.ipynb
- Guided Hunting - Detect potential network beaconing using Apache Spark via Azure Synapse.ipynb
- Guided Hunting - Office365-Exploring.ipynb
- Guided Hunting - Use Machine Learning to Detect Potential Low and Slow Password Sprays using Apache Spark via Azure Synapse.ipynb
- Guided Investigation - MDE Webshell Alerts.ipynb
- Guided Investigation - WAF data.ipynb
- Microsoft Sentinel Query Creator.ipynb
- README.md
- README.md
- TI-Retroactive-Hunting.ipynb
- TI-Retroactive-Hunting.job.yaml
- README.md
- aad_logons.pkl
- alerts_list.pkl
- combined_df.pkl
- data_queries.yaml
- exchange_admin.pkl
- failed_logons_det_df.pkl
- failed_logons_hourly.pkl
- host_logons.pkl
- iforest-demo-data.csv
- processes_on_host.pkl
- timeseries.pkl
- training_incident.pkl
- AML_compute_create.png
- AML_compute_kernel.png
- AML_compute_script.png
- AML_kernel.png
- AML_restart_kernel.png
- aml_terminal.png
- az_sentinel_settings1.png
- az_sentinel_settings2.png
- device_auth_code.png
- device_auth_complete.png
- device_authn.pdn
- device_authn.png
- extra_exception.png
- nb_img1.png
- nb_img2.png
- nb_ipexplorer-mindmap.png
- network_graph.png
- win_env_var.png
- __init__.py
- anomaly_finder.py
- anomaly_lookup_view_helper.py
- __init__.py
- azure_loganalytics_helper.py
- __init__.py
- input_error.py
- __init__.py
- log.py
- __init__.py
- bookmark_helper.py
- __init__.py
- config_reader.py
- input_validation.py
- obfuscation_utility.py
- version_management.py
- __init__.py
- widget_view_helper.py
- __init__.py
- LICENSE.txt
- README.rst
- setup.py
- Snippets.json
- papermill_test_runner.ipynb
- A Getting Started Guide For Azure Sentinel Notebooks.ipynb
- Entity Explorer - Linux Host.ipynb
- Entity Explorer - Windows Host.ipynb
- Example - Step-by-Step Linux-Windows-Office Investigation.ipynb
- Get Started.ipynb
- aad_logons.pkl
- alerts_list.pkl
- all_events_df.pkl
- az_net_comms_df.pkl
- az_whois.df.pkl
- data_queries.yaml
- failedLogons.pkl
- host_logons.pkl
- ip_locations.pkl
- process_tree.pkl
- processes_on_host.pkl
- queries.yaml
- ti_results_ipv4.pkl
- ti_results_url.pkl
- config.json
- Example - Azure Storage VT Hash Lookup.ipynb
- Example - Guided Hunting - Office365-Exploring.ipynb
- Example - Guided Investigation - Process-Alerts.ipynb
- Example - Using Sentinel Search Queries.ipynb
- M365 Defender - APIs ep3.ipynb
- M365 Defender - hunting.ipynb
- MDE APIs Demo Notebook.ipynb
- mp_data.py
- msticpy demo.ipynb
- MSTICPy Tour.ipynb
- Recorded Future Sigma Rules Importer.ipynb
- Senserva Connections Graph Notebook.ipynb
- SigmaRuleImporter.ipynb
- VirusTotal File Behavior Explorer - MS and Sysmon detonation.ipynb
- alertlist.csv
- az_net_flows.csv
- demo_exchange_data.csv
- example.yaml
- host_logons.csv
- ioc_df.csv
- ip_entities.pkl
- ip_locs.csv
- linux_proc_test.pkl
- process_tree.csv
- processes_on_host.csv
- procs_with_cluster.pkl
- TimeSeriesDemo.csv
- win_proc_test.pkl
- AnomalousSequence.ipynb
- AzureBlobStorage.ipynb
- AzureSentinelAPIs.ipynb
- Base64Unpack.ipynb
- Data_Queries.ipynb
- DataObfuscation.ipynb
- DataUploader.ipynb
- DataViewer.ipynb
- EventClustering.ipynb
- EventTimeline.ipynb
- FoliumMap.ipynb
- GeoIPLookups.ipynb
- IoCExtract.ipynb
- MDATPQuery.ipynb
- MordorData.ipynb
- MPSettingsEditor.ipynb
- mybinder.png
- NotebookWidgets.ipynb
- PivotFunctions-Introduction.ipynb
- PivotFunctions.ipynb
- process_tree3.png
- ProcessTree.ipynb
- Readme.md
- ResourceGraphDriver.ipynb
- Splunk-DataConnector.ipynb
- SqlToKql.ipynb
- Sumologic-DataConnector.ipynb
- TimeSeriesAnomaliesVisualization.ipynb
- TIProviders.ipynb
- VirusTotalLookup.ipynb
- VTLookupV3.ipynb
- AddEnvSetup-Requirements.jpg
- AddEnvSetup-Requirements2.jpg
- AddEnvSetup.jpg
- AddEnvSetupPyVersion.jpg
- Dropdown.png
- login.PNG
- ProjectSettings.jpg
- README.md
- Requirements_txt_added.jpg
- Select.PNG
- Warning.png
- Adding Hunting Bookmarks.ipynb
- Adding Secrets to Azure Key Vault.ipynb
- aml-compute-setup.sh
- Automation Setup - Configure Azure Machine Learning Compute Cluster and Managed Identity.ipynb
- Automation Setup - Configure Azure Machine Learning Pipelines.ipynb
- Azure Sentinel Query Creator.ipynb
- Configurate Azure ML and Azure Synapse Analytics.ipynb
- Notebook Template.ipynb
- Provisioning DSVM.ipynb
- README.md
- TroubleShootingNotebooks.ipynb
- A Getting Started Guide For CSharp AML Notebooks.ipynb
- A Python Crash Course - Part 1 - Fundamentals.ipynb
- Training - MSTICPy Training 1221.ipynb
- Training - MSTICPy Training 3 - 2022-01-13.ipynb
- Readme.md
- check_nb_kernel.py
- check_nb_load.py
- config_reader.py
- generate-nb-toc.ipynb
- nb_check.py
- test_mp_extras.py
- .gitignore
- A Getting Started Guide For Azure Sentinel ML Notebooks.ipynb
- A Getting Started Guide For PowerShell AML Notebooks.ipynb
- A Tour of Cybersec notebook features.ipynb
- azure-pipelines.yml
- CODE_OF_CONDUCT.md
- config.json
- Configurate Azure ML and Azure Synapse Analytics.ipynb
- ConfiguringNotebookEnvironment.ipynb
- CONTRIBUTING.md
- Credential Scan on Azure Blob Storage.ipynb
- Credential Scan on Azure Data Explorer.ipynb
- Credential Scan on Azure Log Analytics.ipynb
- Entity Explorer - Account.ipynb
- Entity Explorer - Domain and URL.ipynb
- Entity Explorer - Host.ipynb
- Entity Explorer - IP Address.ipynb
- Entity Explorer - Linux Host.ipynb
- Entity Explorer - Windows Host.ipynb
- Guided Hunting - Anomalous Office365 Exchange Sessions.ipynb
- Guided Hunting - Azure Resource Explorer.ipynb
- Guided Hunting - Base64-Encoded Linux Commands.ipynb
- Guided Hunting - Covid-19 Themed Threats.ipynb
- Guided Hunting - Detect potential network beaconing using Apache Spark via Azure Synapse.ipynb
- Guided Hunting - Investigating Malicious Links Shared in Teams.ipynb
- Guided Investigation - Anomaly Lookup.ipynb
- Guided Investigation - Azure WAF SQLI.ipynb
- Guided Investigation - Fusion Incident.ipynb
- Guided Investigation - Incident Triage.ipynb
- Guided Investigation - Process-Alerts.ipynb
- Guided Investigation - Solarwinds Post Compromise Activity.ipynb
- Guided Triage - Alerts.ipynb
- Hands-on 1. Data Discovery using Azure REST API.ipynb
- Hands-on 2. Surfing Data using Azure SDK.ipynb
- LICENSE
- Machine Learning in Notebooks Examples.ipynb
- msticpyconfig.yaml
- msticpyconfig.yaml.sample
- notebookmetadata.json
- PUBLISHING.md
- README.md
- requirements.txt
- SECURITY.md
- Sentinel Bulk Logs Export.ipynb
π Installation Guide
1. Get the code
git clone https://github.com/Azure/Azure-Sentinel-Notebooks
Downloads the entire project code from GitHub to your computer.
cd Azure-Sentinel-Notebooks
Moves into the project folder you just downloaded.
2. Python
Easy RecommendedPrerequisites
pip install -r mitremap-notebook/requirements.txt
Installs the Python libraries listed in requirements.txt (or similar).
jupyter notebook
Launches Jupyter in your browser so you can open and run the notebook (.ipynb) files.
If it runs without errors and prints output in the terminal, it worked.
// repository documentation
Was this content helpful?
(0 ratings)
