| Topic | Description |
|---|---|
| Event collection to Sentinel | Various topics on events ingestion to Sentinel |
| Windows security events collected by Sentinel | Write-up on the events collected by Sentinel Windows security DCR when configured for All, Common or Minimal set of Windows security events |
| Windows event forwarding | Windows event forwarding between machines in separate domains or WORKGROUP environments |
| Logs ingestion API | Ingest events to Sentinel using logs ingestion API |
| File hash hunting | Threat hunting in Sentinel for file hash indicators with Sysmon events |
| Domain name hunting | Threat hunting in Sentinel for domain name indicators using Sysmon and syslog events |
| Sentinel in Defender portal | Walk through on connecting Sentinel workspace to Defender portal |
| Sentinel MCP | Write-up on using Sentinel MCP for agentic operations |
Folders and files
| Name | Name | Last commit date | ||
|---|---|---|---|---|