sameer fakhoury
  • Home
  • CTF Writeups
  • Course Summaries
  • Cyber Reports
  • Articles
  • Event Notes
  • About Me
Mind Maps for Create detections and perform investigations using Microsoft Sentinel

Mind Maps for Create detections and perform investigations using Microsoft Sentinel

  1. Raw Data Collection: Collect data from various sources.
  2. Data Storage: Store the raw data in Sentinel tables.
  3. Parsing Functions: Apply parsing functions to transform raw data into a standardized format.
    • Parsing Types:
      • Built-in Parsers: Use pre-configured parsers for common data sources.
      • Workspace-Deployed Parsers: Deploy custom parsers for specific data sources.
  4. Source-Specific Parsers: Handle unique data formats for specific sources.
  5. Unifying Parsers: Normalize data from various sources into a unified schema.
  6. Normalized Data: Data is converted into the ASIM schema.
  7. Querying: Write queries based on the ASIM schema.

©sameer fakhoury

GitHubLinkedIn