-
Notifications
You must be signed in to change notification settings - Fork 208
Home
Edoardo Gerosa edited this page Feb 8, 2020
·
25 revisions
This wiki is designed to walk you through setting up Sentinel-ATT&CK in your Azure environment. It's meant to be a lightweight, to the point step-by-step guide.
Setting up Sentinel ATT&CK on Azure is quick and simple, the following steps must be performed:
- Quickly spin-up a test lab on Azure Sentinel (Optional)
- Deploy Sentinel and onboard Sysmon data
- Install the ATT&CK telemetry dashboard on Azure
- Upload selected Kusto queries into Sentinel analytics (Optional)
- Upload available threat hunting workbooks in Azure (Optional)
- Upload available threat hunting Jupyter notebooks in Azure (Optional)