
sysmon-parser
Automatically generated Sysmon parser for Azure Sentinel

Automatically generated Sysmon parser for Azure Sentinel

Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Proof-of-concept telemetry collector for Windows LDAP client activity via ETW, logging structured events to Event Viewer with a Sentinel parser for…

Azure-based client inventory and drift detection tool that collects Windows configuration data (antivirus, patching, Bitlocker) into LogAnalytics for…

Berry Sentinel v5.0 — Advanced behavioral C2 and reverse shell detector for Linux/Windows/Unix systems. Features real-time connection analysis,…

Corelight Dashboards and Parsers for Sentinel One Singularity

The Whale Sentinel Services

Collection of KQL queries