Skip to content
KitploitKITPLOIT
도구블로그
Log in
제출
도구블로그
제출

해킹, 침투 테스트 및 사이버 보안 도구를 당신의 보안 무기고에!

Kitploit은 해킹, 사이버 보안 및 침투 테스트 도구 디렉토리입니다. 최신 프로젝트 업데이트를 발견하여 취약점을 찾고, 시스템을 분석하고, 테스트를 자동화하고, 보안을 강화하세요.

··피드·문의·개인정보·© 2026 Kitploit

도구 디렉토리

카테고리

모든 카테고리 보기
Loading categories
Azure-Sentinel — 클라우드 네이티브 SIEM으로, 전체 엔터프라이즈를 위한 지능형 보안 분석 기능을 제공합니다. | Kitploit
도구/GitHubGitHub/azure/azure-sentinel
Defensive ToolsCloud SecurityThreat IntelligenceIntrusion DetectionLearning & EducationIncident ResponseCurated ResourcesLog Analysis
GitHubazure/azure-sentinel

Azure-Sentinel

클라우드 네이티브 SIEM으로, 전체 엔터프라이즈를 위한 지능형 보안 분석 기능을 제공합니다.

저장소 보기
6.1k3.8k256시간 37분 전Kitploit 검토 완료

인기

모두 보기 →

커뮤니티에서 가장 많이 사용되는 도구를 찾아보세요.

모든 도구 탐색

도구 컬렉션을 둘러보세요

모든 도구 보기 →
공유
웹사이트

Microsoft Sentinel 및 Microsoft 365 Defender

통합된 Microsoft Sentinel 및 Microsoft 365 Defender 리포지토리에 오신 것을 환영합니다! 이 리포지토리에는 즉시 사용 가능한 탐지, 탐색 쿼리, 헌팅 쿼리, 통합 문서, 플레이북 등이 포함되어 있어 Microsoft Sentinel을 빠르게 시작하고 환경을 보호하며 위협을 헌팅하는 데 도움이 되는 보안 콘텐츠를 제공합니다. 헌팅 쿼리에는 Microsoft 365 Defender 및 Microsoft Sentinel의 고급 헌팅 시나리오를 위한 Microsoft 365 Defender 헌팅 쿼리도 포함됩니다. 또한 Microsoft Sentinel에 온보딩할 때 보고 싶은 샘플이나 리소스에 대해 이슈를 제출할 수 있습니다. 이 리포지토리는 기여를 환영하며, 시작하려면 이 리포지토리의 wiki를 참조하세요. 질문이나 피드백은 [email protected]으로 문의하세요.

리소스

  • Microsoft Sentinel 설명서
  • Microsoft 365 Defender 설명서
  • 보안 커뮤니티 웨비나
  • GitHub 시작하기

귀하의 피드백을 소중히 생각합니다. 질문이나 피드백을 전달할 수 있는 몇 가지 채널은 다음과 같습니다.

  1. SIEM 및 SOAR에 대한 일반 제품별 Q&A - Microsoft Sentinel Tech Community 대화에 참여하세요.
  2. XDR에 대한 일반 제품별 Q&A - Microsoft 365 Defender Tech Community 대화에 참여하세요.
  3. 제품별 기능 요청 - Microsoft Sentinel 피드백 포럼에서 투표하거나 새로 게시하세요.
  4. 제품 또는 기여 버그 신고 - Bug 템플릿을 사용하여 GitHub Issue를 제출하세요.
  5. 커뮤니티 및 기여 프로세스에 대한 일반 피드백 - Feature Request 템플릿을 사용하여 GitHub Issue를 제출하세요.

기여 지침

이 프로젝트는 기여와 제안을 환영합니다. 대부분의 기여는 귀하가 기여를 사용할 권리가 있으며 실제로 사용할 권리를 부여한다는 것을 선언하는 기여자 라이선스 계약(CLA)에 동의해야 합니다. 자세한 내용은 https://cla.microsoft.com을 방문하세요.

GitHub에 새 기여 또는 업데이트된 기여 추가

참고: 이 리포지토리에 처음 기여하는 경우, 복제하기 전에 일반 GitHub 리포지토리 포크 가이드 또는 Sentinel 리포지토리 관련 단계를 참조하세요.

일반 단계

다음 방법을 통해 완전히 새롭거나 업데이트된 기여를 제출하세요.

  • GitHub 웹사이트에서 직접 검토를 위해 제출
    • 파일을 업로드할 폴더로 이동
    • Upload Files를 선택하고 파일을 찾습니다.
    • 자신의 브랜치를 생성한 후 검토를 위해 Pull Request를 제출해야 합니다.
  • GitHub Desktop 또는 Visual Studio 또는 VSCode 사용
    • 리포지토리 포크
    • 리포지토리 클론
    • 자신의 브랜치 생성
    • GitHub Desktop에서 추가/업데이트 수행
    • 푸시하기 전에 반드시 master를 브랜치에 병합하세요.
    • 변경 사항을 GitHub에 푸시

Pull Request

  • 변경 사항을 푸시한 후에는 Pull Request (PR)를 제출해야 합니다.
  • 제안된 변경 사항에 대한 세부 정보가 필요합니다. 검토자가 변경 이유와 코드에서 변경 사항이 무엇과 관련되어 있는지 명확히 이해할 수 있도록 최소한의 세부 정보를 포함하세요.
  • 제출 후 Pull Request에서 댓글을 확인하세요.
  • 제안된 대로 변경하거나 브랜치를 업데이트하거나 변경이 필요하지 않은 이유를 설명하세요. 완료되면 댓글을 해결하세요.

Pull Request 탐지 템플릿 구조 유효성 검사 확인

PR 검사의 일환으로 YAML 구조의 필수 부분이 모두 포함되어 있는지 확인하는 구조 유효성 검사를 실행합니다. 탐지의 경우 반드시 포함해야 하는 새 섹션이 있습니다. 자세한 내용은 기여 지침을 참조하세요. 이 섹션 또는 다른 필수 섹션이 포함되지 않으면 아래와 같은 유효성 검사 오류가 발생합니다. 예시는 YAML에 entityMappings 섹션이 누락된 경우입니다.

A total of 1 test files matched the specified pattern.
[xUnit.net 00:00:00.95]     Kqlvalidations.Tests.DetectionTemplateStructureValidationTests.Validate_DetectionTemplates_HaveValidTemplateStructure(detectionsYamlFileName: "ExcessiveBlockedTrafficGeneratedbyUser.yaml") [FAIL]
  X Kqlvalidations.Tests.DetectionTemplateStructureValidationTests.Validate_DetectionTemplates_HaveValidTemplateStructure(detectionsYamlFileName: "ExcessiveBlockedTrafficGeneratedbyUser.yaml") [104ms]
  Error Message:
   Expected object to be <null>, but found System.ComponentModel.DataAnnotations.ValidationException with message "An old mapping for entity 'AccountCustomEntity' does not have a matching new mapping entry."

Pull Request KQL 유효성 검사 확인

PR 검사의 일환으로 템플릿에 정의된 KQL 쿼리의 구문 유효성 검사를 실행합니다. 이 검사가 실패하면 PR의 checks 탭에서 오류 링크를 클릭하여 Azure Pipeline으로 이동하세요. Azurepipeline 파이프라인에서 어떤 테스트가 실패했고 원인이 무엇인지 확인할 수 있습니다. Pipeline Tests Tab

예시 오류 메시지:

A total of 1 test files matched the specified pattern.
[xUnit.net 00:00:01.81]     Kqlvalidations.Tests.KqlValidationTests.Validate_DetectionQueries_HaveValidKql(detectionsYamlFileName: "ExcessiveBlockedTrafficGeneratedbyUser.yaml") [FAIL]
  X Kqlvalidations.Tests.KqlValidationTests.Validate_DetectionQueries_HaveValidKql(detectionsYamlFileName: "ExcessiveBlockedTrafficGeneratedbyUser.yaml") [21ms]
  Error Message:
   Template Id:fa0ab69c-7124-4f62-acdd-61017cf6ce89 is not valid Errors:The name 'SymantecEndpointProtection' does not refer to any known table, tabular variable or function., Code: 'KS204', Severity: 'Error', Location: '67..93',The name 'SymantecEndpointProtection' does not refer to any known table, tabular variable or function., Code: 'KS204', Severity: 'Error', Location: '289..315'

사용자 지정 로그 테이블(기본적으로 모든 작업 영역에 정의되지 않은 테이블)을 사용하는 경우 테이블 스키마가 Azure-Sentinel\.script\tests\KqlvalidationsTests\CustomTables 폴더의 json 파일에 정의되어 있는지 확인하세요.

tablexyz.json 테이블 예시

{
  "Name": "tablexyz",
  "Properties": [
    {
      "Name": "SomeDateTimeColumn",
      "Type": "DateTime"
    },
    {
      "Name": "SomeStringColumn",
      "Type": "String"
    },
    {
      "Name": "SomeDynamicColumn",
      "Type": "Dynamic"
    }
  ]
}

로컬에서 KQL 유효성 검사 실행

Pull Request를 제출하기 전에 로컬 컴퓨터에서 KQL 유효성 검사를 실행하려면:

  • .Net Core 3.1 SDK를 설치해야 합니다 .Net 다운로드 방법 (모든 플랫폼 지원)
  • Shell을 열고 Azure-Sentinel\\.script\tests\KqlvalidationsTests\로 이동
  • dotnet test 실행

출력 예시 (Ubuntu):

Welcome to .NET Core 3.1!
----------------------
SDK Version: 3.1.403

Telemetry
---------
The .NET Core tools collect usage data in order to help us improve your experience. The data is anonymous. It is collected by Microsoft and shared with the community. You can opt-out of telemetry by setting the DOTNET_CLI_TELEMETRY_OPTOUT environment variable to '1' or 'true' using your favorite shell.

Read more about .NET Core CLI Tools telemetry: https://aka.ms/dotnet-cli-telemetry

----------------
Explore documentation: https://aka.ms/dotnet-docs
Report issues and find source on GitHub: https://github.com/dotnet/core
Find out what's new: https://aka.ms/dotnet-whats-new
Learn about the installed HTTPS developer cert: https://aka.ms/aspnet-core-https
Use 'dotnet --help' to see available commands or visit: https://aka.ms/dotnet-cli-docs
Write your first app: https://aka.ms/first-net-core-app
--------------------------------------------------------------------------------------
Test run for /mnt/c/git/Azure-Sentinel/.script/tests/KqlvalidationsTests/bin/Debug/netcoreapp3.1/Kqlvalidations.Tests.dll(.NETCoreApp,Version=v3.1)
Microsoft (R) Test Execution Command Line Tool Version 16.7.0
Copyright (c) Microsoft Corporation.  All rights reserved.

Starting test execution, please wait...
도구 다운로드