Azure-Sentinel: Cloud-Native SIEM for Intelligent Security Analytics
This repository profile is provided by osrepos.com, an open source repository discovery platform.

Summary
Azure-Sentinel is a powerful cloud-native SIEM solution designed for intelligent security analytics across your entire enterprise. This GitHub repository serves as a comprehensive resource, providing out-of-the-box detections, exploration queries, hunting queries, workbooks, and playbooks. It helps security teams quickly ramp up with Microsoft Sentinel and Microsoft 365 Defender, enhancing threat detection and hunting capabilities.
Repository Information
Topics
Click on any tag to explore related repositories
Use at your own risk
OSRepos shares public repositories for knowledge and discovery only. Any installation, execution, configuration, or use of code from these repositories is the user's own responsibility. Always review the repository, source code, dependencies, licenses, and security implications before running or installing anything. OSRepos is not responsible for issues, damages, or losses resulting from third-party repositories.
Introduction
The Azure-Sentinel GitHub repository is the official hub for content related to Microsoft Sentinel, a scalable, cloud-native Security Information and Event Management (SIEM) solution. It provides intelligent security analytics for your entire enterprise, offering a unified experience with Microsoft 365 Defender. This repository is a treasure trove for security professionals, containing a vast collection of out-of-the-box detections, exploration queries, hunting queries, workbooks, and playbooks. Its primary goal is to help users quickly get started with Microsoft Sentinel, secure their environments, and proactively hunt for threats.
Getting Started with Content and Contributions
While Azure-Sentinel itself is a service, this repository provides the essential content to maximize its utility. To begin leveraging the content, you can explore the various folders containing detections, queries, and other resources directly.
For those interested in contributing to this vibrant community, the repository welcomes new content and suggestions. Contributions typically involve agreeing to a Contributor License Agreement (CLA) and following specific guidelines for submitting changes. The process generally involves forking the repository, creating a new branch, making your additions or updates, and then submitting a Pull Request for review. Detailed steps and guidance for getting started with contributions can be found on the project's wiki.
Examples of Content
Within this repository, you will find a rich array of security content designed to enhance your threat detection and response capabilities:
- Detections: Pre-built rules and logic to identify known threats and suspicious activities.
- Exploration Queries: Kusto Query Language (KQL) queries to investigate security incidents and data.
- Hunting Queries: Advanced KQL queries specifically crafted for proactive threat hunting in both Microsoft Sentinel and Microsoft 365 Defender.
- Workbooks: Interactive dashboards and reports for visualizing security data and insights.
- Playbooks: Automated response actions (Azure Logic Apps) to streamline incident handling.
These examples provide practical tools and templates to secure your environment and improve your security posture.
Why Use Azure-Sentinel and This Repository?
Microsoft Sentinel, supported by this repository, offers numerous benefits for modern security operations:
- Cloud-Native SIEM: Leverage the scalability, flexibility, and cost-effectiveness of a cloud-based SIEM solution.
- Intelligent Security Analytics: Utilize advanced analytics and machine learning to detect sophisticated threats.
- Unified Security Experience: Seamlessly integrate with Microsoft 365 Defender for comprehensive XDR (Extended Detection and Response) capabilities.
- Rich Content Library: Access a constantly growing collection of community-driven and Microsoft-provided security content, including detections, queries, and automation playbooks.
- Proactive Threat Hunting: Empower your security team with tools and queries to actively search for threats before they cause damage.
- Community Support: Benefit from an active community and dedicated support channels for questions and feedback.
Important Links
- GitHub Repository: Azure/Azure-Sentinel
- Microsoft Sentinel Documentation: Official Documentation
- Microsoft 365 Defender Documentation: Official Documentation
- Microsoft Sentinel Tech Community: Join the Conversation
- Microsoft 365 Defender Tech Community: Join the Conversation
- Microsoft Sentinel Feedback Forums: Provide Feedback
- Project Wiki (Contribution Guidelines): Get Started
Related repositories
Similar repositories that may be relevant next.

Anthropic Cybersecurity Skills: 754 Structured Skills for AI Agents
May 24, 2026
This repository offers the largest open-source library of 754 structured cybersecurity skills designed for AI agents. It maps these skills across five industry frameworks, including MITRE ATT&CK and NIST CSF 2.0, enabling AI agents to perform expert-level security analysis and operations. The project aims to empower AI with practitioner playbooks to address the global cybersecurity workforce gap.

Fix Inventory: Open-Source Cloud Security Posture Management for Multi-Cloud
May 2, 2026
Fix Inventory is an open-source tool for cloud and security engineers, designed to identify and remediate critical risks across AWS, GCP, Azure, and Kubernetes. It provides a graph-based data model to collect, normalize, and triage security risks in multi-cloud infrastructure, offering a powerful alternative to proprietary cloud security solutions. Written in Python, it supports over 300 cloud services and various security use cases.

Citadel: A Binary Static Analysis Framework for Malware Research
March 20, 2026
Citadel is a robust binary static analysis framework tailored for payload analysis and malware research. It provides comprehensive PE parsing, capability detection, and similarity analysis through a modern web interface, helping researchers understand why implants are detected statically.
Malwoverview: A Comprehensive Tool for Malware Analysis and Threat Intelligence
March 10, 2026
Malwoverview is a powerful rapid response tool designed for cybersecurity professionals, efficiently gathering intelligence from numerous sources like VirusTotal, Hybrid Analysis, and Malpedia. It provides a holistic view of malware samples, URLs, and IP addresses. Additionally, the tool includes robust features for checking Android device vulnerabilities and retrieving vulnerability records from NIST, making it an indispensable asset for threat hunting and incident response.
Source repository
Open the original repository on GitHub.