- 
                Notifications
    You must be signed in to change notification settings 
- Fork 207
Home
        Edoardo Gerosa edited this page Feb 8, 2020 
        ·
        25 revisions
      
    This wiki is designed to walk you through setting up Sentinel-ATT&CK in your Azure environment. It's meant to be a lightweight step-by-step guide.
This wiki can also be used as a basic "training boot-camp" to get to know Azure Sentinel and it's features
Setting up Sentinel ATT&CK on Azure is quick and simple, the following steps must be performed:
- Quickly spin-up a test lab on Azure Sentinel (Optional)
- Deploy Sentinel and onboard Sysmon data
- Install the ATT&CK telemetry dashboard on Azure
- Upload selected Kusto queries into Sentinel analytics (Optional)
- Upload available threat hunting workbooks in Azure (Optional)
- Upload available threat hunting Jupyter notebooks in Azure (Optional)