briandelmsft / STAT-Function

Azure Function for the Microsoft Sentinel Triage AssistanT (STAT)
https://aka.ms/mstat
MIT License
8 stars 1 forks source link

MDCA - Compare user investigation priority to top users #44

Closed briandelmsft closed 9 months ago

briandelmsft commented 10 months ago

In the MDCA module compare the current entities to the max / top 10/50/100? investigation priorities in the tenant to provide a relative sense of the users investigation priority.