briandelmsft / SentinelAutomationModules

The Microsoft Sentinel Triage AssistanT (STAT) enables easy to create incident triage automation in Microsoft Sentinel
MIT License
201 stars 55 forks source link

[Feature] Security Exposure Management module #453

Open piaudonn opened 1 month ago

piaudonn commented 1 month ago

Query Security Exposure Management data to return blast radius, number of paths going from or to a user or device as well as the highest vulnerability level of the nodes. Can use the make-graph operators on the exposure nodes and edges table. Maybe support azure resource as an entity too.