netevert / sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
MIT License
1.05k stars 207 forks source link

Use workbooks resource inheritance to reduce crossComponentResources duplication in workbook template #11

Closed netevert closed 4 years ago

netevert commented 5 years ago

"""If the user is already opening workbooks from inside sentinel, the workspace to query should already be "set" in the workbook's resources (in edit mode, click the gear icon in the toolbar, on the resources tab you should see a workspace already listed there). If that's the case, query steps of the workbook will "inherit" that resource automatically, it doesn't need to be explicitly listed in each step."""

Originally posted by @gardnerjr in #9 (comment)