netevert / sentinel-attack

Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
MIT License
1.06k stars 207 forks source link

Question about the whitelist queries #53

Open secAnalyst opened 1 year ago

secAnalyst commented 1 year ago

Hello!

So I am deploying this to an instance of Sentinel I already have up and running. I added the parser, created the storage container, and uploaded the whitelists. I can't seem to figure out the custom functions for the whitelist tables. Is there any way I can get a bit of help with this?

Thanks in advance.