discovered 03 Aug 2026
sentinel-attack
→ View on GitHubSentinel ATT&CK is a tool designed to facilitate the deployment of a threat hunting capability utilizing Sysmon logs within Azure Sentinel, aligned with the MITRE ATT&CK framework. It includes a Sysmon log parser that is mapped to the OSSEM data model and provides a modular XML configuration for effective log analysis. Users must perform tuning and trialing to optimize the tool's effectiveness for production environments.