A collection of tools and documentation for Microsoft Sentinel practitioners.
Hi, I'm Ofer Shezaf – an InfoSec professional with extensive experience in security research, product definition, and customer-facing activities. I've been working in this field since before "InfoSec" became "Cyber"!
I believe that creating security products requires a unique blend of technology, customer requirements, security expertise, and understanding customer perception of risk. Throughout my career, I've focused on the junction of these disciplines to create security solutions that effectively reduce both real and perceived cyber risk.
Currently, I'm a Principal Product Manager working on Microsoft Sentinel at Microsoft.
Comprehensive reference documentation for Microsoft Sentinel Solutions, automatically generated from the Azure-Sentinel repository using the Solutions Analyzer tool – which I also developed and maintain as part of the Azure-Sentinel repository.
Browse:
- Solutions Index – 495 solutions (393 with connectors, 396 with content)
- Connectors Index – 536 data connectors
- Collection Methods Index – 11 data collection methods
- Tables Index – 2,023 Log Analytics tables
- Content Index – 6,092 content items (analytics, hunting, playbooks, workbooks)
- Parsers Index – 538 non-ASIM parsers
- ASIM Parsers Index – 95 ASIM parser pairs by schema
- ASIM Products Index – 80 products with ASIM support
- Statistics – Comprehensive statistics and metrics
CSV data files are also available in the Solutions Docs directory for programmatic analysis. See the output file documentation for column descriptions.
- solutions.csv – All solutions with marketplace status and content counts
- connectors.csv – All data connectors with collection method, CCF capabilities, and filter fields
- tables.csv – All tables with solution/connector references and feature support
- content_items.csv – All content items (analytics rules, hunting queries, playbooks, etc.)
- parsers.csv – Non-ASIM parsers with source tables and solution references
- asim_parsers.csv – ASIM parsers with schema, source tables, and sub-parser references
- tables_reference.csv – Table metadata from Azure Monitor and Sentinel documentation
- table_schemas.csv – Column schemas from DCR definitions, Azure Monitor docs, and KQL validation
- content_tables_mapping.csv – Mapping of content items to tables with read/write indicators
- solutions_connectors_tables_mapping.csv – Full mapping of solutions to connectors to tables
- solutions_connectors_tables_mapping_simplified.csv – Simplified version of the above mapping
- solution_dependencies.csv – Dependencies between solutions (explicit and ASIM-based)
- solutions_connectors_tables_issues_and_exceptions_report.csv – Issues and exceptions found during analysis
- Azure-Sentinel GitHub Repository – Cloud-native SIEM for intelligent security analytics
- Microsoft Sentinel Documentation
See LICENSE for details.
Built with 🥷 for the Microsoft Sentinel community