Microsoft Sentinel Detection Starter
Three KQL detections plus the catalogue, tuning, hunting and review records needed to operate them.
No account and no email required. The optional email copy is available below.
How to use it
A working starting point, with the limits stated.
The useful part of a detection is not only the query. This pack pairs three KQL samples with the catalogue, tuning workflow, threat-hunt procedure and monthly review record needed to manage their lifecycle.
- Copy the files into an organisation-owned repository.
- Replace placeholders and name accountable owners.
- Review permissions, thresholds and approval points.
- Test in a controlled window and retain the evidence.
Scope note
Validate schemas, thresholds, data coverage and response ownership before enabling alerts.
Templates are operating aids. They are not certification, legal advice or a claim that a target environment is secure.
Want a copy in your inbox?
Optional email delivery makes the link easy to recover. You can download above without submitting anything.
This request does not subscribe you to the Ops Log newsletter.