Microsoft Sentinel Security Playbooks Logo

Microsoft Sentinel Security Playbooks

0
Free
Visit Website

This repo contains sample security playbooks for security automation, orchestration and response (SOAR). Each folder contains a security playbook ARM template that uses Microsoft Sentinel trigger. Instructions for deploying a custom template: After selecting a playbook, in the Azure portal: Search for deploy a custom template Click build your own template in the editor Paste the contents from the GitHub playbook Click Save Fill in needed data and click Purchase Once deployment is complete, you will need to authorize each connection. Click the Microsoft Sentinel connection resource Click edit API connection Click Authorize Click Save Repeat steps for other connections. For Azure Log Analytics Data Collector, you will need to add the workspace ID and Key. You can now edit the playbook in Logic apps. Instructions for templatizing a playbook: Option 1: Azure Logic App/Playbook ARM Template Generator Download tool and run the PowerShell script Extract the folder and open "Playbook_ARM_Template_Generator.ps1" either in Visual Studio Code/Windows PowerShell/PowerShell Core Note The script runs from the user's machine. You must allow PowerShell script execution. To do so, run the

FEATURES

ALTERNATIVES

A remediation orchestration platform that consolidates security alerts, automates triage, and streamlines the remediation process across hybrid environments.

AIL Framework is a modular system for analyzing and detecting information leaks from unstructured data sources, with capabilities for data extraction, correlation, and integration with threat intelligence platforms.

CBRX is a cloud-based platform that automates incident analysis and reporting for cybersecurity teams.

Automated tool for scripting complex sequences in cybersecurity frameworks.

Datadog offers a comprehensive suite of cybersecurity tools for various aspects of application and infrastructure monitoring.

Exabeam Security Operations Platform is a cloud-native security platform that applies AI and automation to security operations workflows for threat detection, investigation, and response.

Fast Intercept is a security automation platform that empowers users to maximize their existing security products and automate routine tasks.

A panic button app for triggering a ripple effect across apps responding to panic events

PINNED