What problem does it solve?
Microsoft Sentinel hunting, analytic-rule, and detection authoring guidance — table-domain decision matrix, identity/cloud workload schemas (SigninLogs, AuditLogs, AzureActivity, OfficeActivity, CommonSecurityLog), TimeGenerated discipline, ResultType code patterns, NRT vs scheduled rule constraints, watchlists, ASIM caveats, materialise+arg_max+coalesce TI patterns, row_window_session sessionisation, BehaviorAnalytics/IdentityInfo enrichment. Always pair with kusto-query-language for language-level optimisation. Use for configurations.sentinel blocks in OpenTide MDR objects and Sentinel-first hypotheses.
Core Features & Use Cases
- Guidance on Sentinel data domains, schema usage, and decision matrices for efficient hunting.
- Best-practice patterns for rule authorship, telemetry correlation, and MITRE mapping.
- Real-world workflows including watchlists, TI enrichment, and cross-table joins.
Quick Start
Use this skill to guide the creation of Sentinel analytic rules with correct table references and timing discipline.