Azure/Azure-Sentinel Cloud-native SIEM for intelligent security analytics for your entire enterprise.

Azure Sentinel

Welcome to the Azure Sentinel repository! This repository contains out of the box detections, exploration queries, hunting queries, workbooks and playbooks to help you get ramped up with Azure Sentinel and provide you security content to secure your environment and hunt for threats. You can also submit to issues for any samples or resources you would like to see here as you onboard to Azure Sentinel. For questions and feedback, please contact [email protected]


Getting started with GitHub

Azure Sentinel documentation

Azure Sentinel Techcommunity

Azure Sentinel UserVoice
Use this to request features to our product.

Security Community Webinars


This project welcomes contributions and suggestions. Most contributions require you to agree to a
Contributor License Agreement (CLA) declaring that you have the right to, and actually do, grant us
the rights to use your contribution. For details, visit

When you submit a pull request, a CLA-bot will automatically determine whether you need to provide
a CLA and decorate the PR appropriately (e.g., label, comment). Simply follow the instructions
provided by the bot. You will only need to do this once across all repos using our CLA.

This project has adopted the Microsoft Open Source Code of Conduct.
For more information see the Code of Conduct FAQ or
contact [email protected] with any additional questions or comments.

For information on how to contribute, refer to the “how to contribute” guide on the project’s wiki.