Azure/Azure-Sentinel
Cloud-native SIEM for intelligent security analytics for your entire enterprise. observed · 2026-08-28
Health v2 · maintenance only
77/100
- Activity 99
- Release rhythm 35
- Longevity 100
Flags: no_releases
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: n/a
- age_days: 2938
- days_rel: n/a
- days_push: 7
- n_releases_24m: 0
Adoption not part of the score
6076 stars · 3790 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
The official community repository for Microsoft Sentinel, a cloud-native SIEM, containing out-of-the-box detections, hunting queries, workbooks, playbooks, and sample code. It provides security analytics content for threat detection and hunting across Microsoft Sentinel and Microsoft 365 Defender environments.
Use cases
- find hunting queries for threat detection in Microsoft Sentinel
- get out-of-the-box detection rules for my SOC
- build KQL queries for Microsoft 365 Defender advanced hunting
- automate incident response with Sentinel playbooks
- contribute security analytics content to a SIEM
- set up workbooks for security monitoring dashboards
When to choose
- you use Microsoft Sentinel or Microsoft 365 Defender and need ready-made detection and hunting content
- you want community-contributed playbooks, workbooks, and queries for Azure security operations
- you are building a SOC on Azure and want to accelerate onboarding
When to avoid
- you need a standalone open-source SIEM rather than content for Microsoft's paid cloud SIEM
- your environment is not on Azure or Microsoft 365
- you want a self-hosted SIEM like Wazuh or Elastic Security
Facets
application · maturity active
security monitoring alerting analytics search-engine security cloud-computing monitoring cloud self-hosted python siem soc threat-hunting microsoft-sentinel detection-rules kql playbooks soar microsoft-365-defender security-content devops
9 sources
- readme: https://github.com/Azure/Azure-Sentinel · fetched 2026-08-28 · f09a82678868
- homepage: https://azure.microsoft.com/en-us/services/azure-sentinel/ · fetched 2026-08-29 · 528d0ea8d7b7
- site_page: https://learn.microsoft.com/docs · fetched 2026-08-29 · f29800be2b9a
- site_page: https://www.microsoft.com/about · fetched 2026-08-29 · 2d2954f13574
- site_page: https://choice.microsoft.com/ · fetched 2026-08-29 · 2db73202bb74
- site_page: https://www.microsoft.com/en-in/security/pricing-overview · fetched 2026-08-29 · 3af8533684b6
- site_page: https://learn.microsoft.com/en-in/security · fetched 2026-08-29 · 0050f9841ee4
- site_page: https://www.microsoft.com/en-in/security/pricing/microsoft-sentinel · fetched 2026-08-29 · 31d0e485bb15
- site_page: https://www.microsoft.com/en-in/security/microsoft-defender-pricing · fetched 2026-08-29 · 109c8108aa4a
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| Azure/Azure-Sentinel | main | 77 |
For agents
markdown · JSON · MCP: product_card(name="Azure/Azure-Sentinel")
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem