This document provides an overview of using notebooks in Azure Sentinel for hunting and investigations. Notebooks allow you to create interactive documents containing live code, visualizations, and narrative text. They provide benefits like a full scripting environment, data persistence, sharing capabilities, and access to various libraries. The document recommends building notebooks on the fly for deep investigations or hunting, and authoring reusable notebooks as templates. It also lists KQL Magic and MSTICPY as tools for using KQL and the Microsoft Threat Intelligence Python SDK in notebooks.
This document provides an overview of using notebooks in Azure Sentinel for hunting and investigations. Notebooks allow you to create interactive documents containing live code, visualizations, and narrative text. They provide benefits like a full scripting environment, data persistence, sharing capabilities, and access to various libraries. The document recommends building notebooks on the fly for deep investigations or hunting, and authoring reusable notebooks as templates. It also lists KQL Magic and MSTICPY as tools for using KQL and the Microsoft Threat Intelligence Python SDK in notebooks.
This document provides an overview of using notebooks in Azure Sentinel for hunting and investigations. Notebooks allow you to create interactive documents containing live code, visualizations, and narrative text. They provide benefits like a full scripting environment, data persistence, sharing capabilities, and access to various libraries. The document recommends building notebooks on the fly for deep investigations or hunting, and authoring reusable notebooks as templates. It also lists KQL Magic and MSTICPY as tools for using KQL and the Microsoft Threat Intelligence Python SDK in notebooks.
Also read Why Use Jupyter for Security Investigations
• Building notebooks on the fly • Tier 3 Analysts requiring deep investigation capability • Hunters/Threat Intel analysts • Authoring reusable notebooks • By Tier 3 analysts and SOC Engineering • For use as template notebooks by Tier 1+ • KQL Magic • MSTICPY Notebooks lab