Skip to content

Create Guided Investigation - MDATP Webshell Alerts.ipynb#28

Merged
petebryan merged 3 commits intoAzure:masterfrom
thmcelro:tom-webshell-investigation
May 29, 2020
Merged

Create Guided Investigation - MDATP Webshell Alerts.ipynb#28
petebryan merged 3 commits intoAzure:masterfrom
thmcelro:tom-webshell-investigation

Conversation

@thmcelro
Copy link
Contributor

New notebook to support analysts investigation MDATP alerts in Azure Sentinel.

Allows for the investigation of a shell file being dropped or a suspicious command being executed and then generates a report on findings. Provides two enrichments from web logs, the first enrichment shows the files accessed immediately prior to web shell installation, the second provides the attackers first access time.

Publication of this notebook precedes the publication of a Sentinel blog covering the analytics and investigation.

@review-notebook-app
Copy link

Check out this pull request on  ReviewNB

Review Jupyter notebook visual diffs & provide feedback on notebooks.


Powered by ReviewNB

@petebryan petebryan merged commit 7719656 into Azure:master May 29, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants