Tools to rapidly deploy a threat hunting capability on Azure Sentinel that leverages Sysmon and MITRE ATT&CK
azure
detection
logging
cybersecurity
sysmon
threat-hunting
siem
security-tools
blue-team
mitre-attack
workbooks
sysmon-config
terraform-azure
kql
azure-sentinel
-
Updated
Jul 23, 2020 - HCL
https://github.com/microsoft/Application-Insights-Workbooks/blob/master/Documentation/Parameters/DropDown.md
there are samples there for json, query dropdowns, but they don't explain the "advanced" behaviors for
column 0 = value, column 1 = name, column 2 = selected, column 3 (or named "group") = group
which applies to all of the various dropdowns.