microsoft / microsoft/AzureMonitorCommunity
How to add back a deleted Microsoft Sentinel built in query?
Nobody has claimed this yet.
- Dominant language
- PowerShell
- Stars
- 1.2k
- Forks
- 493
- PR merge metrics
- No merged PRs in 30d
Description
Hello! I am learning Microsoft Azure. I downloaded the Microsoft Sentinel Training Lab Solution. Then in MIcrosoft Sentinel, /Hunting ran the built in query 'Adding credentials to legitimate OAuth Applications' with the T1098-Account Manipulation technique. I got 5 results but on clicking the query, couldn't get the results page to pop up. So I clicked on the delete thinking I will reselect and rerun the query but looks like I deleted it from the built-in list :( Now I only see the 5 built-in queries
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start in Microsoft Sentinel’s Hunting area and review the built-in query list for “Adding credentials to legitimate OAuth Applications”; the issue names no repository file or test. Done means documenting a supported way to restore or rerun the deleted query, or clearly recording that recovery is unavailable.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- cloud, security
- Issue type
- Documentation
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 20/100