sodejm/sentinel-hunt-workbench
Author and stress-test defensive Microsoft hunting workflows with deterministic offline evidence.
Adapt a defensive hunt between Microsoft hunting surfaces while preserving evidence semantics and reporting incompatibilities.
Author typed, bounded KQL for one declared Microsoft hunting surface from an approved defensive hunt contract.
Plan an authorized Microsoft Sentinel threat hunt as an observable, falsifiable, surface-specific investigation before writing KQL.
Perform a skeptical analyst and security review of a Sentinel hunt for ambiguity, evidence loss, overclaim, and unsafe operational guidance.
Stress-test an offline Sentinel hunt with curated, generated, mutation, metamorphic, scale-boundary, and hostile-content cases.
Run deterministic contract, schema, scope, compatibility, and safety validation for an offline Sentinel hunt artifact.