Skip to content

Commit bbb3cc1

Browse files
committed
init
0 parents  commit bbb3cc1

36 files changed

Lines changed: 4173 additions & 0 deletions

‎.github/workflows/ci.yml‎

Lines changed: 61 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,61 @@
1+
name: Build & Release
2+
3+
on:
4+
push:
5+
branches: [master]
6+
7+
permissions:
8+
contents: write
9+
10+
jobs:
11+
build-and-release:
12+
runs-on: ubuntu-latest
13+
14+
steps:
15+
- uses: actions/checkout@v4
16+
17+
- uses: actions/setup-node@v4
18+
with:
19+
node-version: 20
20+
cache: npm
21+
22+
- run: npm ci
23+
24+
- name: Typecheck
25+
run: npx tsc --noEmit
26+
27+
- name: Build
28+
run: npm run build
29+
30+
- name: Verify userscript header
31+
run: head -1 dist/sentinel-userscript.user.js | grep -q '// ==UserScript=='
32+
33+
- name: Generate release tag
34+
id: tag
35+
run: |
36+
TAG="build-$(date -u +'%Y.%m.%d-%H%M%S')"
37+
echo "TAG=$TAG" >> "$GITHUB_OUTPUT"
38+
echo "DATE=$(date -u +'%B %d, %Y at %H:%M:%S UTC')" >> "$GITHUB_OUTPUT"
39+
40+
- name: Create GitHub Release
41+
uses: softprops/action-gh-release@v2
42+
with:
43+
tag_name: ${{ steps.tag.outputs.TAG }}
44+
name: Build - ${{ steps.tag.outputs.DATE }}
45+
body: |
46+
## Microsoft Sentinel & Defender: Threat Hunting Queries
47+
48+
**Built from** `${{ github.sha }}` on ${{ steps.tag.outputs.DATE }}
49+
50+
### Installation
51+
1. Install [Tampermonkey](https://www.tampermonkey.net/) in your browser
52+
2. Click **sentinel-userscript.user.js** below to auto-install in Tampermonkey
53+
3. Open Tampermonkey dashboard → Utilities → Import from file
54+
4. Select the downloaded `.js` file
55+
56+
Or install directly from the raw URL:
57+
```
58+
https://github.com/${{ github.repository }}/releases/download/${{ steps.tag.outputs.TAG }}/sentinel-userscript.user.js
59+
```
60+
files: dist/sentinel-userscript.user.js
61+
generate_release_notes: true

‎.gitignore‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,5 @@
1+
node_modules/
2+
dist/
3+
*.png
4+
!docs/*.png
5+
.DS_Store

‎LICENSE‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
MIT License
2+
3+
Copyright (c) 2026 Ludovic COULON
4+
5+
Permission is hereby granted, free of charge, to any person obtaining a copy
6+
of this software and associated documentation files (the "Software"), to deal
7+
in the Software without restriction, including without limitation the rights
8+
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
9+
copies of the Software, and to permit persons to whom the Software is
10+
furnished to do so, subject to the following conditions:
11+
12+
The above copyright notice and this permission notice shall be included in all
13+
copies or substantial portions of the Software.
14+
15+
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
16+
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
17+
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
18+
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
19+
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
20+
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
21+
SOFTWARE.

‎README.md‎

Lines changed: 49 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,49 @@
1+
# Microsoft Sentinel & Defender: Threat Hunting Queries
2+
3+
Tampermonkey userscript that adds a threat hunting query menu to **Microsoft Sentinel** and **Microsoft Defender** Advanced Hunting pages.
4+
5+
Browse, search, pin, and inject KQL queries directly into the Monaco editor.
6+
7+
## Screenshots
8+
9+
| Defender (dark mode) | Sentinel | Sentinel (popup) |
10+
|---|---|---|
11+
| ![Defender](docs/defender-dark.png) | ![Sentinel](docs/sentinel-button.png) | ![Popup](docs/sentinel-popup.png) |
12+
13+
## Features
14+
15+
- Inline "Threat Hunting Queries" button in the command bar
16+
- Tabs: **User Rules** (bundled), **Reprise99**, **Bert-JanP** (fetched from GitHub)
17+
- Search across query name, description, category, and KQL content
18+
- Pin queries for quick access (horizontal pill bar above results)
19+
- Click any query row to inject it into the editor
20+
- Works in both Sentinel (reactblade iframe) and Defender (security.microsoft.com)
21+
- Light/dark theme support via Azure Portal CSS variables
22+
23+
## Install
24+
25+
1. Install [Tampermonkey](https://www.tampermonkey.net/)
26+
2. Click **[Install Userscript](https://raw.githubusercontent.com/LasCC/MicrosoftSentinel-Userscript/main/dist/sentinel-userscript.user.js)** (auto-installs in Tampermonkey)
27+
3. Navigate to Advanced Hunting in Sentinel or Defender
28+
29+
## Public Rule Sources
30+
31+
| Repo | Queries | Format |
32+
|------|---------|--------|
33+
| [reprise99/Sentinel-Queries](https://github.com/reprise99/Sentinel-Queries) | ~460 | `.kql` files |
34+
| [Bert-JanP/Hunting-Queries-Detection-Rules](https://github.com/Bert-JanP/Hunting-Queries-Detection-Rules) | ~445 | `.md` with fenced KQL |
35+
36+
Rules are fetched lazily on first tab click, cached locally for 1 hour.
37+
38+
## Build
39+
40+
```
41+
npm install
42+
npm run build
43+
```
44+
45+
Output: `dist/sentinel-userscript.user.js`
46+
47+
## Related
48+
49+
- [SentinelOne Userscript](https://github.com/LasCC/SentinelOne-Userscript) - Similar project for SentinelOne

‎docs/defender-dark.png‎

46.1 KB
Loading

‎docs/sentinel-button.png‎

64.7 KB
Loading

‎docs/sentinel-popup.png‎

83.2 KB
Loading

0 commit comments

Comments
 (0)