- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Too long lines (1000+ characters) 38 files: Guided Triage - Alerts.ipynb Guided Investigation - Solarwinds Post Compromise Activity.ipynb utils/generate-nb-toc.ipynb machine-learning-notebooks/Guided Hunting - Anomaly detection with Isolation Forest on Windows Logon data For Data Scientist .ipynb machine-learning-notebooks/Guided Investigation - Anomalous users generated by Isolation Forest Model for SOC Analysts.ipynb src/SentinelUtilities/SentinelAnomalyLookup/anomaly_finder.py A Getting Started Guide For Azure Sentinel ML Notebooks.ipynb Guided Investigation - Process-Alerts.ipynb tutorials-and-examples/other-language-kernels/A Getting Started Guide For CSharp AML Notebooks.ipynb tutorials-and-examples/example-notebooks/VirusTotal File Behavior Explorer - MS and Sysmon detonation.ipynb tutorials-and-examples/example-notebooks/Recorded Future Sigma Rules Importer.ipynb tutorials-and-examples/example-notebooks/Example - Using Sentinel Search Queries.ipynb tutorials-and-examples/example-notebooks/msticpy demo.ipynb tutorials-and-examples/example-notebooks/Example - Guided Investigation - Process-Alerts.ipynb tutorials-and-examples/example-notebooks/Senserva Connections Graph Notebook.ipynb tutorials-and-examples/example-notebooks/M365 Defender - hunting.ipynb tutorials-and-examples/deprecated-notebooks/Get Started.ipynb tutorials-and-examples/deprecated-notebooks/Entity Explorer - Windows Host.ipynb tutorials-and-examples/deprecated-notebooks/Entity Explorer - Linux Host.ipynb tutorials-and-examples/training-notebooks/A Python Crash Course - Part 1 - Fundamentals.ipynb tutorials-and-examples/feature-tutorials/Base64Unpack.ipynb tutorials-and-examples/feature-tutorials/EventClustering.ipynb tutorials-and-examples/feature-tutorials/GeoIPLookups.ipynb tutorials-and-examples/feature-tutorials/VirusTotalLookup.ipynb tutorials-and-examples/feature-tutorials/FoliumMap.ipynb tutorials-and-examples/feature-tutorials/PivotFunctions-Introduction.ipynb tutorials-and-examples/feature-tutorials/NotebookWidgets.ipynb tutorials-and-examples/feature-tutorials/EventTimeline.ipynb tutorials-and-examples/feature-tutorials/VTLookupV3.ipynb tutorials-and-examples/feature-tutorials/TimeSeriesAnomaliesVisualization.ipynb tutorials-and-examples/feature-tutorials/MPSettingsEditor.ipynb tutorials-and-examples/feature-tutorials/Data_Queries.ipynb tutorials-and-examples/feature-tutorials/PivotFunctions.ipynb Guided Investigation - Anomaly Lookup.ipynb scenario-notebooks/Guided Hunting - Office365-Exploring.ipynb scenario-notebooks/Guided Investigation - WAF data.ipynb scenario-notebooks/AffectedKeyCredentials-CVE-2021-42306.ipynb Guided Hunting - Covid-19 Themed Threats.ipynb - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Too long file (1000000+ bytes) 15 files: src/data/failed_logons_det_df.pkl src/data/exchange_admin.pkl src/data/combined_df.pkl src/data/processes_on_host.pkl tutorials-and-examples/example-notebooks/MSTICPy Tour.ipynb tutorials-and-examples/example-notebooks/data/processes_on_host.pkl tutorials-and-examples/example-notebooks/data/all_events_df.pkl tutorials-and-examples/example-notebooks/Example - Guided Hunting - Office365-Exploring.ipynb tutorials-and-examples/deprecated-notebooks/Example - Step-by-Step Linux-Windows-Office Investigation.ipynb tutorials-and-examples/training-notebooks/Training - MSTICPy Training 3 - 2022-01-13.ipynb tutorials-and-examples/feature-tutorials/DataViewer.ipynb tutorials-and-examples/feature-tutorials/data/procs_with_cluster.pkl tutorials-and-examples/feature-tutorials/TIProviders.ipynb tutorials-and-examples/feature-tutorials/AnomalousSequence.ipynb tutorials-and-examples/feature-tutorials/ProcessTree.ipynb - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Hidden files and folders path like ".*/[.][a-zA-Z0-9_]+.*" 1 files: .gitignore - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Git history path like ".*/git[-]history[.]txt" 1 files: git-history.txt - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -