Sentinel-attack import
sentinel-attack → deploy pack
Deploy the ATT&CK detection library in Sentinel with sentinel-attack, importing the analytic rules from the framework coverage.
Use it when you want to deploy ATT&CK coverage in Sentinel at once: sentinel-attack (from BlueTeamLabs) imports the analytic rules mapped to techniques (those from the library, based on community and Microsoft detections) and deploys them in the workspace with their MITRE mapping. It is the starting point for Sentinel coverage: the main technique rules deployed and ready for tuning. In purple teaming with Sentinel, sentinel-attack accelerates the base coverage — the deployed rules are validated with exercises and adjusted to the environment.
Do not deploy it without reviewing the scope: the full library is hundreds of rules — mass deployment generates noise (generic rules trigger in the real environment) and cost; deploy in phases (the priority techniques of the risk) and in test mode first. The library rules are generic: those for the environment are adapted (fields, indexes) — the library is the starting point, not the final detection. And beware: sentinel-attack is maintained by the community — compatibility with Sentinel versions is verified. The deployed rules are validated with purple team (atomics) before trusting.