{"repo":"noodlemctwoodle/Sentinel-As-Code","free":true,"listed":false,"github":"https://github.com/noodlemctwoodle/Sentinel-As-Code","clone":"git clone https://github.com/noodlemctwoodle/Sentinel-As-Code.git","description":"An automation framework for deploying Microsoft Sentinel environments using pipelines. This project combines infrastructure-as-code (Bicep) with PowerShell automation to streamline the deployment of Sentinel solutions, analytics rules, and workbooks.","language":"PowerShell","stars":71,"topics":["automation","azure-devops","microsoft-security","microsoft-sentinel","powershell","secdevops","bicep","defender-xdr","unified-soc"],"license":"Apache-2.0","category":"workflow-automation","readme_excerpt":"Sentinel As Code Overview This repository provides a complete end-to-end CI/CD solution for deploying Microsoft Sentinel environments using Azure DevOps pipelines or GitHub Actions. Starting from an empty subscription, the pipeline provisions all required infrastructure via Bicep, deploys Content Hub solutions (the source of truth for out-of-the-box content), deploys custom content (detections, watchlists, playbooks, workbooks, hunting queries, automation rules, summary rules), and deploys Defender XDR custom detection rules - all from a single repo. It ships with a five-job PR validation gate, a nightly end-to-end smoke test against a dedicated test workspace, daily portal-drift detection that absorbs edits back into the repo as PRs, an auto-derived dependency graph, a workbook round-trip exporter, and thirteen cross-platform GitHub Copilot agents that work on github.com and in every supported IDE so authors can build, edit, tune, and explain content with repo-aware AI assistance. ### 💛 For organisations using this repository Sentinel-As-Code is built and maintained on my own time as an open source project. I spend countless hours developing, testing, documenting, and supporting the work that lands in this repository - at no cost to the people and organisations who benefit from it. If you are an organisation deploying this code into production , or if it has saved your team meaningful engineering time, please consider supporting the project. Your contribution directly funds","default_branch":null,"files":null,"tree":[],"storefront":"/r/noodlemctwoodle","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/noodlemctwoodle/Sentinel-As-Code/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}