diff --git a/README.md b/README.md index 1ce2271..b2af3b6 100644 --- a/README.md +++ b/README.md @@ -60,6 +60,7 @@ All contributions are welcome, please carefully review the [contributing guideli - [Loghub](https://github.com/logpai/loghub) - Opensource and freely available security data sources for research and testing. - [Elastalert | Yelp](https://github.com/Yelp/elastalert) - ElastAlert is a simple framework for alerting on anomalies, spikes, or other patterns of interest from data in Elasticsearch. - [Matano](https://github.com/matanolabs/matano) - Open source cloud-native security lake platform (SIEM alternative) for threat hunting, Python detections-as-code, and incident response on AWS 🦀. +- [Microsoft XDR Advanced Hunting Schema](https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-schema-tables) To help with multi-table queries, you can use the advanced hunting schema, which includes tables and columns with event information and details about devices, alerts, identities, and other entity types. ## General Resources