Does sentinel has any in-bulit function for Shannon's entropy like we have one in Splunk (ut_shannon())??

Prerna 1 Reputation point
2021-10-25T10:33:20.88+00:00

I am trying to work on a use-case for DGA and was thinking of using Shannon's entropy to get randomness in domain name. Splunk has a function for this but couldn't find anything similar in Sentinel. Would be of great help if we Sentinel has something similar.

Microsoft Security | Microsoft Sentinel
{count} votes

1 answer

Sort by: Most helpful
  1. Prerna 1 Reputation point
    2021-10-26T09:41:32.527+00:00

    @VipulSparsh-MSFT Thanks for your response. I did go through the detailed article and the query which is pretty nice but tweaking it to our needs might be difficult. So, was just wondering if something like Splunk's entropy function/macro can be done with Sentinel.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.