Does sentinel has any in-bulit function for Shannon's entropy like we have one in Splunk (ut_shannon())??

Prerna 1 Reputation point
2021-10-25T10:33:20.88+00:00

I am trying to work on a use-case for DGA and was thinking of using Shannon's entropy to get randomness in domain name. Splunk has a function for this but couldn't find anything similar in Sentinel. Would be of great help if we Sentinel has something similar.

Microsoft Sentinel
Microsoft Sentinel
A scalable, cloud-native solution for security information event management and security orchestration automated response. Previously known as Azure Sentinel.
986 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Prerna 1 Reputation point
    2021-10-26T09:41:32.527+00:00

    @VipulSparsh-MSFT Thanks for your response. I did go through the detailed article and the query which is pretty nice but tweaking it to our needs might be difficult. So, was just wondering if something like Splunk's entropy function/macro can be done with Sentinel.

    0 comments No comments