Skip to content

Add Lookout Mobile Threat Detection hunting notebooks#289

Open
fgravato wants to merge 1 commit intoAzure:masterfrom
fgravato:lookout/threat-hunting-notebooks
Open

Add Lookout Mobile Threat Detection hunting notebooks#289
fgravato wants to merge 1 commit intoAzure:masterfrom
fgravato:lookout/threat-hunting-notebooks

Conversation

@fgravato
Copy link

Summary

Adds 4 Lookout Mobile Threat Detection hunting notebooks to scenario-notebooks/:

  • Guided Hunting - Lookout Mobile Malware Analysis — Investigate high-severity mobile malware, analyze malicious packages, and track detection trends
  • Guided Hunting - Lookout Smishing Detection — Hunt SMS phishing attacks, identify impersonation patterns, and detect coordinated campaigns
  • Guided Hunting - Lookout Device Compliance — Monitor device compliance posture, identify non-compliant devices, and track MDM integration gaps
  • Guided Hunting - Lookout Audit and Insider Threat — Investigate administrative actions, detect unauthorized policy changes, and identify potential insider threats

Data Sources

  • LookoutMtdV2_CL custom log table (via Lookout Codeless Connector Framework)
  • LookoutEvents KQL parser

Related

  • Lookout solution in Azure-Sentinel (PR #13651)
  • All notebooks follow the Guided Hunting naming convention and include standard metadata headers

- Guided Hunting - Lookout Mobile Malware Analysis
- Guided Hunting - Lookout Smishing Detection
- Guided Hunting - Lookout Device Compliance
- Guided Hunting - Lookout Audit and Insider Threat

These notebooks leverage the LookoutMtdV2_CL table and LookoutEvents
parser for threat hunting across mobile malware, SMS phishing, device
compliance, and audit/insider threat scenarios.
@review-notebook-app
Copy link

Check out this pull request on  ReviewNB

See visual diffs & provide feedback on Jupyter Notebooks.


Powered by ReviewNB

@fgravato
Copy link
Author

fgravato commented Mar 3, 2026

Bump

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant