SOC KQL Workbench
Admin
Azure Monitor / Sentinel Connection
Checking Azure status…
AI & Data Masking
Only masked schema and sample rows are sent to the AI assistant. Raw tenant rows are never included in assistant context.
AI provider: openai (gpt-4o) — active when AI_PROVIDER=openai and OPENAI_API_KEY are set.
Local Storage
Query history and detection drafts are persisted in browser localStorage.
Query history: 0 runs
Detection drafts: 0 saved