home.social

#defenderxdr — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #defenderxdr, aggregated by home.social.

fetched live
  1. The next breach won’t care which toolset you cobbled together. It will exploit your blind spots. Defender XDR is the only platform turn-key enough to detect, respond, and protect against threats hiding in the hybrid gray zone.

    Read more 👉 lttr.ai/ArttG

    #EliminateBlindSpots #DefenderXdr #HybridSecurity

  2. Think you’ve got security covered with a patchwork of tools? Think again. The hybrid approach is full of gaps, and attackers know exactly where to look. Defender XDR is the missing piece you can’t afford to ignore.

    Read more 👉 lttr.ai/Ap12O

    #EliminateBlindSpots #DefenderXdr #HybridSecurity

  3. Hybrid security is marketing jargon for ‘almost secure.’ In 2024, ‘almost’ isn’t good enough. Only Defender XDR delivers the integrated intelligence and speed required to outpace today’s adversaries.

    Read more 👉 lttr.ai/AoMtL

    #EliminateBlindSpots #DefenderXdr #HybridSecurity

  4. Your organization doesn’t need another checkbox. It needs comprehensive, unified defense. Enough with the fantasy of hybrid security—Defender XDR stitches the holes and shines a light on threats others can’t even see.

    Read more 👉 lttr.ai/Amvkm

    #EliminateBlindSpots #DefenderXdr #HybridSecurity

  5. Stop believing the myth that you’re protected by a mix of legacy and cloud solutions. Cutting-edge threats need cutting-edge defense. Find out why Defender XDR isn’t just an upgrade–it’s a necessity for organizations serious about security.

    Read more 👉 lttr.ai/AmU6z

    #EliminateBlindSpots #DefenderXdr #HybridSecurity

  6. When Defender XDR is broken and useless, you could play with the acronym. Here are some tongue-in-cheek expansions of XDR that imply it doesn’t work:

    • Extremely Disappointing Results
    • eXtra Downtime & Regret
    • Expect Delays, Reboots
    • Xpect Daily Restarts
    • Experimental Disaster Response
    • X-tremely Dysfunctional Resource
    • Excessive Debugging Required

    Which one is your favorite?
    #DefenderXDR

  7. When Defender XDR is broken and useless, you could play with the acronym. Here are some tongue-in-cheek expansions of XDR that imply it doesn’t work:

    • Extremely Disappointing Results
    • eXtra Downtime & Regret
    • Expect Delays, Reboots
    • Xpect Daily Restarts
    • Experimental Disaster Response
    • X-tremely Dysfunctional Resource
    • Excessive Debugging Required

    Which one is your favorite?
    #DefenderXDR

  8. Yes, Microsoft. This is exactly what I want to see when I'm responding to an incident. Let's take the time so you can tell me how great Defender XDR is. Much better use of my time than responding to the incident.

    #IncidentResponse #DefenderXDR

  9. Yes, Microsoft. This is exactly what I want to see when I'm responding to an incident. Let's take the time so you can tell me how great Defender XDR is. Much better use of my time than responding to the incident.

    #IncidentResponse #DefenderXDR

  10. Narrator: Early morning, on a sunny Friday, our hero opens #DefenderXDR

    Me: Cool no incidents.

    Narrator: Couple hours later

    Me: Oh there is a new incident!

    Narrator: Continues checking the incident details, including the creation date...

    ME: THREE DAYS AGO WFT?!

  11. Narrator: Early morning, on a sunny Friday, our hero opens #DefenderXDR

    Me: Cool no incidents.

    Narrator: Couple hours later

    Me: Oh there is a new incident!

    Narrator: Continues checking the incident details, including the creation date...

    ME: THREE DAYS AGO WFT?!

  12. It seems my team mates still have time work, so they must be able to look at even more applicant for this #SOC analyst role in Switzerland!

    recruitingapp-2563.umantis.com

    #FediHire #DefenderXDR #AzureSentinel

  13. It seems my team mates still have time work, so they must be able to look at even more applicant for this #SOC analyst role in Switzerland!

    recruitingapp-2563.umantis.com

    #FediHire #DefenderXDR #AzureSentinel

  14. Me voy a cagar en Movistar y en la Liga, porque me parece mucha casualidad. Tengo cientos de alertas en Defender XDR de cientos de equipos contactando con C&C, y cuando investigo las IP veo que son CDN y que son de #Cloudflare. Nosotros no hemos metido la gamba y bloqueado estas IP, así que tiene que venir de Microsoft, de su intel, que por algún motivo las ha identificado como C2.

    Y aquí lo que me huelo: espero que los bloqueos de la Liga no hayan empezado a afectar a terceros, proveedores de seguridad, que al compartir intel hayan incluido esas IP de Cloudflare como maliciosas. Porque es que no encuentro otra explicación, salvo que haya un gañán en Microsoft bloqueando lo que no debe. Y encima en viernes, qué casualidad también.

    #ciberseguridad #LaLiga #DefenderXDR

  15. Me voy a cagar en Movistar y en la Liga, porque me parece mucha casualidad. Tengo cientos de alertas en Defender XDR de cientos de equipos contactando con C&C, y cuando investigo las IP veo que son CDN y que son de #Cloudflare. Nosotros no hemos metido la gamba y bloqueado estas IP, así que tiene que venir de Microsoft, de su intel, que por algún motivo las ha identificado como C2.

    Y aquí lo que me huelo: espero que los bloqueos de la Liga no hayan empezado a afectar a terceros, proveedores de seguridad, que al compartir intel hayan incluido esas IP de Cloudflare como maliciosas. Porque es que no encuentro otra explicación, salvo que haya un gañán en Microsoft bloqueando lo que no debe. Y encima en viernes, qué casualidad también.

    #ciberseguridad #LaLiga #DefenderXDR

  16. The November 2024 edition of Microsoft's monthly blog post highlights product updates and new features across their Defender products. Notably, the Microsoft Defender XDR & Microsoft Sentinel have been unified into a single Security Operations Platform. The update also includes improvements to advanced hunting in the Microsoft Defender portal, with users now able to use the arg() operator for Azure Resource Graph queries without needing to go to Log Analytics in Microsoft Sentinel. Other enhancements include added Unified RBAC roles with new permission levels for Threat Experts customers, Insider Risk Management insights integrated into Defender XDR, and an updated training video on how to use the Alert page.

    Microsoft has also introduced several new features for its Sentinel platform including matching analytics for threat detection and a Use Cases Mapper workbook. They've completely updated their Ninja Training program which now points you towards official MS Learning paths so you can earn badges upon completion. There are strategies outlined on how you can save money on your Sentinel ingestion costs by reducing data volume while still collecting necessary information. Additionally, they discuss Cowrie honeypot integration with Microsoft Sentinel and deploying Sentinel using Bicep among other things. To learn more about these updates and others not mentioned here, check out the full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  17. Do you use Microsoft Defender for Endpoint? If so, do you have full automation enabled for MDE’s Automated Investigation and Remediation (AIR) feature? You should. Great feature and I’ve never seen a false positive. #cybersecurity #microsoft #DefenderXDR

    learn.microsoft.com/en-us/defe

  18. Do you use Microsoft Defender for Endpoint? If so, do you have full automation enabled for MDE’s Automated Investigation and Remediation (AIR) feature? You should. Great feature and I’ve never seen a false positive. #cybersecurity #microsoft #DefenderXDR

    learn.microsoft.com/en-us/defe

  19. The article discusses the importance of understanding and mitigating data exfiltration risks in today's complex security landscape. It highlights the integration of Insider Risk Management (IRM) insights into Microsoft's Defender XDR user page, which provides enhanced visibility into insider risk severity and exfiltration activities. This integration allows Security Operations Center (SOC) teams to detect and respond more effectively to insider threats, distinguishing between external and internal attacks.

    Microsoft Purview Insider Risk Management adds value by identifying potential insider risks such as data leaks or intellectual property theft. The system detects unusual employee behavior, manages data exfiltration risks from insiders performing risky activities, and differentiates between external and internal attacks. By integrating IRM insights on the XDR user page, SOC analysts gain a deeper understanding of a user’s behavior and risk profile. If you're interested in learning more about how this technology can help protect your organization from both internal and external threats, check out the full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  20. I am working on my #AzColorizer browser extension to include support colorizing the #DefenderXDR portal and I just accidentally colorized all the buttons, and it LOOKS 🔥

    What do you think?

    The use case here is that in multi-tenant situations the colors could be set for every tenant and the color would change when you switch to another organization.

  21. I am working on my #AzColorizer browser extension to include support colorizing the #DefenderXDR portal and I just accidentally colorized all the buttons, and it LOOKS 🔥

    What do you think?

    The use case here is that in multi-tenant situations the colors could be set for every tenant and the color would change when you switch to another organization.

  22. The October 2024 edition of Microsoft's monthly blog post highlights the latest updates and improvements across their Defender products. Notable enhancements include the general availability of global search for entities in the Microsoft Defender portal, which centralizes results from all entities. The Copilot feature in Defender now includes an identity summary capability that provides instant insights into a user's risk level, sign-in activity, and more. Other significant updates include new features to detect browser anomalies and disrupt attacks early, view featured threat intelligence articles on the home page of Microsoft Defender portal, submit inquiries and view responses from Microsoft Defender Experts, defend against crypto mining attacks with cloud workload alerts integration into Defender XDR.

    To learn more about these exciting developments as well as other product updates like advanced hunting context panes available in more experiences or research analysis ensuring Android security update adoption among others - do check out this comprehensive blog post by Microsoft! It also offers valuable insights into automatic attack disruption strategy via 'Defender for Identity' along with guidance on proactive risk management through 'Microsoft Security Exposure Management'. So don't miss out!
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  23. In the ever-evolving world of cybersecurity, security operation centers (SOCs) are often overwhelmed by a high volume of incidents that require time-consuming manual investigation. To help tackle this issue, Microsoft has introduced Copilot for Security guided response - an AI-driven system designed to assist analysts in efficiently navigating these incidents. The system provides real-time recommendations for investigation, triaging and remediation which helps reduce downtime and prevent potential breaches. However, implementing such a system comes with its own set of challenges including complexity of security incidents, high precision requirements, scalability issues and adaptability to SOC preferences.

    Microsoft's Copilot guided response introduces advanced AI-driven features to streamline the incident response process. It enhances three critical aspects: incident triaging, remediation action recommendation and similar incident investigation. By using historical data and machine learning techniques it reduces manual workload on SOC analysts while improving response times and increasing precision in both triaging and remediation efforts. This not only improves detection speed but also ensures that analysts have relevant information at every stage of the investigation process. For more insights into how Microsoft is transforming security responses with AI technology through their Copilot guided response tool, you can read up on their post.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  24. Microsoft has introduced a new feature for its Copilot for Security, the Identity Summary skill. Available within Microsoft Defender XDR and Copilot for Security portals, this tool provides a natural language summary of user behavioral anomalies and potential misconfigurations. It helps security teams to uncover discrepancies and security gaps in real-time, thereby enhancing an organization's overall security posture.

    The Identity Summary is designed to offer insights into identity behavior and misconfigurations, helping organizations quickly identify and resolve potential security issues. The feature can be triggered within the Defender Experience by navigating to a user page. It covers various aspects like login locations, role changes, devices used by the user, failed login attempts, authentication methods used by the user etc., providing a comprehensive view of identities. To learn more about how you can integrate this feature into your security practices to strengthen your defenses against evolving cybersecurity threats visit the original post.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  25. Detecting browser anomalies is key to identifying and preventing cyber threats early on. These detections can spot unusual session activities, helping to prevent attackers from impersonating legitimate users and gaining access to user credentials. Microsoft Defender XDR offers a variety of tools for detecting these anomalies and automatically disrupting attacks, minimizing their impact by isolating compromised assets. The blog post provides insights into using browser anomalies and malicious sign-in traits for attack disruption at the earliest stages.

    The systematic approach used by Microsoft Defender XDR includes data collection, baseline establishment, real-time monitoring and anomaly detection, as well as correlating threat intelligence. This robust system helps identify potential threats via browser anomalies through thorough analysis of patterns in browser-related information during user sign-in events. If you're interested in enhancing your organization's security measures against cyber threats like Adversary-in-the-Middle attacks or Business Email Compromise (BEC), this article is definitely worth a read.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  26. Microsoft Defender XDR is fighting back against increasingly sophisticated cyber-threats with its automatic attack disruption feature. This AI-powered tool uses correlated signals to stop and prevent further damage from in-progress attacks, recognizing the intent of an attacker and predicting their next move with high confidence. The benefits include disrupting attacks at machine speed (average time of 3 minutes), reducing the impact of attacks by limiting lateral movement within your network, and enhancing security operations by allowing teams to focus on other potential threats.

    The role of Microsoft Defender for Identity is also crucial in this process as it delivers critical identity signals and response actions to the platform. It helps protect through identity-specific posture recommendations, detections, and response actions. In terms of attack disruption, it enables user specific responses like disabling compromised accounts or forcing password resets when credentials have been compromised. To learn more about how Microsoft Defender XDR's automatic disruption capability can enhance your cybersecurity strategy, check out the full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  27. The article discusses the importance of integrating XDR and cloud security insights to defend against advanced attacks like cryptojacking and IaaS resource theft. It highlights how Microsoft Defender for Cloud, integrated into Microsoft Defender XDR, enhances the ability to detect, investigate, and respond to sophisticated threats across hybrid and multi-cloud environments. The piece also presents a case study on defeating a crypto mining attack that started with a phishing email and ended in cloud resource exploitation.

    The case study demonstrates how the integration of Defender for Cloud strengthens native signals in Defender XDR enabling organizations to effectively defend against complex attacks traversing entire attack surfaces including cloud infrastructure. This seamless correlation of alerts ensures swift threat mitigation. In conclusion, this integration represents significant advancement in cybersecurity as it enables understanding and stopping sophisticated threats before they cause harm. To learn more about this powerful integration that keeps IT and cloud environments resilient against evolving threats, check out the full post.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  28. Microsoft has released its September 2024 edition of the monthly news for Defender XDR, summarizing product updates and new assets across their Defender products. The company announced that Microsoft Sentinel data is now available with Defender XDR data in Microsoft Defender multitenant management, which shows security information and event management (SIEM) data from one Microsoft Sentinel workspace per tenant. In addition to this, they have also discussed new management settings for multitenant management. They've also revealed that Defender for Endpoint and Defender for Identity now support local data residency in India.

    In other updates, a webinar exploring OT security is coming up on September 11th where attendees will learn about digital transformation's impact on security challenges in industrial processes and critical infrastructure as well as how Defender XDR is changing the way we safeguard critical assets. Furthermore, enhancements have been made to vulnerability prioritization with asset context and EPSS while predefined Identity classifications were added to the critical assets list under Security Exposure Management. Lastly, Global exclusions for Linux are now publicly previewed along with Network Protection feature being enabled by default on Android devices among others. To get more detailed insights into these updates visit the original post.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  29. Microsoft has introduced a new sensor for its Defender for Identity service on Entra Connect servers, aimed at enhancing security across hybrid identity environments. The sensor is designed to help organizations better prevent, detect and remediate credential theft and privilege escalation attacks that are often initiated against Entra Connect. This comes as part of Microsoft's ongoing commitment to expanding Defender for Identity’s coverage, given that identities are one of the most targeted attack vectors by cyber-criminals.

    The new sensor provides comprehensive monitoring of synchronization activities between Entra Connect and Active Directory, offering crucial insights into potential security threats and unusual activities. It also offers specific security alerts and posture recommendations related to Entra Connect. Furthermore, it includes additional improvements like enhanced accuracy for DC sync attack detection, extended monitoring for security alerts among others. To learn more about how this tool can enhance your organization's cybersecurity measures, check out the full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  30. Hello everyone! We're thrilled to share some updates to the PowerShell module for Microsoft Defender for Identity. The new enhancements are designed to add more functionality and address feedback from users. One of the key features includes a new MDI service account cmdlet, which will be used for remote Security Account Manager (SAM) access and is provisioned in the portal for Defender for Identity Active Directory operations. Additionally, we've introduced automatic Primary Domain Controller Emulator (PDCe) role detection feature that requires no intervention and increases reliability of Group Policy Object creation.

    We've also added manual domain controller targeting if PDC detection fails or you prefer having control over everything. There are user experience enhancements as well like dynamic GPOPrefix parameter, support for Danish language, changes and updates to GPO content setting among others. If you want more information on this module, do check out the PowerShell Gallery and reference documentation links provided in the article above! Your continued usage and feedback is much appreciated as we work on releasing the next version.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  31. Microsoft has announced that its Defender for Endpoint and Defender for Identity now support local data residency in India. This move is part of Microsoft's commitment to aligning with local data sovereignty requirements, enabling customers to onboard confidently knowing their data will remain within the Indian boundary. This helps them meet regulatory obligations and maintain control over their data.

    In addition to India, these services are also available in the United States, European Union, United Kingdom, Australia, and Switzerland. New deployments are automatically created in the Azure region closest to your location. Existing customers can check their deployment geo within the portal or contact Customer Service and Support for a tenant reset if they want to update their service location. For more information on this topic or how you can benefit from it as a customer or potential user of Microsoft's services visit [this link](techcommunity.microsoft.com/t5).
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  32. Microsoft has announced that its Defender for Endpoint and Defender for Identity now support local data residency in India. This move is part of Microsoft's commitment to aligning with local data sovereignty requirements, enabling customers to onboard confidently knowing their data will remain within the Indian boundary. This helps them meet regulatory obligations and maintain control over their data.

    In addition to India, these services are also available in the United States, European Union, United Kingdom, Australia, and Switzerland. New deployments are automatically created in the Azure region closest to your location. Existing customers can check their deployment geo within the portal or contact Customer Service and Support for a tenant reset if they want to update their service location. For more information on this topic or how you can benefit from it as a customer or potential user of Microsoft's services visit [this link](techcommunity.microsoft.com/t5).
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  33. Security operation centers (SOCs) are being overwhelmed by the increasing number of cybersecurity threats and alerts. To manage this, Microsoft has developed a unified security operations platform that uses alert correlation to consolidate disparate alerts into cohesive incidents, reducing the workload for analysts. The platform combines Microsoft Defender XDR and Microsoft Sentinel with AI specifically built for cybersecurity. This innovative approach is projected to save 7.2 million analyst hours annually, equating to $241M per year across all customers.

    The blog post delves deeper into how incident correlation works and its challenges such as mitigating false correlations, minimizing missed correlations, scalability issues, and domain knowledge requirements. It also discusses how Microsoft's unique correlation technology addresses these issues through innovations like geo-distributed architecture, graph-based approach, continuous adaptation among others resulting in over 99% accuracy in correlations. If you're interested in learning more about this cutting-edge solution to modern cybersecurity challenges or want insights into the research behind it - do check out their post. #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  34. The August 2024 edition of Microsoft's monthly blog post highlights the latest updates to their Defender products. The unified security operations platform, which combines the capabilities of Microsoft Sentinel, Microsoft Defender XDR, and Microsoft Copilot in the Defender portal is now generally available. Other new features include customizable columns in Incidents and Alerts queues, filtering for Cloud alerts by associated alert subscription ID, visibility of incidents where a compromised device communicated with an operational technology (OT) device through the Defender for IoT license and Endpoint’s device discovery capabilities. Additionally, critical assets are now part of tags in incident and alert queues.

    Microsoft has also introduced Security Exposure Management that provides a unified view of security posture across company assets and workloads. This solution enriches asset information with security context to help manage attack surfaces proactively, protect critical assets, and explore & mitigate exposure risk. Learning hub resources have moved from the Defender portal to learn.microsoft.com offering Ninja training modules among others. For more details on these updates or other improvements like UrlClickEvents table availability in advanced hunting or releasing/moving email messages from quarantine back to user's inbox directly from Take actions feature etc., check out their full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  35. Registration is now open for our Defender XDR Learning Group!

    This learning group will be exploring subject areas encompassing Defender XDR with the M365 Business Premium license. Starting in August, we’ll be meeting every other week on Thursdays for 10 sessions to discuss chapter content, test configurations and deployments, and work in our lab tenant(s).

    #m365 #Microsoft365BusinessPremium #defenderXDR
    thirdtier.net/product/learning

  36. Registration is now open for our Defender XDR Learning Group!

    This learning group will be exploring subject areas encompassing Defender XDR with the M365 Business Premium license. Starting in August, we’ll be meeting every other week on Thursdays for 10 sessions to discuss chapter content, test configurations and deployments, and work in our lab tenant(s).

    #m365 #Microsoft365BusinessPremium #defenderXDR
    thirdtier.net/product/learning

  37. Australia and USA time zones! We're going to be holding class for 20 hours over the course of 6 months to learn, test and develop SOPs. Plenty of time to soak it in. Register now.

    thirdtier.net/product/learning
    #M365 #microsoft365 #defenderxdr #microsoftdefender
    thirdtier.net/product/learning

  38. Australia and USA time zones! We're going to be holding class for 20 hours over the course of 6 months to learn, test and develop SOPs. Plenty of time to soak it in. Register now.

    thirdtier.net/product/learning
    #M365 #microsoft365 #defenderxdr #microsoftdefender
    thirdtier.net/product/learning

  39. The convergence of Operational Technology (OT) and Information Technology (IT) has introduced new security challenges, particularly in the realm of industrial processes and critical infrastructure. Microsoft is addressing these issues with its Defender XDR platform, which provides comprehensive protection for OT environments. The system integrates Defender for IoT as a native component to address unique cybersecurity challenges faced by organizations across OT industries. It replaces disconnected tools and fragmented analyst experiences with a streamlined platform that breaks down silos between IT and OT environments.

    Microsoft's solution offers several capabilities including agentless discovery for all devices and environments, unified incident management, physical site security, unified vulnerability management for IT and OT, risk-based vulnerability management, and Copilot for Security in OT environments. These features allow businesses to better secure their entire digital landscape from one single platform while reducing complexity and costs. If you're interested in learning more about how Microsoft Defender XDR can help protect your systems against emerging threats while ensuring safety, productivity, reliability - check out the full article.
    Post generated with the help of Azure OpenAI GPT4 🤖 #msftadvocate #M365Defender #DefenderXDR techcommunity.microsoft.com/t5

  40. For M365 admins newsletter is all about catching up with Defender XDR. There will not be a newsletter next week as I continue my holiday. But trust me, there's plenty of reading here. And then be sure to sign up for our 10-session course to not only learn but to build your deployment SOP.

    pblc.me/pub/6656c9bacd9d94
    #microsoft365 #defenderXDR #cybersecurity
    pblc.me/pub/6656c9bacd9d94

  41. For M365 Admins - Recovery. This week's newsletter. Focus on cyber incident recovery. What Microsoft is offering different industries. Third Tier's Defender XDR course is open for registration. #Micrososft365 #M365 #cybersecurity #DefenderXDR #M365BusinessPremium @msftnews pblc.me/pub/4d687b93deb637

  42. Registration is now open for our Defender XDR Learning Group!

    This learning group will be learning and exploring subject areas encompassing Defender XDR with the M365 Business Premium license. Starting in August, we’ll be testing configurations and deployments, and work in our lab tenant(s). The sessions will be recorded, and we may build some shared best practice guides and SOPs as an outgrowth of our work together.

    #m365 #Microsoft365BusinessPremium #defenderXDR
    thirdtier.net/product/learning

  43. This week, in the for M365 admins newsletter, the focus is on preventing Token theft. In the news, I also share information you need to know to help your clients use Copilot and other AI services.

    #entraID #cybersecurity #DefenderXDR #AI
    pblc.me/pub/9496c3045ee76e

  44. This weeks M365 admin newsletter is out! Here's your link. There's a sign-up at the bottom if you're like to get it in your Inbox each Monday. pblc.me/pub/64300c943bf0fb

    #microsoft365 #MSP #MSSP #entraID #Intune #DefenderXDR #copilot

  45. Made a thing for poking around sigma rules adonm.github.io/stlite-apps/ap including conversion to defender kql

    Source is up github.com/adonm/stlite-apps/b (less than 100 lines!), streamlit lite is quite nice to play with

    rules are grabbed from here - github.com/SigmaHQ/sigma

  46. 𝐂𝐨𝐩𝐢𝐥𝐨𝐭 𝐟𝐨𝐫 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲: 𝐞𝐥𝐞𝐦𝐞𝐧𝐭𝐬 𝐨𝐟 𝐚𝐧 𝐞𝐟𝐟𝐞𝐜𝐭𝐢𝐯𝐞 𝐩𝐫𝐨𝐦𝐩𝐭

    From the "Get started with Microsoft Copilot for Security" online training, I highlight this interesting in-depth analysis.

    𝐄𝐟𝐟𝐞𝐜𝐭𝐢𝐯𝐞 𝐩𝐫𝐨𝐦𝐩𝐭𝐬 give Copilot adequate and useful parameters to generate a valuable response. Security analysts or researchers should include the following elements when writing a prompt.

    💡 𝐆𝐨𝐚𝐥 - specific, security-related information that you need

    💡𝐂𝐨𝐧𝐭𝐞𝐱𝐭 - why you need this information or how you'll use it

    💡𝐄𝐱𝐩𝐞𝐜𝐭𝐚𝐭𝐢𝐨𝐧𝐬 - format or target audience you want the response tailored to

    💡𝐒𝐨𝐮𝐫𝐜𝐞 - known information, data sources, or plugins Copilot should use

    At this link other prompting tips:

    learn.microsoft.com/en-us/trai

    Full training: learn.microsoft.com/en-us/trai

    #copilot #copilotforsecurity #securitycopilot #microsoft #microosoftsecurity #llm #openai #azureopenai #llmapps #soc #generativeai #genai #cybersecurity #azure #cloudsecurity #cloudnative #defender #sentinel #microsoftsentinel #xdr #defenderxdr #prompt #promptengineering

  47. 𝐄𝐱𝐩𝐥𝐨𝐫𝐢𝐧𝐠 𝐭𝐡𝐞 𝐧𝐞𝐰 𝐈𝐓𝐃𝐑 𝐞𝐱𝐩𝐞𝐫𝐢𝐞𝐧𝐜𝐞 𝐰𝐢𝐭𝐡𝐢𝐧 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫

    The new ITDR dashboard is designed to provide SOC professionals with a single, prioritized view of Identity-specific security information and recommendations.

    For more information, see:

    techcommunity.microsoft.com/t5

    #itdr #defender #defenderxdr #identity #security #microsoft #microsoftsecurity #mdi #entraid #azuread #Identitythreatdetection #cloud #cloudsecurity #soc #cloudnative

  48. 𝐌𝐚𝐧𝐚𝐠𝐞 𝐲𝐨𝐮𝐫 𝐝𝐞𝐯𝐢𝐜𝐞𝐬 𝐰𝐢𝐭𝐡 𝐞𝐚𝐬𝐞 𝐮𝐬𝐢𝐧𝐠 𝐝𝐲𝐧𝐚𝐦𝐢𝐜 𝐫𝐮𝐥𝐞𝐬 𝐟𝐨𝐫 𝐝𝐞𝐯𝐢𝐜𝐞 𝐭𝐚𝐠𝐠𝐢𝐧𝐠 𝐢𝐧 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐃𝐞𝐟𝐞𝐧𝐝𝐞𝐫

    We are excited to announce that dynamic rules for tagging devices is now generally available. This feature enables security teams to create and manage rules that automatically assign and remove tags from devices based on user-defined criteria directly in the Microsoft Defender portal.

    Dynamic tags:

    - simplify tag management,

    - reduce manual efforts,

    - facilitate efficient device tracking,

    - simplify compliance by automatically categorizing non-compliant devices

    techcommunity.microsoft.com/t5

    #edr #xdr #defender #defenderxdr #microsoft365defender #endpoint #management #tag #device #compliance #microsoft #microsoftsecurity #soc #cloudsecurity #cloud #cloudnative

  49. Get the e-book, 𝐓𝐡𝐞 𝐏𝐚𝐭𝐡 𝐭𝐨 𝐀𝐈: 𝐏𝐚𝐯𝐞 𝐭𝐡𝐞 𝐰𝐚𝐲 𝐟𝐨𝐫 𝐩𝐨𝐰𝐞𝐫𝐟𝐮𝐥 𝐜𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐀𝐈 𝐰𝐢𝐭𝐡 𝐢𝐧𝐭𝐞𝐠𝐫𝐚𝐭𝐞𝐝 𝐗𝐃𝐑 𝐚𝐧𝐝 𝐒𝐈𝐄𝐌

    You'll find information about:

    ➡ 𝐓𝐡𝐞 𝐏𝐚𝐭𝐡 𝐭𝐨 𝐀𝐈: how integrated XDR and SIEM can help organizations prepare for using generative AI cybersecurity tools such as Microsoft Security Copilot.

    ➡𝐓𝐡𝐞 𝐂𝐡𝐚𝐥𝐥𝐞𝐧𝐠𝐞𝐬 𝐨𝐟 𝐂𝐲𝐛𝐞𝐫𝐬𝐞𝐜𝐮𝐫𝐢𝐭𝐲: the common problems that security teams face, such as increasing attacks, expanding attack surfaces, talent shortage, and tool complexity.

    ➡𝐓𝐡𝐞 𝐁𝐞𝐧𝐞𝐟𝐢𝐭𝐬 𝐨𝐟 𝐈𝐧𝐭𝐞𝐠𝐫𝐚𝐭𝐞𝐝 𝐗𝐃𝐑 𝐚𝐧𝐝 𝐒𝐈𝐄𝐌: how combining XDR and SIEM can provide end-to-end visibility, speed, accuracy, and efficiency for security operations, as well as reducing costs and risks.

    ➡𝐓𝐡𝐞 𝐏𝐨𝐭𝐞𝐧𝐭𝐢𝐚𝐥 𝐨𝐟 𝐆𝐞𝐧𝐞𝐫𝐚𝐭𝐢𝐯𝐞 𝐀𝐈: Microsoft Security Copilot, the first generative AI security analysis tool, and how it can amplify security operations with natural language prompts, insights, guidance, and predictions.

    ➡𝐓𝐡𝐞 𝐍𝐞𝐱𝐭 𝐒𝐭𝐞𝐩𝐬 𝐭𝐨 𝐓𝐚𝐤𝐞: exploring deployment options and learn more about Microsoft’s SIEM and XDR solutions and Security Copilot.

    info.microsoft.com/ww-landing-

    #generativeai #genai #ai #xdr #siem #defenderxdr #defender #sentinel #soar #cybersecurity #cloudnative #cloudsecurity #security #copilot #securitycopilot #microsoft #microsoftsecurity #soc

  50. 𝐁𝐞𝐜𝐨𝐦𝐞 𝐚 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐎𝐂 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦 𝐍𝐢𝐧𝐣𝐚

    We are bringing together Microsoft Sentinel and Defender XDR to deliver the most optimized and unified security operations platform.

    It's time to update with a new Ninja training. 🥋

    Note: The integration of Microsoft Sentinel into the Defender portal is currently in private preview,

    techcommunity.microsoft.com/t5

    #microsoft #microsoftsecurity #sentinel #microsoftsentinel #siem #soar #xdr #defenderxdr #soc #defender #azure #cybersecurity #training #hunting #automation #cloudsecurity #cloudnative