home.social

#microsoftsentinel — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #microsoftsentinel, aggregated by home.social.

  1. New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
    Read the blog 👉 marshsecurity.org/sentinel-sat

    In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.

    Most teams aren’t getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.

    - Auto-create tasks when automation fails (so nothing slips through the cracks)
    - Auto-complete tasks when automation succeeds
    - Use tasks to verify automation outcomes
    - Build engineering feedback loops and automation #QA

    Read the blog 👉 marshsecurity.org/sentinel-sat

    #MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
    #CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
    #CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations

  2. 🕵️‍♂️ KQL is both a science and an art.

    If you’ve ever felt your Sentinel queries were running slow or costing more than they should, you’re not alone.
    This week’s #SentinelSaturdays covers how to write leaner, faster, more efficient KQL queries with practical examples you can use today.

    🔗 Read the full walkthrough here: marshsecurity.org/sentinel-ski

    Share your comments 👇
    What’s YOUR top KQL tip or favourite optimisation trick?

    Let’s build a thread of practical advice for the hunting community.
    #MicrosoftSentinel #KQL #ThreatHunting #SecurityOperations

  3. 🎁 NEW UPDATE:

    I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

    More will be coming soon!

    #KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
    👇
    academy.bluraven.io/course/int

  4. 𝐂𝐨𝐩𝐢𝐥𝐨𝐭 𝐟𝐨𝐫 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲: 𝐞𝐥𝐞𝐦𝐞𝐧𝐭𝐬 𝐨𝐟 𝐚𝐧 𝐞𝐟𝐟𝐞𝐜𝐭𝐢𝐯𝐞 𝐩𝐫𝐨𝐦𝐩𝐭

    From the "Get started with Microsoft Copilot for Security" online training, I highlight this interesting in-depth analysis.

    𝐄𝐟𝐟𝐞𝐜𝐭𝐢𝐯𝐞 𝐩𝐫𝐨𝐦𝐩𝐭𝐬 give Copilot adequate and useful parameters to generate a valuable response. Security analysts or researchers should include the following elements when writing a prompt.

    💡 𝐆𝐨𝐚𝐥 - specific, security-related information that you need

    💡𝐂𝐨𝐧𝐭𝐞𝐱𝐭 - why you need this information or how you'll use it

    💡𝐄𝐱𝐩𝐞𝐜𝐭𝐚𝐭𝐢𝐨𝐧𝐬 - format or target audience you want the response tailored to

    💡𝐒𝐨𝐮𝐫𝐜𝐞 - known information, data sources, or plugins Copilot should use

    At this link other prompting tips:

    learn.microsoft.com/en-us/trai

    Full training: learn.microsoft.com/en-us/trai

    #copilot #copilotforsecurity #securitycopilot #microsoft #microosoftsecurity #llm #openai #azureopenai #llmapps #soc #generativeai #genai #cybersecurity #azure #cloudsecurity #cloudnative #defender #sentinel #microsoftsentinel #xdr #defenderxdr #prompt #promptengineering

  5. 𝐍𝐞𝐰 𝐮𝐬𝐞 𝐜𝐚𝐬𝐞𝐬 𝐟𝐨𝐫 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐩𝐢𝐥𝐨𝐭

    📣 The new use cases for Security Copilot now extend beyond investigations in your security operations center to support various security necessities for organizations seeking to strengthen their security against cyberthreats.

    ➡Device management

    ➡Identity management

    ➡Data security

    ➡Cloud security

    ➡External attack surface management

    📣Security Copilot is expanding into embedded experiences across various Microsoft Security solutions!

    microsoft.com/en-us/security/b

    #copilot #security #securitycopilot #llm #ai #genai #openai #microsoft #microsoftsecurity #cybersecurity #intune #purview #entraid #soc #xdr #siem #soar #cloud #cloudnative #cloudsecurity #sentinel #microsoftsentinel #cnapp #defenderforcloud #defender #easm #threatintelligence

  6. 𝐍𝐞𝐰 𝐮𝐬𝐞 𝐜𝐚𝐬𝐞𝐬 𝐟𝐨𝐫 𝐌𝐢𝐜𝐫𝐨𝐬𝐨𝐟𝐭 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐂𝐨𝐩𝐢𝐥𝐨𝐭

    📣 The new use cases for Security Copilot now extend beyond investigations in your security operations center to support various security necessities for organizations seeking to strengthen their security against cyberthreats.

    ➡Device management

    ➡Identity management

    ➡Data security

    ➡Cloud security

    ➡External attack surface management

    📣Security Copilot is expanding into embedded experiences across various Microsoft Security solutions!

    microsoft.com/en-us/security/b

    #copilot #security #securitycopilot #llm #ai #genai #openai #microsoft #microsoftsecurity #cybersecurity #intune #purview #entraid #soc #xdr #siem #soar #cloud #cloudnative #cloudsecurity #sentinel #microsoftsentinel #cnapp #defenderforcloud #defender #easm #threatintelligence

  7. Today, we are thrilled to announce the next major step in this industry-defining vision: combining the power of leading solutions in security information and event management (𝐒𝐈𝐄𝐌), extended detection and response (𝐗𝐃𝐑), and generative AI for security into the first 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦..

    techcommunity.microsoft.com/t5

    #microsoft #microsoftdefender #microsoftdefenderxdr #xdr #siem #soar #sentinel #microsoftsentinel #ai #aisecurity #cybersecurity #soc #genai #generativeai #gpt #azure #microsoftecurity #soc #analyst #copilot #securitycopilot #ignite #microsoftignite #kql

  8. Today, we are thrilled to announce the next major step in this industry-defining vision: combining the power of leading solutions in security information and event management (𝐒𝐈𝐄𝐌), extended detection and response (𝐗𝐃𝐑), and generative AI for security into the first 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦..

    techcommunity.microsoft.com/t5

    #microsoft #microsoftdefender #microsoftdefenderxdr #xdr #siem #soar #sentinel #microsoftsentinel #ai #aisecurity #cybersecurity #soc #genai #generativeai #gpt #azure #microsoftecurity #soc #analyst #copilot #securitycopilot #ignite #microsoftignite #kql

  9. Today, we are thrilled to announce the next major step in this industry-defining vision: combining the power of leading solutions in security information and event management (𝐒𝐈𝐄𝐌), extended detection and response (𝐗𝐃𝐑), and generative AI for security into the first 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦..

    techcommunity.microsoft.com/t5

    #microsoft #microsoftdefender #microsoftdefenderxdr #xdr #siem #soar #sentinel #microsoftsentinel #ai #aisecurity #cybersecurity #soc #genai #generativeai #gpt #azure #microsoftecurity #soc #analyst #copilot #securitycopilot #ignite #microsoftignite #kql

  10. Today, we are thrilled to announce the next major step in this industry-defining vision: combining the power of leading solutions in security information and event management (𝐒𝐈𝐄𝐌), extended detection and response (𝐗𝐃𝐑), and generative AI for security into the first 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦..

    techcommunity.microsoft.com/t5

    #microsoft #microsoftdefender #microsoftdefenderxdr #xdr #siem #soar #sentinel #microsoftsentinel #ai #aisecurity #cybersecurity #soc #genai #generativeai #gpt #azure #microsoftecurity #soc #analyst #copilot #securitycopilot #ignite #microsoftignite #kql

  11. Today, we are thrilled to announce the next major step in this industry-defining vision: combining the power of leading solutions in security information and event management (𝐒𝐈𝐄𝐌), extended detection and response (𝐗𝐃𝐑), and generative AI for security into the first 𝐔𝐧𝐢𝐟𝐢𝐞𝐝 𝐒𝐞𝐜𝐮𝐫𝐢𝐭𝐲 𝐎𝐩𝐞𝐫𝐚𝐭𝐢𝐨𝐧𝐬 𝐏𝐥𝐚𝐭𝐟𝐨𝐫𝐦..

    techcommunity.microsoft.com/t5

    #microsoft #microsoftdefender #microsoftdefenderxdr #xdr #siem #soar #sentinel #microsoftsentinel #ai #aisecurity #cybersecurity #soc #genai #generativeai #gpt #azure #microsoftecurity #soc #analyst #copilot #securitycopilot #ignite #microsoftignite #kql

  12. Did you know there's documentation available that includes details on the data collected by Azure Monitor from various sources?

    Take a look at the Security data—it can be invaluable if you're working with Microsoft Sentinel! 🔒

    learn.microsoft.com/en-us/azur

    #AzureMonitor #MicrosoftSentinel #CyberSecurity #sentinel #siem #soar #log #loganalytics #schema #asim #soc #analyst #cloud #cloudsecurity #microsoft #azure #cybersecurity

  13. Did you know there's documentation available that includes details on the data collected by Azure Monitor from various sources?

    Take a look at the Security data—it can be invaluable if you're working with Microsoft Sentinel! 🔒

    learn.microsoft.com/en-us/azur

    #AzureMonitor #MicrosoftSentinel #CyberSecurity #sentinel #siem #soar #log #loganalytics #schema #asim #soc #analyst #cloud #cloudsecurity #microsoft #azure #cybersecurity

  14. Did you know there's documentation available that includes details on the data collected by Azure Monitor from various sources?

    Take a look at the Security data—it can be invaluable if you're working with Microsoft Sentinel! 🔒

    learn.microsoft.com/en-us/azur

    #AzureMonitor #MicrosoftSentinel #CyberSecurity #sentinel #siem #soar #log #loganalytics #schema #asim #soc #analyst #cloud #cloudsecurity #microsoft #azure #cybersecurity

  15. Did you know there's documentation available that includes details on the data collected by Azure Monitor from various sources?

    Take a look at the Security data—it can be invaluable if you're working with Microsoft Sentinel! 🔒

    learn.microsoft.com/en-us/azur

    #AzureMonitor #MicrosoftSentinel #CyberSecurity #sentinel #siem #soar #log #loganalytics #schema #asim #soc #analyst #cloud #cloudsecurity #microsoft #azure #cybersecurity

  16. Did you know there's documentation available that includes details on the data collected by Azure Monitor from various sources?

    Take a look at the Security data—it can be invaluable if you're working with Microsoft Sentinel! 🔒

    learn.microsoft.com/en-us/azur

    #AzureMonitor #MicrosoftSentinel #CyberSecurity #sentinel #siem #soar #log #loganalytics #schema #asim #soc #analyst #cloud #cloudsecurity #microsoft #azure #cybersecurity

  17. ClientInspector – a cool showcase to demonstrate Log ingestion API, Azure Log Ingestion Pipeline, Azure Data Collection Rules and my new Powershell module AzLogDcrIngestPS rodtrent.com/ebt

    #MicrosoftSentinel #Azure #AzureMonitor #Cybersecurity #MicrosoftSecurity #Security