#microsoftsentinel โ Public Fediverse posts
Live and recent posts from across the Fediverse tagged #microsoftsentinel, aggregated by home.social.
-
Found a way to bypass Entra ID's single-tenant restriction! By leveraging Azure Lighthouse, you can centralize Entra ID logs from multiple tenants into a single Microsoft Sentinel workspace for unified retention.
-
๐จ Turn threat intelligence into action in @microsoft Sentinel
With the CrowdSec Sentinel Playbook, enrich your alerts using CrowdSecโs CTI and automatically detect malicious IPs involved in auth or security events.
Learn more ๐ https://doc.crowdsec.net/u/cti_api/api_integration/integration_ms_sentinel/
-
New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
Read the blog ๐ https://marshsecurity.org/sentinel-saturday-using-tasks-with-automation/In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.
Most teams arenโt getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.
- Auto-create tasks when automation fails (so nothing slips through the cracks)
- Auto-complete tasks when automation succeeds
- Use tasks to verify automation outcomes
- Build engineering feedback loops and automation #QARead the blog ๐ https://marshsecurity.org/sentinel-saturday-using-tasks-with-automation/
#MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
#CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
#CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations -
๐จ GreyNoise for Microsoft Sentinel is here!
Filter out internet background noise automatically. Focus on real threats.
#MicrosoftSentinel #AppAssure -
๐ต๏ธโโ๏ธ KQL is both a science and an art.
If youโve ever felt your Sentinel queries were running slow or costing more than they should, youโre not alone.
This weekโs #SentinelSaturdays covers how to write leaner, faster, more efficient KQL queries with practical examples you can use today.๐ Read the full walkthrough here: https://marshsecurity.org/sentinel-skills-saturday-edition-one/
Share your comments ๐
Whatโs YOUR top KQL tip or favourite optimisation trick?Letโs build a thread of practical advice for the hunting community.
#MicrosoftSentinel #KQL #ThreatHunting #SecurityOperations -
Microsoft Unveils Sentinel Data Lake to Power AI Defenses and Cut Security Costs
#Cybersecurity #Microsoft #MicrosoftSentinel #AI #CloudSecurity #SIEM #DataLake
-
AI Validation for Sentinel Queries: Smarter KQL with Uncoder AI โ Source: socprime.com https://ciso2ciso.com/ai-validation-for-sentinel-queries-smarter-kql-with-uncoder-ai-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #KQLvalidation #socprimecom #UncoderAI #socprime #Blog
-
Zip Archive & C2 Domain Detection in Microsoft Sentinel via Uncoder AI โ Source: socprime.com https://ciso2ciso.com/zip-archive-c2-domain-detection-in-microsoft-sentinel-via-uncoder-ai-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #Latestthreats #socprimecom #UncoderAI #socprime #Blog #KQL
-
IOC Query Generation for Microsoft Sentinel in Uncoder AI โ Source: socprime.com https://ciso2ciso.com/ioc-query-generation-for-microsoft-sentinel-in-uncoder-ai-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #socprimecom #UncoderAI #socprime #Blog #KQL
-
Detecting Covert TOR Access in Microsoft Sentinel with Uncoder AIโs Decision Tree โ Source: socprime.com https://ciso2ciso.com/detecting-covert-tor-access-in-microsoft-sentinel-with-uncoder-ais-decision-tree-source-socprime-com/ #AI-generatedDecisionTree #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #socprimecom #UncoderAI #socprime #Blog
-
Translate from Sigma into 48 Languages โ Source: socprime.com https://ciso2ciso.com/translate-from-sigma-into-48-languages-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #socprimecom #socprime #Splunk #Sigma #Blog #SIEM
-
From IOCs to Queries: How Uncoder AI Automates Threat Intelligence Action โ Source: socprime.com https://ciso2ciso.com/from-iocs-to-queries-how-uncoder-ai-automates-threat-intelligence-action-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #socprimecom #socprime #Elastic #Splunk #Kusto #Blog #STIX #IOC
-
From Threat Report to Detection Logic: Uncoder AI Automates Rule Generation โ Source: socprime.com https://ciso2ciso.com/from-threat-report-to-detection-logic-uncoder-ai-automates-rule-generation-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #socprimecom #socprime #Kusto #Blog
-
How Full Summary in Uncoder AI Supercharges Kusto Query Analysis for Threat Hunters โ Source: socprime.com https://ciso2ciso.com/how-full-summary-in-uncoder-ai-supercharges-kusto-query-analysis-for-threat-hunters-source-socprime-com/ #rssfeedpostgeneratorecho #CyberSecurityNews #MicrosoftSentinel #SOCPrimePlatform #SysmonEventID7 #FullSummary #socprimecom #clfs.sys #socprime #Kusto #Blog
-
๐ NEW UPDATE:
I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.
More will be coming soon!
#KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
๐
https://academy.bluraven.io/course/introduction-to-kql-for-security-analysis -
Is anyone seeing delayed alerts in MS Sentinel? We just received multiple alerts for an account that may have been compromised two days ago. The alerts are dated 11/25 in Defender XDR and IdP, but are dated as 11/27 in Sentinel.
-
Only 5 days to go until our both our Hacking Enterprises and Defending Enterprises training classes kick off at Black Hat USA.
There's still time to snag yourself a ticket for either the weekend or weekday delivery and we'd love to help level up your skills in either offensive or defensive techniques, or both!
Wreak havoc with in our multi-domain enterprise environment and then hunt, detect, monitor and alert after, or vice versa!
#pentesting #redteam #hacking #training #cybersecurity #BHUSA #blueteam #kql #microsoftsentinel #threathunting
-
Less than a month to go until Black Hat USA ๐. I suppose the only thing to say is I look forward to seeing you on either our Hacking Enterprises or Defending Enterprises trainings, or maybe both!
...and if I don't, I suppose the only question to ask is, why haven't your bought your ticket yet? ๐ From phishing, C2, IPv6 and rampaging through multi-domain trusts, to deep threat hunting, monitoring and alerting in our Sentinel lab - I suppose the REAL question is, how many friends or colleagues are signing up with you?!
#pentesting #hacking #redteam #BHUSA #bluetam #threathunting #kql #microsoftsentinel
-
๐ Advanced Time Series Anomaly Detection: Discover methods youโve never seen before.
๐ Attack Path & Execution Chain Detection with Process Mining: A novel approach to threat detection.
๐ Attack Pattern Detection Using Graph Semantics: Start thinking in graphs and revolutionize your detection and investigation skills.https://academy.bluraven.io/advanced-hands-on-kql-for-threat-hunting-and-detection-engineering
#KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #ThreatHunting #DetectionEngineering #training #dfir #incidentresponse
-
This article provides a guide on how to create and debug Microsoft Sentinel Analytic Rules, Automation Rules, and playbooks. It includes steps on creating a playbook, creating a sample Analytic rule for testing, creating an Automation rule, and debugging the playbook. https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/debugging-playbooks/ba-p/4165374 #MicrosoftSentinel #PlaybookCreation #Debugging #softcorpremium
-
Microsoft Intune โ Collezionare i log e analizzarli con Microsoft Sentinel
#MicrosoftIntune #MicrosoftSentinel #SicurezzaInformatica #ICTPower #CyberSecurity #Logs #Analytics #Tech
-
๐ FREE Hands-On KQL for Security Analysis Course is now available! ๐
โ 50 seats bi-monthly
โ Certificate of completion
โ 14-day lab with real-world Microsoft Sentinel and Defender XDR logs ๐ฅ๐ฅ
Enroll for #FREE ๐
https://academy.bluraven.io/intro-to-kql-for-security-analysis
#KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training -
๐ I just started offering Subscription plan for "Hands-On Kusto Query Language (KQL) for Security Analysts" course!
๐ https://academy.bluraven.io/hands-on-kusto-query-language-kql-for-security-analysts#KQL #Kusto #SIEM #MicrosoftSentinel #cybersecurity #training
-
๐๐จ๐ฉ๐ข๐ฅ๐จ๐ญ ๐๐จ๐ซ ๐๐๐๐ฎ๐ซ๐ข๐ญ๐ฒ: ๐๐ฅ๐๐ฆ๐๐ง๐ญ๐ฌ ๐จ๐ ๐๐ง ๐๐๐๐๐๐ญ๐ข๐ฏ๐ ๐ฉ๐ซ๐จ๐ฆ๐ฉ๐ญ
From the "Get started with Microsoft Copilot for Security" online training, I highlight this interesting in-depth analysis.
๐๐๐๐๐๐ญ๐ข๐ฏ๐ ๐ฉ๐ซ๐จ๐ฆ๐ฉ๐ญ๐ฌ give Copilot adequate and useful parameters to generate a valuable response. Security analysts or researchers should include the following elements when writing a prompt.
๐ก ๐๐จ๐๐ฅ - specific, security-related information that you need
๐ก๐๐จ๐ง๐ญ๐๐ฑ๐ญ - why you need this information or how you'll use it
๐ก๐๐ฑ๐ฉ๐๐๐ญ๐๐ญ๐ข๐จ๐ง๐ฌ - format or target audience you want the response tailored to
๐ก๐๐จ๐ฎ๐ซ๐๐ - known information, data sources, or plugins Copilot should use
At this link other prompting tips:
Full training: https://learn.microsoft.com/en-us/training/paths/security-copilot-and-ai/
#copilot #copilotforsecurity #securitycopilot #microsoft #microosoftsecurity #llm #openai #azureopenai #llmapps #soc #generativeai #genai #cybersecurity #azure #cloudsecurity #cloudnative #defender #sentinel #microsoftsentinel #xdr #defenderxdr #prompt #promptengineering
-
๐จ #KQL Course Update and Anniversary Discount!
The "Hands-On Kusto Query Language (KQL) for Security Analysts" course has been updated with 5 new exercises focusing on aggregations to answer investigative questions, with more to come! The course now offers:
โ Lots of examples in the lessons
โ A total of 23 exercises
โ 2 Investigation scenarios
allowing you to enhance your skills in Kusto Query Language.Last ~24 hours to get it 30% OFF!
https://academy.bluraven.io/hands-on-kusto-query-language-kql-for-security-analysts
#KQL
#SecurityAnalysis
#Training
#ThreatHunting
#IncidentResponse
#MicrosoftSentinel
#MicrosoftDefender
#M365Defender
#DFIR
#DataAnalysis -
๐๐จ๐ฐ ๐ญ๐จ ๐ญ๐๐ฆ๐ฉ๐ฅ๐๐ญ๐ข๐ณ๐ ๐๐ข๐๐ซ๐จ๐ฌ๐จ๐๐ญ ๐๐๐ง๐ญ๐ข๐ง๐๐ฅ ๐ฉ๐ฅ๐๐ฒ๐๐จ๐จ๐ค
Have you developed a Logic App playbook for Microsoft Sentinel and want to make it available to the community?
Use the following tool to create a template. It's very easy and useful! ๐
https://github.com/Azure/Azure-Sentinel/tree/master/Tools/Playbook-ARM-Template-Generator
Demo: https://www.youtube.com/watch?v=scTtVHVzrQw
#soar #sentinel #microsoftsentinel #playbook #automation #template #arm #azure #logicapp #microsoft #microsoftsecurity #cloud #cloudsecurity #ARMtemplate #github #soc #cyber #cybersecurity #json
-
In.security's 2024 training schedule has it's first two additions. Pentesting and threat hunting training anyone?!
Hacking Enterprises - 2024 Red Edition, running April 16-17 in-person at Black Hat Asia
https://www.blackhat.com/asia-24/training/schedule/#hacking-enterprises---red-edition-35881
Defending Enterprises - 2024 Edition, running April 18-19 in-person at BruCON Spring training
https://www.brucon.org/2024/brucon-2024-training/defending-enterprises-2024-edition/
#hacking #redteam #pentest #blueteam #kql #MicrosoftSentinel