home.social

#microsoftsentinel โ€” Public Fediverse posts

Live and recent posts from across the Fediverse tagged #microsoftsentinel, aggregated by home.social.

fetched live
  1. Found a way to bypass Entra ID's single-tenant restriction! By leveraging Azure Lighthouse, you can centralize Entra ID logs from multiple tenants into a single Microsoft Sentinel workspace for unified retention.

    #MicrosoftSentinel #EntraID #azurelighthouse

  2. ๐Ÿšจ Turn threat intelligence into action in @microsoft Sentinel

    With the CrowdSec Sentinel Playbook, enrich your alerts using CrowdSecโ€™s CTI and automatically detect malicious IPs involved in auth or security events.

    Learn more ๐Ÿ‘‰ doc.crowdsec.net/u/cti_api/api

    #MicrosoftSentinel #SecurityAutomation #CTI #cybersecurity

  3. New blog post live for my Sentinel Saturday series! :1000: :apartyblobcat:
    Read the blog ๐Ÿ‘‰ marshsecurity.org/sentinel-sat

    In this post, I explore the power of using Microsoft Sentinel Tasks as part of your automation workflows.

    Most teams arenโ€™t getting the full #value out of Tasks in Microsoft Sentinel. Are you? When you combine Sentinel Tasks with automation, they become a game-changer.

    - Auto-create tasks when automation fails (so nothing slips through the cracks)
    - Auto-complete tasks when automation succeeds
    - Use tasks to verify automation outcomes
    - Build engineering feedback loops and automation #QA

    Read the blog ๐Ÿ‘‰ marshsecurity.org/sentinel-sat

    #MicrosoftSentinel #SentinelAutomation #CyberSecurity #SOCAutomation
    #CloudSecurity #AzureSecurity #SIEM #SecOps #Automation #InfoSec
    #CyberSecurityCommunity #BlueTeam #ThreatDetection #SecurityEngineering #SecurityOperations

  4. ๐Ÿ•ต๏ธโ€โ™‚๏ธ KQL is both a science and an art.

    If youโ€™ve ever felt your Sentinel queries were running slow or costing more than they should, youโ€™re not alone.
    This weekโ€™s #SentinelSaturdays covers how to write leaner, faster, more efficient KQL queries with practical examples you can use today.

    ๐Ÿ”— Read the full walkthrough here: marshsecurity.org/sentinel-ski

    Share your comments ๐Ÿ‘‡
    Whatโ€™s YOUR top KQL tip or favourite optimisation trick?

    Letโ€™s build a thread of practical advice for the hunting community.
    #MicrosoftSentinel #KQL #ThreatHunting #SecurityOperations

  5. ๐ŸŽ NEW UPDATE:

    I've added a small challenge to my FREE "Hands-On Introduction to KQL for Security Analysis" course.

    More will be coming soon!

    #KQL #Kusto #MicrosoftDefender #MicrosoftSentinel
    ๐Ÿ‘‡
    academy.bluraven.io/course/int

  6. Is anyone seeing delayed alerts in MS Sentinel? We just received multiple alerts for an account that may have been compromised two days ago. The alerts are dated 11/25 in Defender XDR and IdP, but are dated as 11/27 in Sentinel.

    #MicrosoftSentinel #threatintelligence

  7. Only 5 days to go until our both our Hacking Enterprises and Defending Enterprises training classes kick off at Black Hat USA.

    There's still time to snag yourself a ticket for either the weekend or weekday delivery and we'd love to help level up your skills in either offensive or defensive techniques, or both!

    Wreak havoc with in our multi-domain enterprise environment and then hunt, detect, monitor and alert after, or vice versa!

    in.security/events/

    #pentesting #redteam #hacking #training #cybersecurity #BHUSA #blueteam #kql #microsoftsentinel #threathunting

  8. Less than a month to go until Black Hat USA ๐Ÿ‘€. I suppose the only thing to say is I look forward to seeing you on either our Hacking Enterprises or Defending Enterprises trainings, or maybe both!

    ...and if I don't, I suppose the only question to ask is, why haven't your bought your ticket yet? ๐Ÿ˜Ž From phishing, C2, IPv6 and rampaging through multi-domain trusts, to deep threat hunting, monitoring and alerting in our Sentinel lab - I suppose the REAL question is, how many friends or colleagues are signing up with you?!

    in.security/events/

    #pentesting #hacking #redteam #BHUSA #bluetam #threathunting #kql #microsoftsentinel

  9. ๐Ÿ” Advanced Time Series Anomaly Detection: Discover methods youโ€™ve never seen before.
    ๐Ÿ”— Attack Path & Execution Chain Detection with Process Mining: A novel approach to threat detection.
    ๐ŸŒ Attack Pattern Detection Using Graph Semantics: Start thinking in graphs and revolutionize your detection and investigation skills.

    academy.bluraven.io/advanced-h

    #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #MicrosoftDefenderXDR #Defender #cybersecurity #KQLForSecurityAnalysts #ThreatHunting #DetectionEngineering #training #dfir #incidentresponse

  10. This article provides a guide on how to create and debug Microsoft Sentinel Analytic Rules, Automation Rules, and playbooks. It includes steps on creating a playbook, creating a sample Analytic rule for testing, creating an Automation rule, and debugging the playbook. techcommunity.microsoft.com/t5 #MicrosoftSentinel #PlaybookCreation #Debugging #softcorpremium

  11. ๐Ÿš€ FREE Hands-On KQL for Security Analysis Course is now available! ๐Ÿš€
    โœ… 50 seats bi-monthly
    โœ… Certificate of completion
    โœ… 14-day lab with real-world Microsoft Sentinel and Defender XDR logs ๐Ÿ”ฅ๐Ÿ”ฅ
    Enroll for #FREE ๐Ÿ‘‡
    academy.bluraven.io/intro-to-k
    #KQL #Kusto #SIEM #MicrosoftSentinel #MicrosoftDefender #Defender #cybersecurity #KQLForSecurityAnalysts #training

  12. ๐‚๐จ๐ฉ๐ข๐ฅ๐จ๐ญ ๐Ÿ๐จ๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ: ๐ž๐ฅ๐ž๐ฆ๐ž๐ง๐ญ๐ฌ ๐จ๐Ÿ ๐š๐ง ๐ž๐Ÿ๐Ÿ๐ž๐œ๐ญ๐ข๐ฏ๐ž ๐ฉ๐ซ๐จ๐ฆ๐ฉ๐ญ

    From the "Get started with Microsoft Copilot for Security" online training, I highlight this interesting in-depth analysis.

    ๐„๐Ÿ๐Ÿ๐ž๐œ๐ญ๐ข๐ฏ๐ž ๐ฉ๐ซ๐จ๐ฆ๐ฉ๐ญ๐ฌ give Copilot adequate and useful parameters to generate a valuable response. Security analysts or researchers should include the following elements when writing a prompt.

    ๐Ÿ’ก ๐†๐จ๐š๐ฅ - specific, security-related information that you need

    ๐Ÿ’ก๐‚๐จ๐ง๐ญ๐ž๐ฑ๐ญ - why you need this information or how you'll use it

    ๐Ÿ’ก๐„๐ฑ๐ฉ๐ž๐œ๐ญ๐š๐ญ๐ข๐จ๐ง๐ฌ - format or target audience you want the response tailored to

    ๐Ÿ’ก๐’๐จ๐ฎ๐ซ๐œ๐ž - known information, data sources, or plugins Copilot should use

    At this link other prompting tips:

    learn.microsoft.com/en-us/trai

    Full training: learn.microsoft.com/en-us/trai

    #copilot #copilotforsecurity #securitycopilot #microsoft #microosoftsecurity #llm #openai #azureopenai #llmapps #soc #generativeai #genai #cybersecurity #azure #cloudsecurity #cloudnative #defender #sentinel #microsoftsentinel #xdr #defenderxdr #prompt #promptengineering

  13. ๐Ÿšจ #KQL Course Update and Anniversary Discount!

    The "Hands-On Kusto Query Language (KQL) for Security Analysts" course has been updated with 5 new exercises focusing on aggregations to answer investigative questions, with more to come! The course now offers:
    โœ… Lots of examples in the lessons
    โœ… A total of 23 exercises
    โœ… 2 Investigation scenarios
    allowing you to enhance your skills in Kusto Query Language.

    Last ~24 hours to get it 30% OFF!

    academy.bluraven.io/hands-on-k

    #KQL
    #SecurityAnalysis
    #Training
    #ThreatHunting
    #IncidentResponse
    #MicrosoftSentinel
    #MicrosoftDefender
    #M365Defender
    #DFIR
    #DataAnalysis

  14. ๐‡๐จ๐ฐ ๐ญ๐จ ๐ญ๐ž๐ฆ๐ฉ๐ฅ๐š๐ญ๐ข๐ณ๐ž ๐Œ๐ข๐œ๐ซ๐จ๐ฌ๐จ๐Ÿ๐ญ ๐’๐ž๐ง๐ญ๐ข๐ง๐ž๐ฅ ๐ฉ๐ฅ๐š๐ฒ๐›๐จ๐จ๐ค

    Have you developed a Logic App playbook for Microsoft Sentinel and want to make it available to the community?

    Use the following tool to create a template. It's very easy and useful! ๐Ÿ˜Š

    github.com/Azure/Azure-Sentine

    Demo: youtube.com/watch?v=scTtVHVzrQ

    #soar #sentinel #microsoftsentinel #playbook #automation #template #arm #azure #logicapp #microsoft #microsoftsecurity #cloud #cloudsecurity #ARMtemplate #github #soc #cyber #cybersecurity #json

  15. In.security's 2024 training schedule has it's first two additions. Pentesting and threat hunting training anyone?!

    Hacking Enterprises - 2024 Red Edition, running April 16-17 in-person at Black Hat Asia

    blackhat.com/asia-24/training/

    Defending Enterprises - 2024 Edition, running April 18-19 in-person at BruCON Spring training

    brucon.org/2024/brucon-2024-tr

    #hacking #redteam #pentest #blueteam #kql #MicrosoftSentinel