
Investigate Cloud Activity in Microsoft Defender for Cloud
Use cloud EDR to investigate cloud resources. Microsoft Defender for Cloud is a cloud EDR tool built into Microsoft Security Center that can monitor an expanding list of cloud platforms. The following example image shows which platforms Microsoft Defender for Cloud can protect, they all operate differently, but they can all be investigated with the […]

Microsoft Sentinel Workbooks that All SOCs Should Have.
Get more value out of your data for free with Workbooks. Microsoft Sentinel Workbooks allow security analysts and admins to view data about security in their environment using graphical displays. This is a powerful tool because any data that can be queried can now also be displayed in an easy-to-understand graphical format. Charts like the […]

Why Do I Have four Defender O365 Investigation Menus?
Know the differences to optimize investigations. Microsoft recently began reorganizing their Microsoft Defender 365 security platform to make it easier to use for cybersecurity analysts. With the recent additions to the Microsoft 365 Security menu, there are now four different menus that analysts can go to for investigations involving Defender for Office 365. In this […]

Microsoft Sentinel Security Testing Ground Rules
Keeping test incidents from being actual incidents. Cybersecurity testing is important for ensuring that the security controls that your organization is implementing are working. Cloud cybersecurity testing takes on the same level of importance, but in the cloud your security testing faces some unique challenges because of the constraints placed by the cloud services providers […]

Why Isn’t My Microsoft Sentinel CI/CD Pipeline Working?
Using DevOps to automate management of Microsoft Sentinel features. The “Deploying and Managing Microsoft Sentinel as Code” Tech Community article is a popular blog that describes how to use Microsoft DevOps to create a CI/CD pipeline for Microsoft Sentinel features. The tool described in the article is very powerful, but it is also so complex […]

Essential Azure Sentinel Automations
Boost productivity by automating routine tasks. One of the ways that Azure Sentinel is attempting to differentiate itself from the competition is by integrating the automation tools available in Azure. A Security Operations Center (SOC) can use a combination of Azure Logic Apps, Azure Runbooks, and Azure DevOps to automate many of the incident management […]

Why Aren’t My Microsoft Sentinel Playbooks Working?
Solutions to some common Playbook pitfalls. Some of the error messages that appear in Playbooks are either very cryptic or simply unexplained because many Microsoft Sentinel Logic App components are in preview. Security analysts that are deploying Microsoft Sentinel Playbooks for the first time may see esoteric error messages like the example below and get […]

Advanced Threat Hunting in Microsoft Sentinel.
When Existing Data isn’t Enough, Look for Metadata. Microsoft Sentinel has a constantly expanding list of advanced hunting queries that Microsoft has gathered from around the community to help with finding useful information when investigating cybersecurity incidents. As of the last count, there are 200+ queries available out-of-the-box in Microsoft Sentinel. It is worthwhile […]

Investigating with Microsoft Defender for Endpoints (MDE)
Use a focused methodology to resolve multi-stage incidents quickly and effectively Microsoft Defender for Endpoints (MDE) uses AI and analytics to correlate alerts to create an incident, and it is not shy about showing all the alerts that could potentially be involved with the incident. If a security analyst expands a multistage incident, they may […]