Great article here from @timurengin_ about using Azure Data Explorer (or the Kusto desktop app) to visualize sign in data (or anything else really!) onto an interactive map - https://t.co/GjGsHXGAYM
It's rare to effectively analyse an incident with only on-prem logs, and cloud logging is not at the level it should be. I share some must-have logs in Azure for incident analysis: https://t.co/zikjpWZr0L
@sunnyc7@rucam365@reprise_99 Since December the quality of the queries has gone up quite a bit. Back in December the queries didn't work, now they do.
The queries it does generate aren't the most complex but if you don't know where to start or just want something quick, it's a great tool...
@SBousseaden@anton_chuvakin Are you assuming no configuration changes to reduce number of FPs, or using tools as is? Answer will be quite different depending on this
Maalesef sysadmin ve güvenlik ekipleri Active Directory'e yeterince önem vermiyor. Bu da saldırganlar için işi kolaylaştırıyor. Bu konuda katkımız olsun diye Mehmetcan TOPAL ile beraber AD atak vektörleri, savunma ve tespit yöntemlerini anlattık https://t.co/T3lQpuys88
Kusto Query Language, Microsoft ve Azure servislerinde (güvenlik, yapay zeka, veri yönetimi, ...) kullanılan sorgu dili. Maalesef Türkçe kaynak yok denecek kadar az. KQL'i anlattığım bir seriye başladım, ilk yazı burada: https://t.co/c921qJNdVE
New blog post about some Sentinel automation. Much more customisation available with Logic Apps than I wrote about here. You can use Logic Apps to reduce alert fatigue, update dynamic data stores, etc. https://t.co/sb9u6HfHfr
Really useful blog outlining a tool that I helped work on. The tool works as a GUI to call APIs on multiple devices in MDE. It allows for calling APIs based on query output too. Blog by a fantastic colleague of mine: https://t.co/zurTbSlBO3
and the code:
https://t.co/kF8zXxFZgD