97. Microsoft Azure Sentinel
Автор: Betabit
Загружено: 2024-04-24
Просмотров: 104
Описание:
https://www.betabit.nl/en/betatalks
Jelle and Gerben talk about Microsoft Azure Sentinel. They discuss how to set up monitoring and incident response. They demonstrate how to use Sentinel to centralize security data from Azure activity logs for improved visibility and automated response. Key points included ingesting logs into a log analytics workspace, using content packs for data connectors and analytic rules, and scoping data at the subscription or resource group level. They also show how to analyze logs for potential threats using queries and custom alerts. Their discussion emphasizes starting small, continuously improving rules and workbooks over time based on detected signals, and considering red team testing to evaluate detection capabilities.
Links for more information:
https://www.crowdstrike.com/cybersecu...
Timestamps
00:00 - Introduction begins
00:55 - SIEM & SOC
05:17 - Microsoft Sentinel
07:04 - Microsoft Sentinel requirement & pricing
10:22 - Demo Microsoft Sentinel
15:30 - Workbooks
16:12 - Confirmation that Sentinel is very configurable
16:37 - Microsoft Sentinel Hunting
18:08 - Several incidents and rules
19:55 - Overview and how to start with Sentinel
23:00 - Closing remarks
Join us on our Discord channel: / discord
There is more to come!
https://www.betabit.nl/en
Повторяем попытку...
Доступные форматы для скачивания:
Скачать видео
-
Информация по загрузке: