Category: Azure Sentinel

Monitor and Hunting PowerShell with Azure Sentinel

Hunting P0w3rSh3LL with Azure Sentinel

An attacker is like a lover. He teases until he finds the right moment to act on your network. This behavior is the same for the PowerShell attack.

The following post focuses on PowerShell obfuscation and how to monitor with … Read the rest

Monitor Service Principal with Azure Sentinel

Monitor Service Principal with Azure Sentinel

What’s going on inside the box? Is Service principal monitoring essential? If we rely on the SolarWinds event, then yes, this is necessary monitoring. The post will guide how to Monitor Service Principal with Azure Sentinel.

There are a few … Read the rest

Identity Attacks with Azure Sentinel

There are few terms for credential attacks, such as password attacks, identity attacks, dictionary attacks, etc. Identity attacks come in different styles with different nuances.

The most prevalent attacks are the Password Spray and Brute-force attack.

What are the differences … Read the rest