Tagged: Azure Sentinel

Azure Sentinel

Legacy SIEM and Cloud Native SIEM

Sentinel. Sentry, a defender always on the guard who aims to protect and withstand threats, anticipate any attack, and assume that it will arrive, and adjust the behavior accordingly. Be present to protect the assets and the area.

This blog … Read the rest

Azure Sentinel and Sysmon 4 B!ue T3amer$

Azure Sentinel and Sysmon 4 B!ue T3amer$

Recently, there have been massive cyberattacks against cloud providers and on-premises environments, the most recent of which is the attack and exploitation of vulnerabilities against Exchange servers – TheĀ HAFNIUM. This post focus on Azure Sentinel and Sysmon 4 … Read the rest

Azure Sentinel Cost Optimization with KQL Tips

Do you know the difference between a successful implementation and a failed implementation in the cloud? Costs! This post focus on Azure Sentinel Cost Optimization with KQL Tips.

Cloud costs are critical, and even they have a specific role nowadays … Read the rest

Monitor and Hunting PowerShell with Azure Sentinel

Hunting P0w3rSh3LL with Azure Sentinel

An attacker is like a lover. He teases until he finds the right moment to act on your network. This behavior is the same for the PowerShell attack.

The following post focuses on PowerShell obfuscation and how to monitor with … Read the rest