Tagged: Azure Sentinel

Monitor Service Principal with Azure Sentinel

Monitor Service Principal with Azure Sentinel

What’s going on inside the box? Is Service principal monitoring essential? If we rely on the SolarWinds event, then yes, this is necessary monitoring. The post will guide how to Monitor Service Principal with Azure Sentinel.

There are a few … Read the rest

Identity Attacks with Azure Sentinel

There are few terms for credential attacks, such as password attacks, identity attacks, dictionary attacks, etc. Identity attacks come in different styles with different nuances.

The most prevalent attacks are the Password Spray and Brute-force attack.

What are the differences … Read the rest

Identify Forwarding with Kusto

Hunting Mail Forwarding with Azure Sentinel

Do you know what is occurring inside your Exchange environment? Probably no… in a single week, there are hundreds of changes inside Exchange Online by the IT team and some users’ changes. The Hunting Mail Forwarding with Azure Sentinel post … Read the rest

Unified SIEM and XDR

Unified SIEM and XDR – Azure Sentinel and Defender 365

Integrated threat protection from Microsoft will empower your organization’s defenders by putting the right tools and intelligence in the hands of the right people. Get insights across your entire environment with Azure Sentinel. Use integrated, automated, extended detection and response … Read the rest