While working with security incidents, the primary key is information. Things like important information, logs, data sources, a correlation between all data, and the signals – All of these are valuable when hunting and searching for specific information, for example, … Read the rest
In today’s world, the classic concept of remote workers and external users is still acceptable? As you know, once you’re on the cloud, the perimeter is dead, and each user is DMZ.
So the modern concept for an external user … Read the rest
When talking security investigation and forensics, please take the word “prevent” out of the dictionary because organizations realize that stopping complicated cyber attacks in many situations is unrealistic.
Note: this post is an introduction for investigation with Microsoft 365
In the next series of articles, we will be focused on how to troubleshoot and resolve common and special issues that can occur when working with Azure Information Protection. This blog post will be focused on how to run a … Read the rest