Building Microsoft Sentinel Usecases with automation using playbooks

Ғылым және технология

#Microsoft #Sentinel is nothing without good #usecases! In this video I'll demonstrate how you can setup Analytics rules (use cases) and automate response on them by using #playbooks.
▼ In this video:
0:00 - Intro
1:05 - Coffee
2:56 - Introduction in Analytics Rules
4:04 - Alert rules based on other Microsoft security solutions
4:46 - Azure Sentinel Fusion (with Demo)
7:22 - Azure Sentinel Rule Templates (with Demo)
10:25 - Scheduled Rules (Theory)
22:50 - Scheduled Rules (Tips)
25:11 - Scheduled Rules - Demo: Analytics Rule setup
36:46 - Setting up automation rules
40:42 - Triggering the automation rule
41:39 - Check incident that has been generated
43:14 - Outro
▼ Automation rules explained:
• Getting started with a...
▼ Pluralsight course about KQL queries
www.pluralsight.com/courses/k...
▼ Microsoft KQL docs
docs.microsoft.com/en-us/azur...
▼ My mediun.com page
/ jeroenniesen
▼ KustoKing
www.kustoking.com/
▼ Social Jeroen Niesen
Twitter: / jeroenniesen​​
▼ Social AzureVlog
Twitter: / azurevlog

Пікірлер: 16

  • @yt0ng646
    @yt0ng6463 жыл бұрын

    You are doing a fantastic job here, thanks a lot !

  • @Christian-np6je
    @Christian-np6je2 жыл бұрын

    Awesome video and summary! Thanks a lot!

  • @willemplug3366
    @willemplug3366 Жыл бұрын

    Love the time and effort you put in the coffee edit😁

  • @shijinsuresh8864
    @shijinsuresh886410 ай бұрын

    Great Job! Thanks

  • @pauldelasaux5756
    @pauldelasaux57563 жыл бұрын

    Keep it up! These are good.

  • @bala007raju
    @bala007raju Жыл бұрын

    very nice video , thanks lot

  • @progod6017
    @progod601711 ай бұрын

    Good video

  • @wilkinsanchez8737
    @wilkinsanchez87372 жыл бұрын

    Excellent video. How do you keep track of your expenses when doing these labs? How much money do you usually spend? Is there a way I could do things like this in a lab environment without worrying for a big bill?

  • @AzureVlog

    @AzureVlog

    10 ай бұрын

    As long as you don't ingest that much data into Microsoft Sentinel, it isn't expensive. You pay per GB that gets ingested into Sentinel. Another way to keep things within budget, is to delete resources after finishing your lab.

  • @jytan740
    @jytan740 Жыл бұрын

    is there any guide that can help splunk users translate from SPL to KQL?

  • @polonia66
    @polonia66 Жыл бұрын

    HI, thank you for your great videos. I have question about 42:51 If i would like to set playbook to block the user, what is the best way to do it? as i can see in your case - you add URL with username? so this playbook will be just for one user, how to do with case of any user?

  • @AzureVlog

    @AzureVlog

    Жыл бұрын

    You can use variables in the URI of the HTTP activity. You use the "Entities - Get Account" activity to retrieve the username. Then use that username as variable in the URI. It is actually quite bad that I "hardcoded" the username in the URI of the HTTP activity.

  • @polonia66

    @polonia66

    Жыл бұрын

    @@AzureVlog thank you so much!

  • @motorhead1791
    @motorhead1791Ай бұрын

    In sentinel log in OperationName column nothing is appearing what to do?

  • @IamSahilVerma
    @IamSahilVerma3 жыл бұрын

    First like from Canada...

  • @IamSahilVerma
    @IamSahilVerma3 жыл бұрын

    First like from Canada..

Келесі