Microsoft Sentinel

Microsoft Sentinel

Fixing the "Rare Application Consent" Analytic Rule

Alright class. Back in the Entra audit log for this

Fixing the "Privileged Role Assigned Outside PIM" Analytic Rule

Alright class. There is a good chance you are using

Fixing the "Account Created From Non-Approved Sources" Analytic Rule

Alright class. A companion piece to the last lesson, from

Azure Diagnostic Settings: The Azure Policy Rabbit Hole Nobody Told You About

All right class. If you run Microsoft Sentinel and you

Fixing the "Account Created or Deleted by Non-Approved User" Analytic Rule

Alright class. This one comes from the Entra ID audit

Fixing the "Account Created and Deleted in Short Timeframe" Analytic Rule

Alright class. Today it is "Account Created and Deleted

PIM Auditing in Microsoft Sentinel: High Value Detections

Alright class. Most lessons in this series are usually autopsies.

Sentinel Incident Email Alerts: Free Logic App with ARM Template

All right class One of the most common questions I&

The Nag Machine: A Logic App That Badgers Your Team About Unowned Sentinel Incidents

All right class Today is a quick one so you

Building Your First Threat Hunting Hypothesis (The MITRE Way)

All right class. Lots of SOC teams say they do
Consent Preferences