Тёмный

Announcing the New Microsoft Sentinel Incident Investigation Experience! 

Microsoft Security Community
Подписаться 29 тыс.
Просмотров 7 тыс.
50% 1

Tuesday, January 17, 2023, 12:00 PM ET / 9:00 AM PT (webinar recording date)
Microsoft Sentinel Webinar | Announcing the New Microsoft Sentinel Incident Investigation Experience!
Presenter: Michal Shechter & Tiander Turpijn
Description:
In this exciting, demo-rich session, we will take you through the new incident triage and investigation experience, showcasing new features which substantially reduce the time needed to triage and investigate incidents.
Timestamps:
00:00 - Introduction
01:45 - Research Process
03:34 - Main Pain Points
04:27 - Reduce the Time it Takes to Triage, Investigate, and Resolve
09:51 - Demo
47:37 - Outro
SUBSCRIBE for new Microsoft Security videos every week.
aka.ms/SecurityCommunity/Subs...
To ensure you hear about future Microsoft Sentinel webinars and other developments, make sure you join our community by going to aka.ms/SecurityCommunity
#microsoftsentinel #incidentinvestigation #microsoftsecuritycommunity #threatintelligence

Наука

Опубликовано:

 

6 июл 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 8   
@warrenmatthews8946
@warrenmatthews8946 Год назад
Really good work. Thank you.
@dm8144
@dm8144 Год назад
This will be very helpful in day to day incident managing.
@patresepinheiro3743
@patresepinheiro3743 Год назад
Amazing!
@NeilNatic
@NeilNatic Год назад
In that top insights pane, i would love to be able to see the last x signins. Im really after what locations the user logged in from, did they come from managed devices, pass conditional access, etc etc .
@HerrKapitaen
@HerrKapitaen Год назад
I built an Incidents Analytics Workbook, where you type in the incedent number and it resolves the related entites. When you select an Account it shows you their last logins (SigninLogs) with location etc. as well as the last AuditLogs for that account. You can click a direct Link to the AAD user page as well. If you select an IP address, it shows all SigninLogs with that IP (create for those Password Spray Attacks). You can customize all your needs with a Workbook. I'm happy the new experience comes closer to my Workbook now. Maybe you consider building your own Workbook based on your needs, I found it to be very useful and flexible.
@NeilNatic
@NeilNatic Год назад
@@HerrKapitaen what a great idea! Thx!!
@harshanharidasan1649
@harshanharidasan1649 Год назад
Awesome 😎
@collegenote
@collegenote Год назад
👍👍👍
Далее
D3 Ваз 2107 Не умри от зависти!
18:57
Explaining NERC's CIP Standards
6:07
Просмотров 3,7 тыс.
Microsoft Sentinel in just 30 minutes
36:20
Просмотров 19 тыс.
Azure Sentinel webinar: Data Collection Scenarios
1:00:29
What is RabbitMQ?
10:10
Просмотров 309 тыс.
PA-RISC рабочая станция HP Visualize
41:27