Тёмный

Microsoft Sentinel Incident Investigation and Incident Management 

WhiteEyeSecurity(TheRealTechnicalConfiguration)
Подписаться 1,6 тыс.
Просмотров 10 тыс.
50% 1

After you connected your data sources to Microsoft Sentinel, you want to be notified when something suspicious happens. To enable you to do this, Microsoft Sentinel lets you create advanced analytics rules that generate incidents that you can assign and investigate.
Investigate incidents
Use the investigation graph
An incident can include multiple alerts. It's an aggregation of all the relevant evidence for a specific investigation. An incident is created based on analytics rules that you created in the Analytics page. The properties related to the alerts, such as severity and status, are set at the incident level. After you let Microsoft Sentinel know what kinds of threats you're looking for and how to find them, you can monitor detected threats by investigating incidents.
learn.microsof...
learn.microsof...

Опубликовано:

 

1 окт 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 19   
@ravbhuva
@ravbhuva 2 месяца назад
How do you block, Sandbox, or Isolate devices or Networks?
@frezerdugasa7937
@frezerdugasa7937 3 месяца назад
I really appreciate your work, Bro. I could not thank you enough for your video. You really make it Very simple and easy to understand. I just want to wish you all success and achievements. Keep Up!! The good work. Thanks☺
@whiteeyesecuritytherealtec6623
@whiteeyesecuritytherealtec6623 3 месяца назад
You are most welcome
@RawiChadulla
@RawiChadulla 10 месяцев назад
How to Identify the Incident is a "True Positive or false Positive" and can you explain one true positive case Incident. It will helpfull
@whiteeyesecuritytherealtec6623
@whiteeyesecuritytherealtec6623 10 месяцев назад
Basically if it is related to some Malicious activities or there are some malicious Entities Like IP, URL, DNS, etc. You can treat that as a True positive. False positive is something which have Inaccurate or incomplete data.
@martinbaran7570
@martinbaran7570 11 месяцев назад
not great
@haricharantg5274
@haricharantg5274 Год назад
very Understandable video so far
@whiteeyesecuritytherealtec6623
Thanks!
@Cybergazi007
@Cybergazi007 Год назад
Awesome video Thank bro
@whiteeyesecuritytherealtec6623
Glad you liked it
@appasahebaddodagi
@appasahebaddodagi Год назад
thank you
@whiteeyesecuritytherealtec6623
You're welcome
@chintallakavitha5279
@chintallakavitha5279 7 месяцев назад
Awesome
@naxeltechnologies4700
@naxeltechnologies4700 Год назад
Amazing
@whiteeyesecuritytherealtec6623
Thank you! Cheers!
@haseebmohd6063
@haseebmohd6063 Год назад
Hi , how do we reach you
@whiteeyesecuritytherealtec6623
Please email me at "whiteeyesec@gmail.com". Thank You.
@MrVinay-xj2ug
@MrVinay-xj2ug Год назад
Superb 👌👌👌
@whiteeyesecuritytherealtec6623
Thanks 🤗
Далее
Microsoft Sentinel in just 30 minutes
36:20
Просмотров 27 тыс.
Incident Response Procedures with Microsoft Sentinel
15:26
# Rural Funny Life Wang Ge
00:18
Просмотров 774 тыс.
Microsoft Sentinel and Defender XDR Demo
1:00:17
Просмотров 1,5 тыс.
Microsoft Sentinel Incident Investigation | Free Lab
9:44