topic
Investigation
2 posts tagged “Investigation”.
Identity Attack Graph in Microsoft Sentinel
How Sentinel's Identity Attack Graph exposes hidden access paths between identities, permissions, groups, and Azure resources — use cases, onboarding prerequisites (including the Azure Resource Graph connector), and how graph-based investigation complements KQL.
Microsoft Sentinel MCP Entity Analyzer: Explainable Risk Analysis for URLs and Identities
How Sentinel's Entity Analyzer changes the enrichment and triage model — a single explainable verdict for URLs and identities via the Sentinel MCP tools, with the prerequisites, concurrency limits, cost model, and rollout pattern that make it work in production.