topic
SIEM
8 posts tagged “SIEM”.
Operational Notes on Microsoft Security Copilot Agents in Defender XDR and Microsoft Entra ID
Practical SOC observations on Security Copilot agents — how they're deployed, how they consume Security Compute Units, the agentic identities and Unified RBAC roles they create, where to monitor usage, and KQL for reviewing agent activity.
What's New in Microsoft Sentinel and XDR: AI Automation, Data Lake Innovation, and Unified SecOps
The engineering shift to unified security operations in the Defender portal — Azure portal sunset timeline, the AI playbook generator, CCF Push, data lake tier ingestion, and the migration implications that actually change how you build detections.
Endpoint and EDR Ecosystem Connectors in Microsoft Sentinel
An engineering-first approach to multi-EDR SOCs — ingesting Cisco Secure Endpoint, WithSecure, Samsung Knox, and Lookout into Microsoft Sentinel, then normalizing, correlating, and orchestrating response across vendors.
Threat Intelligence & Identity Ecosystem Connectors in Microsoft Sentinel
Integrating third-party threat-intel feeds (GreyNoise, Team Cymru) with identity logs (OneLogin, PingOne, Keeper) in Microsoft Sentinel — enrichment pipelines, false-positive reduction, and MITRE-mapped detection rules.
SAP & Business-Critical App Security Connectors in Microsoft Sentinel
Making SAP and SAP-adjacent security signals operational in a SOC — reliable ingestion, stable schemas, a normalization layer, and detections for ABAP privilege abuse that survive latency and schema drift.
Integrating Proofpoint and Mimecast Email Security with Microsoft Sentinel
Ingesting Proofpoint POD/TAP and Mimecast Secure Email Gateway telemetry into Microsoft Sentinel, and correlating it with identity, endpoint, and threat-intel signals for end-to-end phishing detection.
Cloud Posture + Attack Surface Signals in Microsoft Sentinel (Prisma Cloud + Cortex Xpanse)
Bringing Palo Alto Prisma Cloud (CSPM/CWPP) and Cortex Xpanse exposure signals into Microsoft Sentinel, plus the KQL correlation recipes that turn posture and attack-surface data into prioritized incidents.
Ingesting Google Cloud Logs into Microsoft Sentinel: Native vs. Custom Architectures
Bringing GCP audit, VPC flow, and DNS logs into Microsoft Sentinel — the native Pub/Sub connector versus a custom ingestion pipeline, with setup steps, trade-offs, and troubleshooting.