topic
Threat Hunting
7 posts tagged “Threat Hunting”.
Campaign-Centric Hunting with Microsoft Defender XDR and Microsoft Sentinel
Moving from a single suspicious email to full campaign impact — using Defender for Office 365 Campaign Views and the CampaignInfo table with EmailEvents, UrlClickEvents, and post-delivery data to see who was targeted, who clicked, and what to prioritize.
Identity Attack Graph in Microsoft Sentinel
How Sentinel's Identity Attack Graph exposes hidden access paths between identities, permissions, groups, and Azure resources — use cases, onboarding prerequisites (including the Azure Resource Graph connector), and how graph-based investigation complements KQL.
Endpoint and EDR Ecosystem Connectors in Microsoft Sentinel
An engineering-first approach to multi-EDR SOCs — ingesting Cisco Secure Endpoint, WithSecure, Samsung Knox, and Lookout into Microsoft Sentinel, then normalizing, correlating, and orchestrating response across vendors.
Threat Intelligence & Identity Ecosystem Connectors in Microsoft Sentinel
Integrating third-party threat-intel feeds (GreyNoise, Team Cymru) with identity logs (OneLogin, PingOne, Keeper) in Microsoft Sentinel — enrichment pipelines, false-positive reduction, and MITRE-mapped detection rules.
SAP & Business-Critical App Security Connectors in Microsoft Sentinel
Making SAP and SAP-adjacent security signals operational in a SOC — reliable ingestion, stable schemas, a normalization layer, and detections for ABAP privilege abuse that survive latency and schema drift.
Integrating Proofpoint and Mimecast Email Security with Microsoft Sentinel
Ingesting Proofpoint POD/TAP and Mimecast Secure Email Gateway telemetry into Microsoft Sentinel, and correlating it with identity, endpoint, and threat-intel signals for end-to-end phishing detection.
Cloud Posture + Attack Surface Signals in Microsoft Sentinel (Prisma Cloud + Cortex Xpanse)
Bringing Palo Alto Prisma Cloud (CSPM/CWPP) and Cortex Xpanse exposure signals into Microsoft Sentinel, plus the KQL correlation recipes that turn posture and attack-surface data into prioritized incidents.