Building Microsoft Sentinel Usecases with automation using playbooks

  Рет қаралды 8,788

AzureVlog

AzureVlog

Күн бұрын

Пікірлер: 16
@willemplug3366
@willemplug3366 2 жыл бұрын
Love the time and effort you put in the coffee edit😁
@yt0ng646
@yt0ng646 3 жыл бұрын
You are doing a fantastic job here, thanks a lot !
@Christian-np6je
@Christian-np6je 2 жыл бұрын
Awesome video and summary! Thanks a lot!
@polonia66
@polonia66 2 жыл бұрын
HI, thank you for your great videos. I have question about 42:51 If i would like to set playbook to block the user, what is the best way to do it? as i can see in your case - you add URL with username? so this playbook will be just for one user, how to do with case of any user?
@AzureVlog
@AzureVlog 2 жыл бұрын
You can use variables in the URI of the HTTP activity. You use the "Entities - Get Account" activity to retrieve the username. Then use that username as variable in the URI. It is actually quite bad that I "hardcoded" the username in the URI of the HTTP activity.
@polonia66
@polonia66 2 жыл бұрын
@@AzureVlog thank you so much!
@shijin_suresh
@shijin_suresh Жыл бұрын
Great Job! Thanks
@motorhead1791
@motorhead1791 8 ай бұрын
In sentinel log in OperationName column nothing is appearing what to do?
@wilkinsanchez8737
@wilkinsanchez8737 3 жыл бұрын
Excellent video. How do you keep track of your expenses when doing these labs? How much money do you usually spend? Is there a way I could do things like this in a lab environment without worrying for a big bill?
@AzureVlog
@AzureVlog Жыл бұрын
As long as you don't ingest that much data into Microsoft Sentinel, it isn't expensive. You pay per GB that gets ingested into Sentinel. Another way to keep things within budget, is to delete resources after finishing your lab.
@paul.delasaux
@paul.delasaux 3 жыл бұрын
Keep it up! These are good.
@bala007raju
@bala007raju 2 жыл бұрын
very nice video , thanks lot
@progod6017
@progod6017 Жыл бұрын
Good video
@jytan740
@jytan740 2 жыл бұрын
is there any guide that can help splunk users translate from SPL to KQL?
@IamSahilVerma
@IamSahilVerma 3 жыл бұрын
First like from Canada..
@IamSahilVerma
@IamSahilVerma 3 жыл бұрын
First like from Canada...
Using Azure Sentinel with Logstash
18:03
AzureVlog
Рет қаралды 6 М.
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН
黑天使只对C罗有感觉#short #angel #clown
00:39
Super Beauty team
Рет қаралды 36 МЛН
Beat Ronaldo, Win $1,000,000
22:45
MrBeast
Рет қаралды 158 МЛН
人是不能做到吗?#火影忍者 #家人  #佐助
00:20
火影忍者一家
Рет қаралды 20 МЛН
Announcing the New Microsoft Sentinel Incident Investigation Experience!
49:13
Microsoft Security Community
Рет қаралды 7 М.
Use Threat Intelligence to Detect Malicious Activity in Azure Sentinel
28:09
Learn Live: Threat response with Microsoft Sentinel playbooks | CLL94
57:18
Kusto Query Language (KQL) Overview
1:03:38
John Savill's Technical Training
Рет қаралды 70 М.
Introduction to Azure Sentinel. Part 1 - Foundations
54:21
Netrix Global
Рет қаралды 12 М.
33 Microsoft Sentinel Workbooks
1:02:06
Hannes Lagler-Gruener
Рет қаралды 6 М.
Azure Sentinel webinar: Enabling User and Entity Behavior Analytics (UEBA)
58:46
Microsoft Sentinel Setup and Configuration
24:09
AzureVlog
Рет қаралды 29 М.
Building Production RAG Over Complex Documents
1:22:18
Databricks
Рет қаралды 18 М.
We Attempted The Impossible 😱
00:54
Topper Guild
Рет қаралды 56 МЛН