Demystifying correlations in the Unified Security Operations Platform

  Рет қаралды 679

Microsoft Security Community

Microsoft Security Community

Күн бұрын

Пікірлер: 3
@j3remy313
@j3remy313 Ай бұрын
Hi! We have a separate team that handles Purview incidents - and they seem to be creating thousands of alerts (ie, one for each file). When we enable Unified SOC with XDR, all those thousands of alerts come into Sentinel incidents, and also get correlated to other alerts, and even get correlated into "multistage incidents" with themselves. We'd love a way to not have correlation view Purview/DLP alerts, or add exclusions. Is there a way to do this? Feel free to reach out to me on the Customer CCP as well :)
@saus660
@saus660 Ай бұрын
Things I hate: 1. The use of the word Demystifying in presentations 2. Misuse of the word Depreciation
@HeikeRitter
@HeikeRitter Ай бұрын
Oh, why is that? Can you explain please?
Network Security Protection with Azure Firewall, Azure WAF, and Azure DDoS
28:05
Microsoft Security Community
Рет қаралды 808
Defender for Office 365: In-depth defense with dual-use scenario
23:39
Microsoft Security Community
Рет қаралды 1,2 М.
ТЫ В ДЕТСТВЕ КОГДА ВЫПАЛ ЗУБ😂#shorts
00:59
BATEK_OFFICIAL
Рет қаралды 2,7 МЛН
When mom gets home, but you're in rollerblades.
00:40
Daniel LaBelle
Рет қаралды 139 МЛН
Introduction to Report Generation
16:32
LlamaIndex
Рет қаралды 4,6 М.
Generative AI in a Nutshell - how to survive and thrive in the age of AI
17:57
425 Show | Phishing-Resistant Passwordless Deployment Guide
58:18
Microsoft Security Community
Рет қаралды 580
Why 27 U.S. States Are Going Broke
11:36
CNBC
Рет қаралды 669 М.
Cisco XDR Detection Analytics and Gen AI
32:36
Cisco
Рет қаралды 925
What's New in Microsoft Sentinel & Unified Portal Enhancements
49:49
Microsoft Security Community
Рет қаралды 2,8 М.
Splunk Enterprise Security Free Training | Using Threat Intelligence
26:56
Enhancing Cloud Security Posture with Defender CSPM
56:50
Microsoft Security Community
Рет қаралды 1 М.