Getting started with Microsoft Sentinel Tasks to Standardise Cyber Security Incident Response

  Рет қаралды 2,875

AzureVlog

AzureVlog

Күн бұрын

Пікірлер: 6
@janetwilcox5314
@janetwilcox5314 Жыл бұрын
Outstanding
@b2secops
@b2secops Жыл бұрын
Thanks for the video, do you require VirusTotal premium for the lookup from Sentinel to work?
@jackobyte
@jackobyte Жыл бұрын
Great video, just wondering.. adding the tasks (via the automation rule) shouldnt have an effect on costs? its only when they are logic apps? is that right?
@progod6017
@progod6017 Жыл бұрын
I had no idea virus total has a free API. Thanks for sharing!
@alexandervogtsanchez7522
@alexandervogtsanchez7522 Жыл бұрын
It's pretty much useless if you have a medium to high volume of IPs included in alerts/incidents. Rate limit is like 4 per minute. BTW sentinel now has enrichment widgets for IP addresses so no need to include a task for this. If you still want to use logic apps, use the HTTP connector rather than the built-in virus total one. This way you can check the status code of the call. If it returns 204 you can call another HTTP with a different api key. Somewhat ugly but could work to overcome rate limitations
@progod6017
@progod6017 Жыл бұрын
it is actually useless. true. @@alexandervogtsanchez7522
Getting started with Threat Hunting in Microsoft Sentinel
13:22
Their Boat Engine Fell Off
0:13
Newsflare
Рет қаралды 15 МЛН
Wednesday VS Enid: Who is The Best Mommy? #shorts
0:14
Troom Oki Toki
Рет қаралды 50 МЛН
Microsoft Sentinel Incident Investigation and Incident Management
22:54
Sudo Rootcast (The Security Channel)
Рет қаралды 12 М.
How to respond FAST to Incidents in Cybersecurity
11:47
Tech with Jono
Рет қаралды 7 М.
Cyber Incident Response Tabletop Exercise
1:01:02
IT Governance Ltd
Рет қаралды 19 М.
SOC 101: Real-time Incident Response Walkthrough
12:30
Exabeam
Рет қаралды 210 М.
Their Boat Engine Fell Off
0:13
Newsflare
Рет қаралды 15 МЛН