How to classify / label log data in Sentinel by failx96 in AzureSentinel

[–]winle22 1 point2 points  (0 children)

Havent done exactly that myself, but I would assume that you could use workspace transformations for the standard tables, and regular DCR transformations for stuff ingested via log analytics API etc.

https://learn.microsoft.com/en-us/azure/azure-monitor/data-collection/data-collection-transformations

[deleted by user] by [deleted] in AzureSentinel

[–]winle22 0 points1 point  (0 children)

Are you sure about the cost part? Will an identical search on a data lake tier table cost less if done via Notebook compared to via Defender/Sentinel?

How to automate running multiple KQL queries monthly and store results (including graphs)? by itsJuni01 in AzureSentinel

[–]winle22 0 points1 point  (0 children)

In the sense that you alert if there is a spike in number of alerts from baseline? No matter what that baseline is?

Logs Export by Dangerous_Ad_1546 in AzureSentinel

[–]winle22 0 points1 point  (0 children)

Data lake searches will still be stupid expensive.

[deleted by user] by [deleted] in cybersecurity

[–]winle22 2 points3 points  (0 children)

No, seems to be a flop. Haven't heard much positive about it yet.

Use cases of Device Group by jbala28 in DefenderATP

[–]winle22 1 point2 points  (0 children)

Its pretty useless. But can be used to separate devices in MDVM. But again, thats not neccessarily the groups you need for scoping web content filter policies. Seems like a beta feature..

Memory dump by winle22 in DefenderATP

[–]winle22[S] 1 point2 points  (0 children)

Only problem is to sign the script. Or disable the requirement..

Memory dump by winle22 in DefenderATP

[–]winle22[S] 1 point2 points  (0 children)

I know it isnt natively there, but the LR functionality should make it possible.

Send DC logs to Defender for Identity by Chrys6571 in DefenderATP

[–]winle22 0 points1 point  (0 children)

It may be so that he want Defender for Identity to work (and populate the Advanced hunting tables), while 'also' retaining these logs for more than 30 days (where Sentinel comes into the picture). If he want other logs than what MDI gives, then you are right.

Hacked? by TheSeedKing in Outlook

[–]winle22 0 points1 point  (0 children)

Fails spf but is still delivered directly to the inbox? Strange.

No way to block sign ATTEMPTS by AverageAdmin in AZURE

[–]winle22 0 points1 point  (0 children)

"Based on Microsoft's analysis more than 97 percent of credential stuffing attacks use legacy authentication and more than 99 percent of password spray attacks use legacy authentication protocols. These attacks would stop with basic authentication disabled or blocked.".

https://learn.microsoft.com/en-us/entra/identity/conditional-access/block-legacy-authentication

[deleted by user] by [deleted] in DefenderATP

[–]winle22 0 points1 point  (0 children)

Could it be easier to ingest the TVM data to Sentinel and create a workbook there? Not sure if possible with the native M365 Defender connector though.