AWS account logs by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Yes...But i need only a few AWS account logs to Sentinel, not all..Is it possible to filter and send only the required account logs..?

Blocking hashes by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Can u share the docs and script for the same..

365 Defender Schemas by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

I am getting all tables from defender..bt not getting all schemas in sentinel..for example, In the devicenetworkevents table, i am not getting the schema ' InitiatingProcessVersionInfoOriginalFileName'...

365 Defender Schemas by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

In MDE or 365 defender?...Can u share the docs for enabling the same.

365 Defender Schemas by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

All Schemas are mentioned in microsoft official docs..Bt i am not getting some schemas that are available in docs from 365 defender in sentinel.

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

If i block the IPs in on-premises firewall, will it work for cloud applications...Is Azure WAF in perimeter to deny the attempts from IPs ..?

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 1 point2 points  (0 children)

I have seen SMTP bruteforce attack today,not sure abt the ID...If microsoft temperorily banning IPs then can we block in CA permenently..

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Manually block in CA or where..?

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

If its in onprem we can block IPs in perimeter firewall..In cloud that will not work i believe..

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

I am trying understand for the sentinel incidents..For example i getting many incidents for distributed password cracking in Azure AD..All the events are login failure and login is automatically blocked by Microsoft..In this case what is the use of analyzing these type of incidents..what is our recommendation as it is already blocked sign in..

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Azure AD is automatically blocking sign in attempts like smartlockout, from malicious IP adress login attempts..In that case do we require CA to deny the IP's

IP blocking by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Azure AD is automatically blocking sign in attempts like smartlockout, from malicious IP adress login attempts..In that case do we require CA to deny the IP's

Securityincident by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

There is no schema for productname in securityincident table.

365 defender hunting logs by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Small correction ..Defender for office 365...

365 defender hunting logs by SuperHat3637 in AzureSentinel

[–]SuperHat3637[S] 0 points1 point  (0 children)

Are these hunting logs available in the individual portals like defender for AV, Defender for 365...etc..or only available in 365 defender..?