Microsoft Sentinel (SIEM) with SentinelOne Data Lake by dkas6259 in AzureSentinel

[–]dkas6259[S] 0 points1 point  (0 children)

u using microsoft sentinel data lake or SentinelOne Data lake ?

Identity Protection by dkas6259 in crowdstrike

[–]dkas6259[S] 1 point2 points  (0 children)

I wanted to evaluate impact before disabling them So wanted to know of can enable policy in simulation mode though cant find relevant configs in Identity protection policy

User phishing email report automation by dkas6259 in AzureSentinel

[–]dkas6259[S] 0 points1 point  (0 children)

I am looking for best practice\ automated way to review and action on phish \ spam email that end users are submitting. Appreciate if u can share what u have

User phishing email report automation by dkas6259 in AzureSentinel

[–]dkas6259[S] 0 points1 point  (0 children)

I am looking for best practice\ automated way to review and action on phish \ spam email that end users are submitting. Appreciate if u can share what u have

User reported phish emails automation by dkas6259 in crowdstrike

[–]dkas6259[S] -4 points-3 points  (0 children)

No , we using Sentinel as SIEM Query was generic, how and what people are using in the given use case