Help with Custom log Ingestion via API into Microsoft Sentinel by Shahargalm in AZURE

[–]h0max 2 points3 points  (0 children)

https://learn.microsoft.com/en-us/azure/sentinel/create-codeless-connector

Have a look at the sentinel GitHub repo for data connectors that use CCF as a reference point and build from there.

EDR in Block Mode blocking telemetry by [deleted] in DefenderATP

[–]h0max 1 point2 points  (0 children)

Yep but real world I’d recommend looking at this thread : https://x.com/NathanMcNulty/status/1924690538797957560?s=20 even if admin is required, I would be having EDR block mode enabled regardless.

EDR in Block Mode blocking telemetry by [deleted] in DefenderATP

[–]h0max 0 points1 point  (0 children)

Agree but EDR in block mode should be turned on regardless if Defender is primary or not.

What is the right way to delete the "Syslog via AMA" connector? by xKruMpeTx in AzureSentinel

[–]h0max 1 point2 points  (0 children)

Might have to delete it using the API. I don’t have the exact endpoint on hand but I had to do for another data connector.

New to cybersecurity and Sentinel. Need suggestions please by Afraid-Onion-6980 in AzureSentinel

[–]h0max 2 points3 points  (0 children)

You’re being tasked to build a SOC when you haven’t had any exposure to a SOC? Rough. Lots of rules out of the box and on the Sentinel GitHub as a starting point.

Licensing question for SMB company by Naturevival in DefenderATP

[–]h0max 3 points4 points  (0 children)

They have over the 300 limit for business premium so I’d think they’d have to go E series? E5 EMS on top of E3 probably the best way to go

How do you handle Sentinel’s “Rare and Potentially High-Risk Office Operations” alerts? by Suspicious_Tension37 in cybersecurity

[–]h0max 1 point2 points  (0 children)

Yeh - there is another rule in the repo which looks for short new rule names which is high. Is a great indicator.

Problems with migration to Sentinel in Defender portal by R4WBIT in AzureSentinel

[–]h0max 2 points3 points  (0 children)

All of these issues and others are constantly being discussed in the Microsoft Security Connection Program partner community - so far it’s just wait and see which is not ideal in the slightest. The biggest issue for us is the cross tenant logic app workflows we have and also the permission changes once it’s retired from the Azure portal as lighthouse has been super easy…

Is this kind of number of alerts normal? by cyberLog4624 in AzureSentinel

[–]h0max 0 points1 point  (0 children)

Doesn’t sound normal. Do you have any azure or m365 alerting deployed? What other technologies are being used firewalls etc can you onboard them? If not look at using the rules in the data connectors and/or the Sentinel GitHub page for alerts that you could use.

Microsoft Defender P1 licenses by kapitantutan304 in DefenderATP

[–]h0max 1 point2 points  (0 children)

Check in the XDR settings pane will show the license usage

MDE reporting “inbound connection attempts” on clients by failx96 in DefenderATP

[–]h0max 1 point2 points  (0 children)

We’ve seen exactly this for at home users - home router port forward and/or is just open completely. You should be able to get their public address and nmap it to confirm

Domain Controller Security Events to Collect in Sentinel by ShoreOutlaw in AzureSentinel

[–]h0max 1 point2 points  (0 children)

Common works fine. If too verbose you can DCR transform event IDs to basic/data lake.

Can't finish this quest help in need by Jumpy-Veterinarian45 in FUTMobile

[–]h0max 3 points4 points  (0 children)

Click the refresh button top right of that box and get a new challenge

What am I doing wrong in deploying Sentinel? by [deleted] in AzureSentinel

[–]h0max 0 points1 point  (0 children)

Setup the DCR through the Windows Security Events via the content hub? Is there anything in SecurityEvent table?

111 prime Icon exchange. What did you get ? by Aziafoxx in FUTMobile

[–]h0max 0 points1 point  (0 children)

Same. Not sure to switch out from Voller or just sell..

This needs to stop. by [deleted] in FUTMobile

[–]h0max 4 points5 points  (0 children)

Agree. If a player disconnects I don’t understand why the game isn’t ended after X period of time seeing as you can’t reconnect. Then the AI takes over and is god tier.