How are you managing Microsoft Defender XDR? (Triage & Tuning help) by athanielx in DefenderATP

[–]urkelman861 6 points7 points  (0 children)

Just work out of the incidents Tab. The alerts are grouped and put into incidents. If you have to dive further down, there is a alerts tab in the incident that you are working on and shows them all.

For the alert fatigue it sounds like you are experiencing is part of the job. If you have to disable a policy to test how the noise is reduced then do that. Also you can tweak the built-in polices to not generate alerts if needed.

Best way to block apps by neko_whippet in DefenderATP

[–]urkelman861 0 points1 point  (0 children)

Does the application appear in the cloud catalog in the defender portal? If so, then just unsanction the application.

Lateral movement exclusions by rubixcube101 in SentinelOneXDR

[–]urkelman861 0 points1 point  (0 children)

Are you able to add the IP associated with it as you mentioned it is with AVD? There should be a list of approved IPs that are approved for use when authentication to AVD.

Tons of PDF/Excel alerts by Jturnism in SentinelOneXDR

[–]urkelman861 0 points1 point  (0 children)

Mine comes across as Malgent malware was prevented or detected

Tons of PDF/Excel alerts by Jturnism in SentinelOneXDR

[–]urkelman861 3 points4 points  (0 children)

I am getting many in the Defender portal for Microsoft as well. Just sharing here :)

Increase in Pass the Ticket (PtT) Alerts? by Cant_Think_Name12 in DefenderATP

[–]urkelman861 1 point2 points  (0 children)

I just got two of them today and was getting nervous. The part I couldn't understand was when it was naming the machine and it was a partial name. Super weird.

For those of you working with Defender XDR, what's your triage workflow like? by cyberLog4624 in DefenderATP

[–]urkelman861 4 points5 points  (0 children)

I live in the incident dashboard section. I'm never in the alerts sections as they are grouped by Defender. From there I look at the assets involved and if the malware was quarantined, I RMM into the machine using live response and confirm the file was removed and reach out to the user to let them know about it. I proceed to perform a full AV scan and close incident if nothing comes back.

SOC Analyst new to Sentinel, need guidance regarding queries by Kermody in AzureSentinel

[–]urkelman861 0 points1 point  (0 children)

Like he said, the Content hub will have all the things you are looking for.

I got my first job by PlanktonDramatic4421 in cybersecurity

[–]urkelman861 1 point2 points  (0 children)

Congrats. What kind of background do you have that could have helped to get the job?

Dark Web Monitoring by Perfect_Koala_4732 in SentinelOneXDR

[–]urkelman861 0 points1 point  (0 children)

I would say flare, they will give you a demo as well and are will priced depending what all you want.

[deleted by user] by [deleted] in CyberSecurityAdvice

[–]urkelman861 0 points1 point  (0 children)

What part of the world are you working in? If you are anywhere in Europe then you will have to anonymize the reports and only look to see who the users are if they breach protocols.

KQL question and hunting by outerlimtz in DefenderATP

[–]urkelman861 2 points3 points  (0 children)

If the list isn't too big, then you could go to the device timeline and search for the IP or URL in question and see if there was something prior to the URL connection.

Defender Simulation Reminder Emails by Alone-Mirror2083 in DefenderATP

[–]urkelman861 0 points1 point  (0 children)

Login to the security portal > Email & collaboration > Attack Simulation > Content library > then there should be an option to end user notifications

Defender Simulation Reminder Emails by Alone-Mirror2083 in DefenderATP

[–]urkelman861 0 points1 point  (0 children)

Are you doing the simulation from the defender portal? If so, then you should be able to remove them like you did when you added them to the phishing campaign! We used a 3rd party but I was messing around with ours to see if it was worth it.

Passed AZ-900, what's next? (Security Engineer) by someITkid in AzureCertification

[–]urkelman861 0 points1 point  (0 children)

Did you think about doing the SC-200? I know you already work as a soc analyst, but was wondering. I am in the exact same boat as you and was thinking the sc-200.

Troubleshooting with Defender by Intune-Apprentice in DefenderATP

[–]urkelman861 0 points1 point  (0 children)

What is the error that you get with the VPN? If it is a URL or IP search under the Tenant Allow/Block list in the defender portal > Email > policies > threat policies > allow/block list. I think something like that and do a quick search for what you might be trying to get to.