Building Microsoft Sentinel Usecases with automation using playbooks

แชร์
ฝัง
  • เผยแพร่เมื่อ 5 ม.ค. 2025

ความคิดเห็น • 16

  • @willemplug3366
    @willemplug3366 2 ปีที่แล้ว

    Love the time and effort you put in the coffee edit😁

  • @yt0ng646
    @yt0ng646 3 ปีที่แล้ว +1

    You are doing a fantastic job here, thanks a lot !

  • @Christian-np6je
    @Christian-np6je 2 ปีที่แล้ว

    Awesome video and summary! Thanks a lot!

  • @motorhead1791
    @motorhead1791 8 หลายเดือนก่อน

    In sentinel log in OperationName column nothing is appearing what to do?

  • @shijin_suresh
    @shijin_suresh ปีที่แล้ว +1

    Great Job! Thanks

  • @polonia66
    @polonia66 2 ปีที่แล้ว

    HI, thank you for your great videos. I have question about 42:51
    If i would like to set playbook to block the user, what is the best way to do it? as i can see in your case - you add URL with username? so this playbook will be just for one user,
    how to do with case of any user?

    • @AzureVlog
      @AzureVlog  2 ปีที่แล้ว +1

      You can use variables in the URI of the HTTP activity. You use the "Entities - Get Account" activity to retrieve the username. Then use that username as variable in the URI. It is actually quite bad that I "hardcoded" the username in the URI of the HTTP activity.

    • @polonia66
      @polonia66 2 ปีที่แล้ว

      @@AzureVlog thank you so much!

  • @wilkinsanchez8737
    @wilkinsanchez8737 3 ปีที่แล้ว +1

    Excellent video. How do you keep track of your expenses when doing these labs? How much money do you usually spend? Is there a way I could do things like this in a lab environment without worrying for a big bill?

    • @AzureVlog
      @AzureVlog  ปีที่แล้ว

      As long as you don't ingest that much data into Microsoft Sentinel, it isn't expensive. You pay per GB that gets ingested into Sentinel. Another way to keep things within budget, is to delete resources after finishing your lab.

  • @jytan740
    @jytan740 2 ปีที่แล้ว

    is there any guide that can help splunk users translate from SPL to KQL?

  • @paul.delasaux
    @paul.delasaux 3 ปีที่แล้ว

    Keep it up! These are good.

  • @bala007raju
    @bala007raju 2 ปีที่แล้ว

    very nice video , thanks lot

  • @progod6017
    @progod6017 ปีที่แล้ว

    Good video

  • @IamSahilVerma
    @IamSahilVerma 3 ปีที่แล้ว

    First like from Canada..

  • @IamSahilVerma
    @IamSahilVerma 3 ปีที่แล้ว +1

    First like from Canada...