TechTalk Dudes S03E06 - Microsoft Sentinel Entity Behavior

แชร์
ฝัง
  • เผยแพร่เมื่อ 6 ต.ค. 2024
  • In this episode we walk through the ‘Entity Behavior’ feature in Microsoft Sentinel. When you come across a user account, a hostname, IP address, or an Azure resource in an incident investigation, you may decide you want to know more about it.
    For example, you might want to know its activity history, whether it's appeared in other alerts or incidents, whether it's done anything unexpected or out of character, and so on. The Enrichment widgets are recently introduced that provide you with in-depth, actionable intelligence about entities. They integrate external and internal content and data from various sources, allowing you a better understanding of potential security threats.

ความคิดเห็น •