Microsoft Sentinel automation rules to manage response | Logic Apps | Automation Rules | Playbooks

แชร์
ฝัง
  • เผยแพร่เมื่อ 21 ม.ค. 2025

ความคิดเห็น • 8

  • @Absolut257
    @Absolut257 วันที่ผ่านมา

    Good illustration of making automation rules. Side note and this is probably obvious for most folks, in this particular example the right way to do things would have been to create the analytic rule to already ignore the office space IP range so as not to waste time and money creating additional automation rule to suppress the resulting false positives.

  • @krishnabadrib1706
    @krishnabadrib1706 ปีที่แล้ว +1

    Do Soc analyst L1 will do this in office!

    • @SudoRootcast
      @SudoRootcast  ปีที่แล้ว +1

      Not sure, Its Depends Usually L2 and L3. Thanks!

  • @Fmd63067
    @Fmd63067 6 หลายเดือนก่อน

    what is authpriv? failed login attempts in authpriv, Is it like a table of logs?

    • @SudoRootcast
      @SudoRootcast  6 หลายเดือนก่อน

      unix.stackexchange.com/questions/59525/difference-between-authpriv-and-auth

  • @VivekSharma-vy1xk
    @VivekSharma-vy1xk ปีที่แล้ว +1

    Great content. I followed it step wise for MFA related Incidents. It failed me on 3rd step with error : 
    ExpressionEvaluationFailed. The execution of template action 'For_each' failed: the result of the evaluation of 'foreach' expression '@triggerBody()?['object']?['properties']?['Alerts']' is of type 'Null'. The result must be a valid array. Am I missing something here?

  • @RaniUG
    @RaniUG ปีที่แล้ว

    Are data connector , , analytic rule playbook are interconnected?