Microsoft Sentinel

https://pariswells.com/blog/research/microsoft-sentinel-pricing

Create a new Log Analytics workspace because you probably have all your logs everywhere

Enable Sentinel On Logs Analytics

Choose Common for SecurityLogs

Install Connectors for everything you have

Cloudapps

Turn on the UEBA feature

Setup Enrichment Services : [Part1] New Microsoft Sentinel’s Enrichment Widget in UEBA Module – Hacknowledge

Import Bulk Analytics

GitHub – MSSAPSCA1/Azure_Sentinel: Bulk turn on Analytic rules in Azure Sentinel

GitHub – garybushey/AzSentinelAnalyticsRules: PowerShell commands to export the Azure Sentinel Rule Templates to a CSV and to create the Rules from selected entries in the CSV file

SecureHacks/scripts/Azure/Sentinel/Enable-AlertRules at main · SecureHats/SecureHacks · GitHub

1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading...