SecOpsLab
Subscribe
Sign in
Home
Archive
About
Notes on multi-tenant Defender and Sentinel management
A quick look into a rapidly developing field; how to do multi-tenant management in Defender and Sentinel, when the Unified XDR & Sentinel is portal is…
Nov 26
•
Mikko Koivunen
2
3
Latest
Top
Discussions
Microsoft Sentinel incident list in Teams
A live view of Microsoft Sentinel incidents directly in Microsoft Teams? Its possible and as I’ve implemented this a few times recently, I wanted to…
Jan 30
•
Mikko Koivunen
8
6
3
Modular playbook architectures
Sometimes we end up building problems for ourselves when creating automations in Microsoft Sentinel. One way to work around some of these problems is to…
Jan 23
•
Mikko Koivunen
3
Differentiate XDR and SIEM incidents
After onboarding to Unified SIEM & XDR portal, the incident status and history log table gets a rewrite. We need a new approach to differentiate between…
May 30, 2024
•
Mikko Koivunen
1
Direct linking to Microsoft Sentinel incidents in the unified portal
This might be the smallest thing I've ever written about here, but anyhow.. If you've onboarded to SIEM & XDR unified portal, you may wonder how to…
May 23, 2024
•
Mikko Koivunen
Send custom data from Logic Apps to Microsoft Sentinel
How to send custom data from Azure Logic Apps to Microsoft Sentinel using the Logs Ingestion API.
Apr 9, 2024
•
Mikko Koivunen
1
Enterprise-scale SecOps: Naming conventions
Continuing on a journey started in early 2023. How to deploy a well-architected security toolkit in Azure? This time we look at resource naming…
Jan 25, 2024
•
Mikko Koivunen
1
Multi-tenant XDR incidents in Microsoft Sentinel
The native Sentinel Connector for Microsoft Defender XDR only supports integration inside one tenant. How to collect incidents from multiple tenants to…
Jan 11, 2024
•
Mikko Koivunen
7
1
See all
SecOpsLab
Articles by Mikko Koivunen on security operations & threat detection, usually in the Microsoft cloud ecosystem.
Subscribe
Recommendations
Detection Engineering Weekly
Zack Allen
Cyber Defence Analysis for Blue & Purple Teams
Ollie
SecOpsLab
Subscribe
About
Archive
Recommendations
Sitemap
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts