SecOpsLab
Subscribe
Sign in
Home
Archive
About
New
Top
Discussion
Microsoft Sentinel data engineering with Cribl
With fresh experience from client log pipeline development projects, I wanted to share some quick notes on Sentinel and Cribl Stream integration.
Nov 18
•
Mikko Koivunen
Share this post
Microsoft Sentinel data engineering with Cribl
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
October 2023
Quality assurance in Microsoft Sentinel: how to ensure accurate threat detections?
You've just pushed 100 Analytics Rules to a Sentinel instance. Mission accomplished, right?
Oct 4
•
Mikko Koivunen
Share this post
Quality assurance in Microsoft Sentinel: how to ensure accurate threat detections?
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
August 2023
Unlocking Application Visibility in Defender for Cloud Apps
A quick article on how to give an application administrator restricted visibility to a specific app in Defender for Cloud Apps.
Aug 30
•
Mikko Koivunen
Share this post
Unlocking Application Visibility in Defender for Cloud Apps
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
June 2023
Introducing the SolutionKB
I am building something new - a searchable database for Microsoft Sentinel Content Hub Solutions.
Jun 28
•
Mikko Koivunen
Share this post
Introducing the SolutionKB
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
Maintain a Watchlist on Public IPs in Azure
A simple Logic App for collecting Public IP address resources into a Microsoft Sentinel Watchlist from your Azure tenant
Jun 15
•
Mikko Koivunen
2
Share this post
Maintain a Watchlist on Public IPs in Azure
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
1
May 2023
Facing a problem with Microsoft 365 Defender Data Connector in Sentinel?
A quick post to document an unofficial, hopefully temporary workaround for an "Interaction required" error when configuring the M365 Defender connector.
May 9
•
Mikko Koivunen
1
Share this post
Facing a problem with Microsoft 365 Defender Data Connector in Sentinel?
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
4
Living in a Lighthouse: Defender for Cloud
Azure Lighthouse provides cross-tenant management capabilities in Defender for Cloud. Let's take a brief look at how it works in practice and what the…
May 2
•
Mikko Koivunen
Share this post
Living in a Lighthouse: Defender for Cloud
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
April 2023
Incident management & on-call schedules with Microsoft Sentinel
Are there benefits in using a separate incident management platform together with a SIEM? Let's investigate.
Apr 10
•
Mikko Koivunen
2
Share this post
Incident management & on-call schedules with Microsoft Sentinel
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
March 2023
Using Managed Identities in Azure AD response playbooks
Some notes related to authenticating with the out-of-the-box (OOTB) provided Microsoft Sentinel Playbooks for Azure AD.
Mar 24
•
Mikko Koivunen
Share this post
Using Managed Identities in Azure AD response playbooks
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
February 2023
Enterprise-scale SecOps: Azure architecture
How to deploy a well-architected security toolkit in Azure?
Feb 6
•
Mikko Koivunen
1
Share this post
Enterprise-scale SecOps: Azure architecture
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
January 2023
Microsoft Sentinel: Living in a Lighthouse
For 2023 I have set myself a goal of doing feature focus videos for Microsoft Sentinel. First one goes live now, showing the user experience of…
Jan 25
•
Mikko Koivunen
Share this post
Microsoft Sentinel: Living in a Lighthouse
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
November 2022
Different approaches to Detection as Code
Introduction While I spend most of my “SIEM time” in Microsoft Sentinel these days, I believe it’s important to understand how the product field in…
Nov 25, 2022
•
Mikko Koivunen
Share this post
Different approaches to Detection as Code
secopslab.substack.com
Copy link
Facebook
Email
Note
Other
This site requires JavaScript to run correctly. Please
turn on JavaScript
or unblock scripts