- Видео 96
- Просмотров 258 965
AzureVlog
Нидерланды
Добавлен 8 авг 2017
Welcome to AzureVlog! Your one-stop destination for all things Microsoft Security. From mastering KQL to streamlining incident response, Microsoft Sentinel and Defender for Endpoint, we've got you covered. Join us me as I explore the endless possibilities of AI in Security and delve deeper into the world of cybersecurity. Subscribe now for valuable and informative content that will enhance your Microsoft Security skills 💻🔒 #MicrosoftSecurity #MicrosoftSentinel #Cybersecurity
How to Use Microsoft 365 Copilot Safely
Here is how Microsoft 365 Copilot can be used safely!
👉 Getting started with sensitivity labels: ruclips.net/video/D7PnAHECef8/видео.html
V I D E O S T O W A T C H N E X T :
Getting started with Purview Data Loss Prevention: ruclips.net/video/1BARW8qxa1Q/видео.html
Getting started with Copilot for Security: ruclips.net/video/AesbRF_Hys4/видео.html
--------------------------------------------
➡️ How to onboard and get started with Copilot for Security: ruclips.net/video/AesbRF_Hys4/видео.html
--------------------------------------------
Are you leveraging Microsoft 365 Copilot or using Microsoft Copilot Studio but worried about data security? In this video, we'll show you how to use Microsoft 36...
👉 Getting started with sensitivity labels: ruclips.net/video/D7PnAHECef8/видео.html
V I D E O S T O W A T C H N E X T :
Getting started with Purview Data Loss Prevention: ruclips.net/video/1BARW8qxa1Q/видео.html
Getting started with Copilot for Security: ruclips.net/video/AesbRF_Hys4/видео.html
--------------------------------------------
➡️ How to onboard and get started with Copilot for Security: ruclips.net/video/AesbRF_Hys4/видео.html
--------------------------------------------
Are you leveraging Microsoft 365 Copilot or using Microsoft Copilot Studio but worried about data security? In this video, we'll show you how to use Microsoft 36...
Просмотров: 206
Видео
How to implement data loss prevention (DLP) and protect your data like a pro
Просмотров 1,4 тыс.3 месяца назад
Here is how to get started with Purview Data Loss Prevention (DLP) 👉 Getting started with sensitivity labels: ruclips.net/video/D7PnAHECef8/видео.html V I D E O S T O W A T C H N E X T : Using Copilot for Security in Microsoft XDR: ruclips.net/video/EYu4soFAMQU/видео.html Getting started with Copilot for Security Plugins: ruclips.net/video/0WlRh7DJzCc/видео.html ➡️ How to onboard and get starte...
Getting started with Sensitivity Labels in Microsoft Purview to protect your data
Просмотров 9733 месяца назад
Here is how to get started with Sensitivity Labels in Microsoft Purview. 👉 Getting started with Data Loss Prevention (DLP): ruclips.net/video/D7PnAHECef8/видео.html V I D E O S T O W A T C H N E X T : Using Copilot for Security in Microsoft XDR: ruclips.net/video/EYu4soFAMQU/видео.html Getting started with Copilot for Security Plugins: ruclips.net/video/0WlRh7DJzCc/видео.html ➡️ How to onboard ...
Getting started with Copilot for Security Promptbooks
Просмотров 3337 месяцев назад
In this video, I'll dive deep into the world of promptbooks in Microsoft Copilot for Security. Promptbooks are powerful tools that streamline and automate various security-related tasks, enhancing the efficiency and effectiveness of your security operations. I'll start by explaining what promptbooks are and their role in the Copilot for Security ecosystem. Learn how promptbooks can automate seq...
Getting started with Copilot for Security plugins
Просмотров 3907 месяцев назад
In this video, I dive into the role that plugins play in the Microsoft Copilot for Security. Designed to enhance the functionality and efficiency of security operations, plugins allow for a highly customizable and powerful user experience. Learn how to effectively use plugins within Copilot for Security. I'll show you how to configure and personalize plugins like Microsoft Sentinel, allowing yo...
Copilot for Security in Microsoft XDR
Просмотров 5228 месяцев назад
Discover Microsoft Copilot for Security: Revolutionize your cybersecurity with the power of AI. Microsoft Copilot for Security is a cutting-edge solution that amplifies the effectiveness and efficiency of security teams. Whether you're tackling incident response, threat hunting, or gathering intelligence, Copilot for Security enhances your capabilities with AI-driven insights and actions. Integ...
Getting started with Copilot for Security
Просмотров 3,1 тыс.9 месяцев назад
Getting started with Copilot for Security
Getting started with the Microsoft Unified Security Operations Platform
Просмотров 1,8 тыс.9 месяцев назад
Getting started with the Microsoft Unified Security Operations Platform
Create sample incidents for Microsoft Defender for Endpoint
Просмотров 96610 месяцев назад
Create sample incidents for Microsoft Defender for Endpoint
Getting started with Live Response in Microsoft defender for Endpoint
Просмотров 90010 месяцев назад
Getting started with Live Response in Microsoft defender for Endpoint
Getting started with Deception as Defense in Microsoft Defender for Endpoint
Просмотров 1,5 тыс.11 месяцев назад
Getting started with Deception as Defense in Microsoft Defender for Endpoint
I used the new Microsoft Unified Security Operations Platform, it is amazing!
Просмотров 2,8 тыс.11 месяцев назад
I used the new Microsoft Unified Security Operations Platform, it is amazing!
I used vulnerability management in Defender for Endpoint. This is what i learned
Просмотров 1,4 тыс.Год назад
I used vulnerability management in Defender for Endpoint. This is what i learned
Set Up Microsoft Defender for Endpoint and Integrate with Defender for Cloud and Intune
Просмотров 5 тыс.Год назад
Set Up Microsoft Defender for Endpoint and Integrate with Defender for Cloud and Intune
Can you create your own Microsoft Sentinel Cyber Security AI assistant?
Просмотров 2,9 тыс.Год назад
Can you create your own Microsoft Sentinel Cyber Security AI assistant?
Threat Hunting: Catch an Attacker with Live-streamed Data
Просмотров 562Год назад
Threat Hunting: Catch an Attacker with Live-streamed Data
Advanced Configuring of Azure Firewall & Enhancing Cybersecurity with Microsoft Sentinel
Просмотров 820Год назад
Advanced Configuring of Azure Firewall & Enhancing Cybersecurity with Microsoft Sentinel
Getting started with Azure Firewall (2023 edition)
Просмотров 1,4 тыс.Год назад
Getting started with Azure Firewall (2023 edition)
I created a dashboard using Microsoft Sentinel Workbooks: this is what I learned
Просмотров 5 тыс.Год назад
I created a dashboard using Microsoft Sentinel Workbooks: this is what I learned
Unleash the Power: Automatically Enrich Threat Indicators in Microsoft Sentinel
Просмотров 2,3 тыс.Год назад
Unleash the Power: Automatically Enrich Threat Indicators in Microsoft Sentinel
Master Microsoft Sentinel's NRT Analytic Rules: Fast Threat Detection and Response Explained
Просмотров 1,5 тыс.Год назад
Master Microsoft Sentinel's NRT Analytic Rules: Fast Threat Detection and Response Explained
Getting started with Microsoft Sentinel Analytics Rules (Cybersecurity Usecases) (2023 edition)
Просмотров 9 тыс.Год назад
Getting started with Microsoft Sentinel Analytics Rules (Cybersecurity Usecases) (2023 edition)
Managing Microsoft Sentinel at Scale with Workspace Manager
Просмотров 3,6 тыс.Год назад
Managing Microsoft Sentinel at Scale with Workspace Manager
Fine-tuning OpenAI Model for Cybersecurity Incident Classification in Microsoft Sentinel
Просмотров 2,1 тыс.Год назад
Fine-tuning OpenAI Model for Cybersecurity Incident Classification in Microsoft Sentinel
Use OpenAI for Cyber Security with Microsoft Sentinel in a secure way
Просмотров 2,7 тыс.Год назад
Use OpenAI for Cyber Security with Microsoft Sentinel in a secure way
DIY Microsoft Sentinel LED Lamp: 3D Printing, Wiring & Firmware Tutorial
Просмотров 390Год назад
DIY Microsoft Sentinel LED Lamp: 3D Printing, Wiring & Firmware Tutorial
Rich Microsoft Sentinel Notifications in Teams: Notify and take action!
Просмотров 4,3 тыс.Год назад
Rich Microsoft Sentinel Notifications in Teams: Notify and take action!
Getting started with Microsoft Sentinel Automation (2023 edition)
Просмотров 14 тыс.Год назад
Getting started with Microsoft Sentinel Automation (2023 edition)
Getting started with Threat Hunting in Microsoft Sentinel
Просмотров 5 тыс.Год назад
Getting started with Threat Hunting in Microsoft Sentinel
Getting started with Microsoft Sentinel Tasks to Standardise Cyber Security Incident Response
Просмотров 2,9 тыс.Год назад
Getting started with Microsoft Sentinel Tasks to Standardise Cyber Security Incident Response
How much does it cost for these labs?
very instructive video, keep going
You are great!
Amazing thank you and amazing coffee machine BTW!
Hey, I really liked your content; it is really good. Can you please share your GitHub repo or the ARM template used?
Thanks for your video! Very informative. Could you please make more videos like this? We are in the early stages of building out Copilot usage for 365 and I found this extremely helpful. Thank you
we need to see how we can cover all these points and make sure the number of secure score increased
Are these lures/decoys installed on actual devices?
Yes; the "breadcrumbs" are deployed to devices. When a user is using them (e.g. a DNS entry to a host), Defender will create an alert.
Will I be able to use the graph API to send Microsoft Defender alerts to a ticket system?
Thanks AzureVlog Team for the content, Screen clarity can be improved , not able to read words and options you are selecting,
Are there any types of sentinel alerts that won't show up in MSgraph API? We are ingesting msgraph API alerts and we have a lot of sentinel and defender alerts being logged to the SIEM, but there was one type of sentinel alert which was a scheduled detection i believe that didn't show up in our msgraphAPI logs and I can't figure out why?
Opbouwend kritiek: oefen het alfabet in het Engles want je gebruikt de Nederlandse uitspraak ❤
DLP On-premises Scanner 😊
Friend, I just started my first job, and my first challenge is working in Purview with another colleague. We were running tests and realized that we created the labels, then published them, but we only applied them to our users. However, we were later informed that other users in the organization reported labeled files, even though they weren’t included. I’m not sure if you might have an idea of how to fix this. We also added groups, but the labels didn’t apply. Another thing is that the DLP part is something to include later (Sorry, I’m still documenting myself). What could have happened?
Check if Auto labeling Policy was created and in Enforced mode
Just brilliant - exactly what I have been looking for. Dank je wel.
Thanks for the content. Is this the same process as the one for onboarding to Defender for Endpoint? In other words I don't have MDE so I can't onboard devices but I do get the option from Purview..
Thanks man very helpful
Thank!
You are a life saver. Thanks man!
You're welcome! Great to help you out!
Can you help me with more repro of the deception feature please please..if u can help me with the test commands so that I can reproduce it
Sure! Hit me a DM trough LinkedIn please!
Hi, I need to know the ip address of the machine I'm connected to...
More pls
Thanks
need more of this pls! but how do you give the permissions to the RG? do you do that under logic apps role assignment and scope to the RG of the workspace?
thank u man
You are a living legend, thanks for the TIps
Came for azure stayed for the coffee
Good tip!
Nice introduction! Please keep sharing 👍
Good demonstration 🎉
awesome content
Hi, I'm always trying to replicate in a lab all your videos, so that I can truly learn and understand, Thanks a lot for all your videos. Can you provide more details on the App Registration and on the "Parse JSON" action? I'm stuck in those two...
i think sentinel can automatically do this now...saw a video about auto integration with virus total
Hi there please can you share the video link or github link
really nice, really cool
Just what I needed to onboard my first servers using Defender for Cloud tomorrow.
It always says the following error: Can't get account information Try again in a few minutes. If the issue persists, contact an administrator. please help me
How do you connect and setup the azure firewall
The problem is this is very expensive. 😂
Congratulations on your channel; it's helping me a lot. It's always bringing new information and helping those who want to stay updated in the world of Microsoft cybersecurity. You are very good! Thank you for sharing with us
In sentinel log in OperationName column nothing is appearing what to do?
Nice introduction, I'm looking forward to see some of the uses for Copilot for Security. I just deployed it in my tenant and began using it. I'm currently working on having it automatically provide an executive summary for incidents using the one from the promptbook. Since there isn't a way to run a whole promptbook automatically, I am writing a Logic App in Sentinel that basically runs each prompt of that promptbook, and will continue using the same session ID for each one until the executive summary is complete. Then, it can add the summary to the incident as a comment. Since this normally takes some time, having it run automatically so the comment is already present by the time you review the incident will be nice. Another tip to optimize SCU resource utilization is to limit using Copilot for queries. If there is something that can be defined by a KQL query, you can do that and feed the results to Copilot instead of asking it to do that query. For example, instead of saying "Go back and tell me about Security Incidents in Sentinel that happened in the last 12 hours", you can run a KQL query to return the Incident numbers during your desired time, and then instead ask Copilot "Tell about about the following Security Incidents" and then list the KQL results. This way Copilot doesn't have to use resources to figure out simple things like "what time is it now and how far is 12 hours back" and "What incidents were created in that time range". Cheers!
I need to be able to collect and change alerts' status from an external alert management system. Should I use Graph Security API or Azure Management API? What are the prerequisites for the Sentinel alerts appearing in the graph API? Thanks!
tried this, said it no longer works at open ai model is deprecated. is there any workaround?
can you make a video to show how to auto add ip addresses or urls detected in your TI feed to your org's block list automatically
Security Copilot is not living up to the potential promised in current version. It can not decode base64 and it can not decode powershell obfuscated script if it has more then a few words. the limitations here are massive. And the code analyser uses so much SCU even if it fails (6 to 8.5).
Hi! Thanks for your response. I see this version as just the initial version of Copilot for Security. I think it has al the potential to become a very good security assistent. I just tested base64 encoding. That did work actually. I haven't fed a large script with multiple layers of obfuscation to it as I don't have such a file available at the moment; but would love to give it a try.
Good job and Nice video! Please keep sharing❤ Looking forward to seeing Purview related video, thanks
Thanks for the suggestion! Purview is on the list of things to make videos about 🙂
Kudos to you mate, great high level tutorial. Implementing similar to gather response for risky users :).
Can you create openai do a simple video in sentinel to reduce false positives ?
Is there anyway to reduce false psotives in azure ?
Hello, do you know if Multi Tenant Support for the unified Portal will be available (for example if I have multiple Sentinel Workspaces with Azure Lighthouse or Multiple XDR Tenants via MTO Defender)?
Greetings and thank you for all your great content. I've really been looking forward to the unification of Defender Portal and Sentinel but once connected I felt there is alot missing still. Playbooks for example. We use those extensively to enrich our entities in Sentinel Incidents but I have yet to find a way to do that in the Defender Portal
What do you think of it today? I know some things will still live in the Azure Portal; but have you got used to the new portal?