Unleash the Power: Automatically Enrich Threat Indicators in Microsoft Sentinel

Поделиться
HTML-код
  • Опубликовано: 3 дек 2024

Комментарии • 13

  • @verdugocolon250
    @verdugocolon250 Год назад

    I usually watch the videos on your channel in the morning and the coffee sections are so good that they make me make myself a coffee before continuing to watch the videos. With this, I feel that we are having coffee together and discussing the subject of the video.

  • @progod6017
    @progod6017 Год назад +2

    sick alternative to using the free virustotal api.
    huge shoutout to u for showing this around.

    • @progod6017
      @progod6017 Год назад

      I mean this would be great, does it cost 4 k a month? lmao

    • @hamzacyber_lab
      @hamzacyber_lab Год назад

      @@progod6017 lol

  • @purplesprout5774
    @purplesprout5774 Год назад +1

    Thanks for covering data enrichment for Sentinel, really beginning to make use of it. Do you have plans to cover the use of MIcrosoft's Sentinel Triage Assistant (MSTAT)? There is, I understand the connectors and modules which help with the initial triage looking at the history of the entities in the incident and risk scoring these, ultimately adjusting the severity of the incident based on this risk score.

    • @Cloud4Paul
      @Cloud4Paul Год назад

      For STAT, most don’t understand it, but fairly easy to set up in a lab or in a commercial environment. Huge advantage for a SOC team as it is basically an additional analyst.

    • @AzureVlog
      @AzureVlog  Год назад

      Thanks for mentioning it! I will have a look into MSTAT and maybe create a video about it!

  • @DeepakRay4
    @DeepakRay4 Год назад

    Do you have plans to share automation videos for blocking IOC's on PaloAlto, Fortinet, Other Firewalls etc. Loving your videos Thank you :)

  • @Pita_22
    @Pita_22 5 месяцев назад

    Hi, I'm always trying to replicate in a lab all your videos, so that I can truly learn and understand, Thanks a lot for all your videos. Can you provide more details on the App Registration and on the "Parse JSON" action? I'm stuck in those two...

  • @adventuresofa9jaguy322
    @adventuresofa9jaguy322 6 месяцев назад

    i think sentinel can automatically do this now...saw a video about auto integration with virus total

    • @YashimaTameyoshi
      @YashimaTameyoshi 5 месяцев назад

      Hi there please can you share the video link or github link

  • @nasyaramadhana6788
    @nasyaramadhana6788 Год назад

    Do you have linkedin sir? Lets connect

    • @AzureVlog
      @AzureVlog  Год назад

      Sure! Just search on Jeroen Niesen and you will find my profile :-)