Getting started with Microsoft Sentinel Tasks to Standardise Cyber Security Incident Response

Поделиться
HTML-код
  • Опубликовано: 25 окт 2024

Комментарии • 6

  • @janetwilcox5314
    @janetwilcox5314 Год назад

    Outstanding

  • @progod6017
    @progod6017 Год назад

    I had no idea virus total has a free API. Thanks for sharing!

    • @alexandervogtsanchez7522
      @alexandervogtsanchez7522 9 месяцев назад +1

      It's pretty much useless if you have a medium to high volume of IPs included in alerts/incidents. Rate limit is like 4 per minute.
      BTW sentinel now has enrichment widgets for IP addresses so no need to include a task for this.
      If you still want to use logic apps, use the HTTP connector rather than the built-in virus total one. This way you can check the status code of the call. If it returns 204 you can call another HTTP with a different api key. Somewhat ugly but could work to overcome rate limitations

    • @progod6017
      @progod6017 9 месяцев назад

      it is actually useless. true. @@alexandervogtsanchez7522

  • @jackobyte
    @jackobyte Год назад

    Great video, just wondering.. adding the tasks (via the automation rule) shouldnt have an effect on costs? its only when they are logic apps? is that right?

  • @b2secops
    @b2secops Год назад

    Thanks for the video, do you require VirusTotal premium for the lookup from Sentinel to work?