Working with Threat Intelligence in Azure Sentinel

Поделиться
HTML-код
  • Опубликовано: 10 дек 2024

Комментарии • 11

  • @nimaforoughi3008
    @nimaforoughi3008 3 года назад +1

    Hi Jeroen, can you explain in a video how to automatically ingest the latest suspicious IP-Addresses or domains from Threat intelligence platforms or feeds into our Sentinel Analytics?

  • @antoniogomezmartin7455
    @antoniogomezmartin7455 2 года назад

    There are Threat Intelligence services like Maltiverse that can be connected to Sentinel via TAXII connector. That works great

  • @prasantchettri133
    @prasantchettri133 Год назад

    How does the TIP knows that it is connected to right registered app? Step 2 of MS article suggest - For the target product, specify Azure Sentinel. But I do not see that in app registration or Sentinel. Also, anomal website has now been shut and I cannot use it in the bicep anymore?

  • @shanayshah4133
    @shanayshah4133 Год назад

    How would you create a analytics query to search only new IOCs over a period of 90 days?

  • @deep001007
    @deep001007 Год назад

    Best video on TI in Sentinel

  • @amaurisrodriguez9914
    @amaurisrodriguez9914 3 года назад

    Hi Jeroen, Have you found a way to import IOCs into Sentinel from a STIX file?...here in USA usually CISA provides downloadable copy of IOCs via a STIX file.

    • @AzureVlog
      @AzureVlog  3 года назад +1

      Hi Amauris, I haven't done that yet. It does make sense to use STIX as it is becoming an industry standard. Let me figure out how STIX and Azure Sentinel can work together and let me get back to you.

    • @amaurisrodriguez9914
      @amaurisrodriguez9914 3 года назад

      @@AzureVlog Thanks for the prompt response. Take your time, I am doing my research as well.

  • @nirmaal2255
    @nirmaal2255 8 месяцев назад

    make video on MISP to Azure Sentinel Integration with diagram

    • @AzureVlog
      @AzureVlog  8 месяцев назад +1

      That video might be on the backlog to create! Currently working on a integration of MISP with Sentinel :-)

    • @nirmaal2255
      @nirmaal2255 8 месяцев назад

      @@AzureVlog Thank you