Blog Post

Microsoft Sentinel Blog
4 MIN READ

Introducing SOC Optimization Recommendations Based on Similar Organizations

NirAnchel's avatar
NirAnchel
Icon for Microsoft rankMicrosoft
Dec 19, 2024

One of the key challenges that security teams in modern SOCs regularly face is determining which new data sources to onboard and which detections to activate. This ongoing process takes time and requires constant evaluation of the organization’s assets and the value that the data brings to the SOC.

 

"…determining which logs to ingest for better threat coverage is time-consuming and requires significant effort. I need to spend a long time identifying the appropriate logs..." 
Elie El Karkafi, Senior Solutions Architect, ampiO Solutions

 

Today, we’re excited to announce the public preview of recommendations based on similar organizations - a first-of-its-kind capability for SOC optimizations. Recommendations based on similar organizations use peer-based insights to guide and accelerate your decision-making process.

 

We believe that applying insights learned from the actions of organizations with similar profiles can provide great value. Recommendations based on similar organizations use advanced machine learning to suggest which data to ingest, based on organizations with similar ingestion patterns. The recommendations also highlight the security value you can gain by adding the data. They list out-of-the-box rules that are provided by Microsoft research, which you can activate to enhance your coverage. 

 

Use the new recommendations to swiftly pinpoint the next recommended data source for ingestion and determine the appropriate detections to apply. This can significantly reduce the time and costs typically associated with research or consulting external experts to gain the insights you need.

 

Recommendations based on similar organizations are now available in the SOC optimization page, in both the Azure portal and the unified security operations platform:

Recommendations based on similar organizations - unified security operations platform

Use cases

Let’s take a tour of the unified security operations platform, stepping into the shoes of a small tech company that benefited from recommendations based on similar organizations during its private preview phase. In the following image, the new recommendation identifies that the AADNonInteractiveUserSignInLogs table is used by organizations similar to theirs: 

 

Selecting View details button on the recommendation card allowed them to explore how other organizations use the recommended table. This includes insights into the percentage of organizations using the table for detection and investigation purposes. 

Recommendations based on similar organizations, side panel - unified security

 

By selecting See details hyperlink, the SOC engineer was able to explore how coverage could be improved with respect to the MITRE ATT&CK framework, using Microsoft’s out-of-the box rules: 

Recommendations based on similar organizations, side panel - unified security operations platform


By selecting Go to Content hub, the SOC engineer was able to view all the essential data connectors needed to start ingesting the recommended tables. This page also includes a detailed list of out of the box, recommended analytics rules, which can provide immediate value and enhanced protection for your environment:

Recommendations based on similar organizations - unified security operations platform  


Finally, by following the recommendation, which uses the security practices of similar organizations as a benchmark, the tech company quickly ingested the AADNonInteractiveUserSignInLogs table and activated several recommended analytics rules. Overall, this resulted in improved security coverage, corresponding to the company's specific characteristics and needs. 

Feedback from private preview:

“I think this is a great addition. Like being able to identify tables not being used, it is useful to understand what tables other organizations are utilizing which could reveal things that so far haven't been considered or missed...” 
Chris Hoard, infinigate.cloud 

"In my view, those free recommendations are always welcomed and we can justify cost saving and empowering SOC analysts (that we know are more and more difficult to find)." 
Cyrus Irandoust, IBM 

“These recommendations will help us to take a look at the left out stuffs” 
Emmanuel Karunya, KPMG

“Nice overview and insights! Love the interface too - nice and easy overview!” 

Michael Morten Sonne, Microsoft MVP  

Q&A:

Q1: Why don’t I see these recommendations? 
A: Not all workspaces are eligible for recommendations based on similar organizations. Workspaces only receive these recommendations if the machine learning model identifies significant similarities between your organization and others, and discovers tables that they have but you don’t. If no such similarities are identified, no extra recommendations are provided. You’re more likely to see these recommendations if your SOC is still in its onboarding process, rather than a more mature SOC. 

Q2:  What makes an organization similar to mine? 
A: Similarity is determined based on ingestion trends, as well as your organization's industry and vertical, when available in our databases.  

Q3: Is any of my PII being used to make recommendations to other customers?
A:  No. The recommendations are generated using machine learning models that rely solely on Organizational Identifiable Information (OII) and system metadata. Customer log content is never accessed or analyzed, and no customer data, content, or End User Identifiable Information (EUII) is exposed during the analysis process. Microsoft prioritizes customer privacy and ensures that all processes comply with the highest standards of data protection. 

Looking forward 

Microsoft continues to use artificial intelligence and machine learning to help our customers defend against evolving threats and provide enhanced protection against cyberattacks. This ongoing innovation is a key part of SOC optimization’s commitment to help you maximize your value from your SIEM & XDR.  

Learn More:  

SOC optimization documentation:  SOC optimization overview ; Recommendation's logic 

Short overview and demo:  SOC optimization Ninja show 

In depth webinar:  Manage your data, costs and protections with SOC optimization 

SOC optimization API: Introducing SOC Optimization API | Microsoft Community Hub 

Updated Dec 19, 2024
Version 1.0
  • It’s so exciting to see this finally released, as it will help us all immensely! It’s truly an honor to be part of this journey and contribute to making these products even better together! 😎

    Merry Chrismas! 🎄🚀