Forum Discussion
Ninja Cat Giveaway: Episode 3 | Sentinel integration
For this episode, your opportunity to win a plush ninja cat is the following -
Reply to this thread with: what was your favorite feature Javier presented? Oh and what does UEBA stand for?
This offer is non-transferable and cannot be combined with any other offer. This offer ends on April 14th, 2023, or until supplies are exhausted and is not redeemable for cash. Taxes, if there are any, are the sole responsibility of the recipient. Any gift returned as non-deliverable will not be re-sent. Please allow 6-8 weeks for shipment of your gift. Microsoft reserves the right to cancel, change, or suspend this offer at any time without notice. Offer void in Cuba, Iran, North Korea, Sudan, Syria, Region of Crimea, Russia, and where prohibited.
38 Replies
- what was your favorite feature Javier presented?
remediation playbooks for Microsoft 365 Defender with Automation. And the MITRE ATT&CK Preview Overview.
Oh and what does UEBA stand for?
UEBA = User and entity behavior analytics - TrulsTDCopper Contributor
For me the best part is the automation rules and playbooks.
UEBA is User and Entity Behavior Analytics 😁👍 - Fabian BaderBrass ContributorThe new incident page shown is really great. Enjoyed using it since day one. The direct integration of M365D links makes it so much easier and the exposed entities help to get additional UEBA (User and Entity Behavior Analytic) information. Which in my opinion is one of the hidden champions in the products. Have to do an new blog in this especially on how to expose more insights to the analyst
- paleskinnyswedeCopper Contributor
First of all, it was a great presentation even for me who's been working with Sentinel for a couple of years.
I really liked the MITRE ATT&CK heat map. That's a great addition to the service so we can see where our gaps are.
UEBA is User and Entity Behaviour Analytics.
And I was the one who replied to you on LinkedIn mentioning that a dog person giving away cats for free 😉 Since the Ninja cat was chased by a dog at 18:27 I'd like to adopt one to keep it safe from harm. And as you can see on my avatar, I need a sidekick on our superhero endeavours fighting cybercrime and annoying antagonists on a daily-basis.- HeikeRitter
Microsoft
😄 hahaha, I am still laughing thinking about that comment! Your answer is perfect, and one cat will be extremely happy to get adopted by you ❤️ check your mailbox here
- pnorman821Copper ContributorHeikeRitter
In the episode I enjoyed learning that Content Hub (Preview) contains more connectors/logs that can be ingested into Azure Sentinel. Also 'Next Steps' on the connector page showing what KQL can be used to look for those logs.
UEBA stands for User and Entity Behavior Analytics - lukepessoaCopper Contributor
One of my favorite features presented by Javier in the video was the threat-hunting module in Microsoft Sentinel which enables security analysts to proactively search for security threats within an organization's IT environment.
I find the threat-hunting module a powerful tool that allows organizations to proactively detect and respond to potential threats before they escalate into more serious security incidents.
UEBA stands for User and Entity Behavior Analytics. It is a type of cybersecurity technology that uses machine learning algorithms to analyze and identify anomalous behavior patterns in users and entities accessing a computer network. The goal is to detect potential insider threats or external attacks that may be missed by traditional security measures.- HeikeRitter
Microsoft
Hi Luke! I checked with Javier, just to be sure I am not missing anything, and he did not present this in the show.- lukepessoaCopper ContributorThat's funky. I must have had something else on my mind, but I rewatched the video and edited my response. Thank you!
- Rob_B777Copper ContributorEUBA is threat hunting using behavior analytics. One of the things I found incredibly helpful is the connectors with the various non MS products. This helps build Sentinel as the SIEM that will make data coorilations for me.
- CloudHunter007Copper Contributor
Hello Heike, great show! Thank you for having Javier on.
EBA == User and Entity Behavior Analytics
UEBA uses Artificial Intelligence (AI) and Machine Learning (ML) algorithms used to
establish a user and entity baselines and then monitor/identify anomalies, impossible travel,
and/or any other inconsistent behaviors from established baselines. Originated from FinTech as a means to minimize credit card fraud.SOAR == Security, Orchestration, Automation, and Response is needed as SOC analysts have to do more with less. SOAR can also reduce alert fatigue in Analysts by handling common activities / alert and when a certain threshold is exceeded, alert the SOC Analyst to events they should really focus on. This is a critical capability.
One of my favorite features of Sentinel is the Fusion Analytic correlation engine that uses 10's of trillions of signals (daily) with AI/ML to produce low noise, high fidelity alerts. This dynamic content feeding Sentinel raises the bar from static on-premises manual processes into a continuous cloud powered platform!
I particularly like how Sentinel can bring in visibility from other Defender Security solutions, cloud providers, on-premises infrastructure via Azure Arc and provide dashboards with dynamic displays in a single pane of glass. I also like how Kusto Query Langauge (KQL) can be used in M365 Defender, Sentinel, Log Analytics, and Azure Data Explorer. One common language used to deeply explore, enrich, and correlate information across various Azure security solutions (MDE,MDI,MDC,MDO, etc).
Lastly the automation demonstration through logic apps and the Microsoft 365 Defender connector in Sentinel was great! This cross-functional integration of telemetry woven into and through the Azure security solution stack is impressive and very useful when it comes to event/alert enrichment, correlation, thus illuminating the operational environment folks are responsible for defending. - P4tr8kBrass ContributorDefinietly the Automation section! I'm currently working on it in my organization, so the information from the episode came in handy.
UEBA - User and Entity Behavior Analytics - sifriger
Microsoft
my favorite feature is fusion that automatically fuse together all alerts using ML and AI
UEBA = User and Entity Behavior Analytics