Creating a Proof of Concept with Azure Sentinel

%3CLINGO-SUB%20id%3D%22lingo-sub-2576630%22%20slang%3D%22en-US%22%3ECreating%20a%20Proof%20of%20Concept%20with%20Azure%20Sentinel%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2576630%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22salkhan_0-1626976927034.png%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F297706i8CFB87424B0C4850%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%22salkhan_0-1626976927034.png%22%20alt%3D%22salkhan_0-1626976927034.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%202020%2C%20when%20everything%20was%20in%20lockdown%2C%20I%20spent%20quite%20a%20lot%20of%20time%20in%20getting%20to%20know%20how%20to%20create%20a%20proof%20of%20concept%20for%20Azure%20sentinel%2C%20and%20show%20its%20value%20to%20the%20management.%20I%20found%20quite%20a%20lot%20of%20resources%20on%20the%20internet%2C%20and%20used%20many%20hours%20studying%20Microsoft%20security%20blogs%20to%20find%20out%20best%20ways%20of%20doing%20it.%20I%20will%20share%20my%20experience%20here%2C%20so%20that%20it%20is%20a%20bit%20easier%20for%20our%20colleagues%20in%20the%20community%20to%20implement%20it.%20The%20idea%20with%20this%20proof%20of%20concept%20is%20to%20show%20the%20following%20in%20action%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CTABLE%20width%3D%22462%22%3E%3CTBODY%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E1%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3ESecurity%20Orchestration%20%26amp%3B%20Automated%20Response%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E2%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3ESecurity%20Analytics%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E3%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3EThreat%20Monitoring%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E4%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3EAdvanced%20cyber%20threat%20detection%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E6%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3ENetwork%20insights%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E7%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3EUser%20Behavior%20Analysis%20(UBA)%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E8%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3ENetwork%20Hierarchy%26nbsp%3B%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3CTR%3E%3CTD%20width%3D%22108%22%3E%3CP%3E9%3C%2FP%3E%3C%2FTD%3E%3CTD%20width%3D%22355%22%3E%3CP%3EEvents%20and%20Alerts%3C%2FP%3E%3C%2FTD%3E%3C%2FTR%3E%3C%2FTBODY%3E%3C%2FTABLE%3E%3CP%3E%3CBR%20%2F%3E%3CBR%20%2F%3ETo%20start%2C%20you%20must%20have%20Azure%20AD.%20Connecting%20onPremises%20AD%20via%20MMA%20will%20not%20work%2C%20because%20Sentinel%20will%20not%20have%20access%20to%20password-hashes%20and%20wont%20know%20if%20passwords%20were%20breached.%20Also%2C%20Azure%20AD%20will%20be%20important%20to%20test%20features%20like%20CASB%20etc.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you%20have%20AAD%20in%20place%2C%20you%20must%20make%20an%20architecture.%20It%20is%20to%20visualize%20how%20it%20will%20be%20implemented%20and%20how%20it%20will%20look%20like%20when%20it%20has%20gone%20live.%20It%20is%20possible%20that%20the%20POC%20will%20be%20extended%20to%20get%20into%20production%20on%20same%20tenant%2C%20so%20plan%20accordingly.%20For%20example%2C%20scoping%20around%20how%20many%20devices%20(onPrem%20%26amp%3B%20cloud)%20will%20participate%20in%20it.%20Which%20services%20to%20include%20in%20POC.%26nbsp%3B%20If%20you%20are%20using%20O365%2C%20it%20will%20be%20obvious%20to%20include%20this%20as%20well%2C%20to%20see%20malicious%20links%20and%20attachments%20and%20getting%20alerted%20on%20it.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESince%20it%20is%20a%20POC%2C%20you%20can%20save%20some%20money%20on%20using%20Anomali%20as%20a%20TI%20feed.%20It%20offers%20free%20of%20cost%20threat%20intelligence%20and%20it%20can%20be%20used%20to%20correlate%20with%20IP%20addresses%20and%20URLs%20in%20logs.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you%20are%20using%20any%20other%20Microsoft%20services%20like%20Intune%2C%20you%20can%20use%20it%20too.%20There%20are%20some%20advanced%20Microsoft%20services%20which%20offer%2090%20days%20free%20trial%20(for%20example%20AD%20premium%20license)%2C%20which%20can%20easily%20be%20activated%20for%20this%20proof%20of%20concept.%26nbsp%3B%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUsing%20most%20of%20the%20existing%20Microsoft%20cloud%20services%20will%20add%20to%20the%20benefits%2C%20while%20costs%20will%20be%20minimal.%20Azure%20sentinel%20offers%2090%20days%20free%20of%20cost%20data%20retention.%20When%2090%20days%20period%20is%20over%2C%20the%20data%20will%20be%20deleted.%20If%20you%20need%20to%20keep%20the%20data%20afterwards%2C%20you%20can%20use%20ADX%20to%20retain%20the%20data%20at%20cheaper%20rates.%20But%2090%20days%20should%20be%20enough%20for%20the%20proof%20of%20concept.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20a%20few%20log-sources%20(including%20email%2C%20intune%2C%20AAD%2C%20VMs%2C%20etc)%20are%20connected%2C%20you%20can%20focus%20only%20on%20security%20logs%20and%20do%20not%20import%20performance%20logs.%20This%20should%20already%20be%20defined%20in%20the%20project%20scope%2C%20but%20important%20to%20keep%20in%20mind%20to%20reduce%20costs.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20you%20can%20select%20and%20fine%20tune%20the%20rules%20that%20you%20need%20to%20get%20alerted%20on.%20Remember%20to%20automate%20a%20couple%20of%20response%20scenarios%2C%20like%20log%20on%20from%20a%20new%20location.%20It%20shows%20an%20excellent%20resource%20saving%20feature%2C%20that%20management%20will%20love.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20kept%20running%20proof%20of%20concept%20with%20all%20the%20above%20stated%20log%20sources%2C%20with%20a%20total%20cost%20of%20USD%20%2426.00.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETo%20keep%20this%20post%20readable%2C%20I%20have%20posted%20a%20few%20highlights.%20If%20there%20are%20any%20questions%2C%20or%20comments%2C%20please%20feel%20free%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

salkhan_0-1626976927034.png

 

In 2020, when everything was in lockdown, I spent quite a lot of time in getting to know how to create a proof of concept for Azure sentinel, and show its value to the management. I found quite a lot of resources on the internet, and used many hours studying Microsoft security blogs to find out best ways of doing it. I will share my experience here, so that it is a bit easier for our colleagues in the community to implement it. The idea with this proof of concept is to show the following in action:

 

1

Security Orchestration & Automated Response

2

Security Analytics

3

Threat Monitoring

4

Advanced cyber threat detection

6

Network insights

7

User Behavior Analysis (UBA)

8

Network Hierarchy 

9

Events and Alerts



To start, you must have Azure AD. Connecting onPremises AD via MMA will not work, because Sentinel will not have access to password-hashes and wont know if passwords were breached. Also, Azure AD will be important to test features like CASB etc.

 

Once you have AAD in place, you must make an architecture. It is to visualize how it will be implemented and how it will look like when it has gone live. It is possible that the POC will be extended to get into production on same tenant, so plan accordingly. For example, scoping around how many devices (onPrem & cloud) will participate in it. Which services to include in POC.  If you are using O365, it will be obvious to include this as well, to see malicious links and attachments and getting alerted on it. 

 

Since it is a POC, you can save some money on using Anomali as a TI feed. It offers free of cost threat intelligence and it can be used to correlate with IP addresses and URLs in logs. 

 

If you are using any other Microsoft services like Intune, you can use it too. There are some advanced Microsoft services which offer 90 days free trial (for example AD premium license), which can easily be activated for this proof of concept.   

 

Using most of the existing Microsoft cloud services will add to the benefits, while costs will be minimal. Azure sentinel offers 90 days free of cost data retention. When 90 days period is over, the data will be deleted. If you need to keep the data afterwards, you can use ADX to retain the data at cheaper rates. But 90 days should be enough for the proof of concept.

 

Once a few log-sources (including email, intune, AAD, VMs, etc) are connected, you can focus only on security logs and do not import performance logs. This should already be defined in the project scope, but important to keep in mind to reduce costs.

 

Now you can select and fine tune the rules that you need to get alerted on. Remember to automate a couple of response scenarios, like log on from a new location. It shows an excellent resource saving feature, that management will love.

 

I kept running proof of concept with all the above stated log sources, with a total cost of USD $26.00.

 

To keep this post readable, I have posted a few highlights. If there are any questions, or comments, please feel free :)

 

 

0 Replies