New Blog Post | Using Automated Notebooks and Azure Sentinel to Improve Sec Ops

%3CLINGO-SUB%20id%3D%22lingo-sub-2592311%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20Using%20Automated%20Notebooks%20and%20Azure%20Sentinel%20to%20Improve%20Sec%20Ops%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2592311%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%22JasonCohen1892_0-1627406100944.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F298765i8FC1F28E9A2C9031%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%22JasonCohen1892_0-1627406100944.png%22%20alt%3D%22JasonCohen1892_0-1627406100944.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fsoftware-defined-monitoring-using-automated-notebooks-and-azure%2Fba-p%2F2587775%22%20target%3D%22_blank%22%3ESoftware%20Defined%20Monitoring%20-%20Using%20Automated%20Notebooks%20and%20Azure%20Sentinel%20to%20Improve%20Sec%20Ops%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EIncident%20triage%20is%20a%20core%20component%20of%20security%20monitoring%20operations%20and%20ensuring%20triage%20processes%20are%20efficient%20and%20effective%20is%20key%20to%20detecting%20security%20threats.%20Recent%20high%20profile%20security%20incidents%20have%20shown%20that%20detecting%20threats%20is%20insufficient%20unless%20effective%20triage%20and%20investigation%20of%20them%20is%20conducted.%20In%20this%20blog%20we%20detail%20how%20to%20deploy%20and%20use%20a%20solution%20that%20allows%20for%20the%20automatic%20execution%20of%20Jupyter%20Notebooks%20to%20provide%20enrichment%20to%20incidents%20within%20Azure%20Sentinel.%20%26nbsp%3BThis%20process%20allows%20security%20analysts%20to%20triage%20incidents%20more%20quickly%20and%20effectively%2C%20as%20well%20as%20ensuring%20a%20consistent%2C%20quality%20approach%20is%20taken.%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3EOriginal%20Post%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fsecurity-compliance-and-identity%2Fnew-blog-post-using-automated-notebooks-and-azure-sentinel-to%2Fm-p%2F2592309%23M6116%22%20target%3D%22_blank%22%3ENew%20Blog%20Post%20%7C%20Using%20Automated%20Notebooks%20and%20Azure%20Sentinel%20to%20Improve%20Sec%20Ops%20-%20Microsoft%20Tech%20Community%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

JasonCohen1892_0-1627406100944.png

Software Defined Monitoring - Using Automated Notebooks and Azure Sentinel to Improve Sec Ops - Micr...

Incident triage is a core component of security monitoring operations and ensuring triage processes are efficient and effective is key to detecting security threats. Recent high profile security incidents have shown that detecting threats is insufficient unless effective triage and investigation of them is conducted. In this blog we detail how to deploy and use a solution that allows for the automatic execution of Jupyter Notebooks to provide enrichment to incidents within Azure Sentinel.  This process allows security analysts to triage incidents more quickly and effectively, as well as ensuring a consistent, quality approach is taken.

 

Original Post: New Blog Post | Using Automated Notebooks and Azure Sentinel to Improve Sec Ops - Microsoft Tech Com...

0 Replies