Next Generation SOC

%3CLINGO-SUB%20id%3D%22lingo-sub-1297374%22%20slang%3D%22en-US%22%3ENext%20Generation%20SOC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297374%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20want%20to%20create%20a%20document%20on%20Microsoft%20Azure%20Sentinel%20for%20SOC%20providers.%20Basically%20what%20I%20want%20to%20do%20on%20this%20document%20is%20as%20follow%3A%3C%2FP%3E%3CP%3E1.%20Introduction%20of%20Azure%20Sentinel%20(Architecture%2C%20How%20it%20works%2C%20what%20are%20the%20benefits%2C%20etc.)%3C%2FP%3E%3CP%3E2.%20How%20to%20enable%20Azure%20Sentinel%20(Azure%20subscription%2C%20Pricing%20and%20Pricing%20options%2C%20storage%2C%20analytics%20and%20other%20add-ins)%3C%2FP%3E%3CP%3E3.%20How%20to%20configure%20and%20connect%20different%20types%20of%20SIEM%2C%20Firewalls%2C%20End%20Points%2C%20Devices%20and%20Syslog%3C%2FP%3E%3CP%3E4.%20Integrate%203rd%20party%20services%20and%20customize%20Dashboard%20(Open%20Threat%20eXchange%2C%20PoC%2C%20etc.)%3C%2FP%3E%3CP%3E4.1%20Risk%20and%20Threat%20Assessment%3C%2FP%3E%3CP%3E4.2%20Integrate%20Vulnerability%20Assessment%3C%2FP%3E%3CP%3E4.3%20Integrate%20Penetration%20Testing%3C%2FP%3E%3CP%3E4.4%20Integrating%20Information%20System%20Audit%3C%2FP%3E%3CP%3E4.5%20Integrating%20SAM%20and%20IT%20Inventory%3C%2FP%3E%3CP%3E4.6%20Integrating%20Software%20Licensing%20(Microsoft%20Products)%20Status%20Verification%3C%2FP%3E%3CP%3E5.%20How%20to%20hunt%20cyber%20threats%20(Detect%2C%20Identify%2C%20and%20Respond)%3C%2FP%3E%3CP%3E5.1%20On-Premises%20Network%2C%20System%2C%20Devices%2C%20Services%2C%20Software%20Platforms%3C%2FP%3E%3CP%3E5.2%20Branch%20and%20Mobile%20Network%20and%20Devices%3C%2FP%3E%3CP%3E5.3%20Cloud%20Services%20(VPS%2C%20Microsoft%20Cloud%20Services%2C%20Other%20Cloud%20Services)%3C%2FP%3E%3CP%3E6.%20Threat%20response%3C%2FP%3E%3CP%3E7.%20Recording%20an%20incident%20and%20incident%20handling%20process%3C%2FP%3E%3CP%3E8.%20Creating%20an%20incident%20report(s)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBasically%20what%20I%20want%20to%20create%20is%20how%20to%20build%20a%20Security%20Operation%20Center%20with%20Azure%20Sentinel.%20Can%20you%20help%20me%20to%20create%20this%20document%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1297880%22%20slang%3D%22en-US%22%3ERe%3A%20Next%20Generation%20SOC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297880%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F184482%22%20target%3D%22_blank%22%3E%40Sachin%20Jung%20Karki%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EI%20would%20like%20to%20help%20on%20some%20topics!%20At%20the%20moment%20I%20am%20doing%20research%20on%20Azure%20Sentinel%20for%20my%20graduation%20project.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1297896%22%20slang%3D%22en-US%22%3ERe%3A%20Next%20Generation%20SOC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1297896%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F184482%22%20target%3D%22_blank%22%3E%40Sachin%20Jung%20Karki%3C%2FA%3E%26nbsp%3BYou%20should%20be%20able%20to%20capture%20most%20of%20that%20from%20here%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-resource-terminus-board-here%2Fba-p%2F1269252%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fazure-sentinel%2Fazure-sentinel-resource-terminus-board-here%2Fba-p%2F1269252%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1585399%22%20slang%3D%22en-US%22%3ERe%3A%20Next%20Generation%20SOC%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1585399%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F184482%22%20target%3D%22_blank%22%3E%40Sachin%20Jung%20Karki%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20you%20finish%20this%20Document%3F%20I%20wold%20Like%20to%20desing%20the%20Next%20Generation%20SOC%20in%20my%20company%20and%20I%20think%20your%20paper%20can%20be%20great%20in%20my%20research%20about%20this%20kind%20of%20services...%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks...%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Visitor

Hi,

 

I want to create a document on Microsoft Azure Sentinel for SOC providers. Basically what I want to do on this document is as follow:

1. Introduction of Azure Sentinel (Architecture, How it works, what are the benefits, etc.)

2. How to enable Azure Sentinel (Azure subscription, Pricing and Pricing options, storage, analytics and other add-ins)

3. How to configure and connect different types of SIEM, Firewalls, End Points, Devices and Syslog

4. Integrate 3rd party services and customize Dashboard (Open Threat eXchange, PoC, etc.)

4.1 Risk and Threat Assessment

4.2 Integrate Vulnerability Assessment

4.3 Integrate Penetration Testing

4.4 Integrating Information System Audit

4.5 Integrating SAM and IT Inventory

4.6 Integrating Software Licensing (Microsoft Products) Status Verification

5. How to hunt cyber threats (Detect, Identify, and Respond)

5.1 On-Premises Network, System, Devices, Services, Software Platforms

5.2 Branch and Mobile Network and Devices

5.3 Cloud Services (VPS, Microsoft Cloud Services, Other Cloud Services)

6. Threat response

7. Recording an incident and incident handling process

8. Creating an incident report(s)

 

Basically what I want to create is how to build a Security Operation Center with Azure Sentinel. Can you help me to create this document?

3 Replies
Highlighted

@Sachin Jung Karki 

I would like to help on some topics! At the moment I am doing research on Azure Sentinel for my graduation project. 

Highlighted
Highlighted

Hello @Sachin Jung Karki 

Have you finish this Document? I wold Like to desing the Next Generation SOC in my company and I think your paper can be great in my research about this kind of services...

 

thanks...