Microsoft Sentinel Blog

Options
4,824
yohasson on Oct 11 2022 08:50 AM
11.6K
Daniel_Davrayev on Oct 07 2022 07:37 AM
3,715
OferInbar on Sep 29 2022 11:03 AM
5,270
Maayan_Magenheim on Sep 22 2022 07:50 AM
5,805
vani_asawa on Sep 14 2022 08:28 AM
4,045
Ed_Gardner on Sep 12 2022 10:52 AM
6,072
MichalShechter on Sep 12 2022 04:21 AM
3,246
RijutaKapoor on Sep 06 2022 08:00 AM
3,677
Yael_Bergman on Aug 31 2022 05:46 AM
27.5K
Cyb3rWard0g on Aug 26 2022 08:57 AM
15.9K
Pete Bryan on Aug 17 2022 08:00 AM
4,703
Maayan_Magenheim on Aug 17 2022 12:34 AM
9,721
Yaniv Shasha on Aug 12 2022 11:06 AM
8,194
jurege on Aug 11 2022 09:10 AM
21.2K
AmritpalSingh on Aug 11 2022 09:05 AM
7,971
RijutaKapoor on Aug 02 2022 08:12 AM
4,808
YoavDaniely on Aug 02 2022 05:40 AM
12.1K
RijutaKapoor on Aug 02 2022 05:40 AM
3,862
Matt_Lowe on Aug 01 2022 04:21 PM
7,634
Idan_Bellayev on Jul 27 2022 11:57 PM
9,747
yohasson on Jul 14 2022 07:00 AM
20.9K
BenjiSec on Jul 13 2022 01:57 AM
3,721
ianhelle on Jul 11 2022 09:45 AM
4,877
AndrewLomakin on Jul 05 2022 12:00 PM
4,491
liortamir on Jul 04 2022 07:48 AM
13.9K
BenjiSec on Jul 01 2022 06:37 AM
10.5K
RijutaKapoor on Jun 29 2022 09:54 AM

Latest Comments

Hi, The tasks created in the Sentinel alert seems to be duplicating. The tasks defined in watchlist gets created twice in the Sentinel alert. Any ideas?
0 Likes
The most important part of this story was left out. How does the largest corporation in the world allow a sub domain to be created under their main domain? This implies they had access to DNS or Azure somehow allows any customer to create a sub domain under microsoft.com.
0 Likes
in Debugging Playbooks on Jun 12 2024 09:18 AM
Thanks for the runthrough! :) always usefull.I have to add, for me who is learning to create some basic playbooks - it would be superhelpfull if it was possible to chose some modules (like the "microsoft incident" and be able to trigger it from the builder (ie: press "run/play-button") just to see r...
0 Likes
@robeving wrote:Provision a cloud Azure resource with the same name and now visiting blog.somedomain.com will redirect to the attacker’s resource. Here they control the content. [...] This happened in 2021 when the domain was temporarily used to host a malware C2 service.I've seen plenty of phishing...
1 Likes
@Ciyaresh91 It is possible, but these streams are not chained. So instead of creating one with a 'Drop' destination you can just tell not to include that data set in your table, like this:So everything else will be forwarded but the data you want to filter out. { "streams": [ "Microsoft-Microsoft-Wi...
0 Likes