New Blog Post | Microsoft Sentinel this Week - Issue #60

%3CLINGO-SUB%20id%3D%22lingo-sub-3334850%22%20slang%3D%22en-US%22%3ENew%20Blog%20Post%20%7C%20Microsoft%20Sentinel%20this%20Week%20-%20Issue%20%2360%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-3334850%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fwww.getrevue.co%2Fprofile%2FAzureSentinelToday%2Fissues%2Fmicrosoft-sentinel-this-week-issue-60-1157204%3FWT.mc_id%3Dmodinfra-64942-rotrent%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Sentinel%20this%20Week%20-%20Issue%20%2360%20%7C%20Revue%20(getrevue.co)%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CDIV%20class%3D%22revue-p%22%3EHappy%20Friday%20all!%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EI%E2%80%99m%20out%20and%20about%20this%20week%20at%20an%20in-person%20conference%20at%20the%20Mall%20of%20America%20in%20Bloomington%2C%20MN.%20It%E2%80%99s%20been%20a%20fantastic%20week%20talking%20about%20Defender%20for%20Cloud%20and%20Microsoft%20Sentinel%20to%20a%20group%20of%20folks%20that%20aren%E2%80%99t%20normally%20focused%20on%20security.%20There%E2%80%99s%20real%20interest%20in%20how%20Microsoft%20security%20offerings%20can%20bolster%20a%20career%20and%20can%20be%20integrated%20with%20current%20workloads%20without%20overwhelming.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EI%E2%80%99ll%20have%20more%20to%20share%20about%20this%20week%E2%80%99s%20experiences%20in%20next%20week%E2%80%99s%20newsletter.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%E2%80%A6%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EWe%20have%20a%20couple%20new%20surveys%20this%20week%20that%20I%20know%20is%20of%20interest%20to%20a%20large%20number%20of%20people.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EFor%20the%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Efirst%20one%3C%2FSTRONG%3E%2C%20I%20published%20a%20Playbook%20template%20for%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F4dg%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Esending%20a%20daily%20email%20of%20Sentinel%20Incidents%3C%2FA%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Erecently%20that%20a%20lot%20of%20you%20found%20useful.%20We%E2%80%99re%20trying%20to%20simplify%20this%20capability%20because%20it%20is%20so%20popular%20and%20valuable.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%0A%3CDIV%20class%3D%22revue-p%22%3EFrom%20the%20product%20team%3A%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EToday%2C%20emails%20can%20be%20sent%20automatically%20when%20incidents%20and%20alerts%20are%20created%20using%20playbooks.%20There%20are%20playbook%20templates%20ready-to-use%2C%20which%20leverage%20the%20Outlook%20Logic%20Apps%20connector.%26nbsp%3B%3C%2FEM%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EUsing%20playbooks%20for%20sending%20emails%20has%20great%20benefits%3A%20It%20allows%20full%20customization%20of%20the%20email%20message%20and%20advanced%20capabilities%20such%20as%20approvals.%20On%20the%20other%20hand%2C%20we%20hear%20customer%20challenges%20using%20this%20method.%3C%2FEM%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EWe%20are%20looking%20to%20allow%20customers%20to%20easily%20send%20emails%20by%20Automation%20Rules.%20We%20are%20seeking%20to%20learn%20about%20real-life%20email-scenarios%20to%20make%20sure%20we%20design%20the%20feature%20to%20fit%20your%20needs.%3C%2FEM%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EWe%20appreciate%20your%20feedback%20on%20our%20form.%20We%20are%20committed%20to%20reviewing%20every%20data%20point%20in%20detail%20and%20we%20will%20get%20back%20to%20you%20if%20we%20have%20questions.%26nbsp%3BPlease%20note%20that%20in%20some%20cases%2C%20platform%20limitations%20prevent%20us%20from%20developing%20an%20integration.%20Also%2C%20we%20may%20have%20limited%20resources%2C%20so%20not%20every%20request%20will%20be%20prioritized.%3C%2FEM%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EParticipate%20in%20the%20following%20survey%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F4dh%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ESend%20email%20from%20automation%20rules%3C%2FA%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%0A%3CDIV%20class%3D%22revue-p%22%3EThe%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3Esecond%20one%3C%2FSTRONG%3E%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3Eis%20focused%20on%20Microsoft%20Sentinel%20Fusion.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EMicrosoft%20Sentinel%20uses%20Fusion%2C%20a%20correlation%20engine%20based%20on%20scalable%20machine%20learning%20algorithms%2C%20to%20automatically%20detect%20multistage%20attacks%20by%20identifying%20combinations%20of%20anomalous%20behaviors%20and%20suspicious%20activities%20that%20are%20observed%20at%20various%20stages%20of%20the%20kill%20chain.%20On%20the%20basis%20of%20these%20discoveries%2C%20Microsoft%20Sentinel%20generates%20incidents%20that%20would%20otherwise%20be%20difficult%20to%20catch.%20These%20incidents%20comprise%20two%20or%20more%20alerts%20or%20activities.%20By%20design%2C%20these%20incidents%20are%20low-volume%2C%20high-fidelity%2C%20and%20high-severity.%3C%2FEM%3E%3C%2FDIV%3E%0A%3CUL%20class%3D%22revue-ul%22%3E%0A%3CLI%3E%3CEM%3EMore%20information%20about%20Fusion%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Faka.ms%2FSentinelFusion%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3E%3CEM%3Ehttps%3A%2F%2Faka.ms%2FSentinelFusion%3C%2FEM%3E%3C%2FA%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3EHow%20Fusion%20works%3A%26nbsp%3B%3C%2FEM%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fmicrosoft-sentinel-blog%2Fbehind-the-scenes-the-ml-approach-for-detecting-advanced%2Fba-p%2F3239236%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%3E%3CEM%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fmicrosoft-sentinel-blog%2Fbehind-the-scenes-the-ml-approach-for...%3C%2FEM%3E%3C%2FA%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%3CEM%3EAs%20we%20continue%20to%20expand%20the%20Fusion%20coverage%20to%20help%20you%20detect%20emerging%20and%20advanced%20attacks%2C%20and%20improve%20the%20experiences%20to%20help%20you%20speed%20up%20the%20investigation%2C%20we%E2%80%99d%20like%20to%20learn%20more%20from%20you.%26nbsp%3BIn%20this%20survey%2C%20we%E2%80%99d%20like%20to%20get%20your%20perspectives%20on%3A%3C%2FEM%3E%3C%2FDIV%3E%0A%3CUL%20class%3D%22revue-ul%22%3E%0A%3CLI%3E%3CEM%3EFusion%20detection%3C%2FEM%3E%3C%2FLI%3E%0A%3CLI%3E%3CEM%3ECustomization%2Fconfiguration%20options%20for%20Fusion%3C%2FEM%3E%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CDIV%20class%3D%22revue-p%22%3EYou%20can%20participate%20in%20this%20one%20here%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F4dn%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3EMicrosoft%20Sentinel%20Fusion%20Survey%3C%2FA%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%E2%80%A6%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3ELastly%2C%20I%20had%20awesome%20discussions%20with%20customers%20this%20week.%20Delivering%20Microsoft%20Sentinel%20sessions%20to%20a%20group%20of%20folks%20who%20have%20zero%20knowledge%20of%20the%20product%20was%20absolutely%20rewarding.%20I%20could%20see%20lightbulbs%20go%20off%20as%20I%20was%20describing%20the%20features%20and%20value.%20One%20individual%20-%20experienced%20with%20%E2%80%9Cother%E2%80%9D%20SIEMs%20who%20is%20now%20sold%20on%20Sentinel%20-%20invented%20a%20new%20tagline%20which%20has%20now%20been%20turned%20into%20a%20T-shirt.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EI%20present%2C%20the%20%E2%80%9C%3CSTRONG%3EMy%20SOC%20Doesn%E2%80%99t%20SUC%3C%2FSTRONG%3E%E2%80%9D%20T-shirt%3A%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Fcda.ms%2F4dB%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fcda.ms%2F4dB%3C%2FA%3E%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EAll%20proceeds%20go%20to%20St.%20Jude.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%E2%80%A6%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3EThat%E2%80%99s%20it%20for%20me%20for%20this%20week.%20It%E2%80%99s%20time%20to%20pack%20up%20and%20head%20home.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3ETalk%20soon.%3C%2FDIV%3E%0A%3CDIV%20class%3D%22revue-p%22%3E-%3CA%20href%3D%22https%3A%2F%2Ftwitter.com%2Frodtrent%3Futm_campaign%3DMicrosoft%2520Sentinel%2520this%2520Week%26amp%3Butm_medium%3Demail%26amp%3Butm_source%3DRevue%2520newsletter%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3ERod%3C%2FA%3E%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-3334850%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EContent%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESurveys%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

Microsoft Sentinel this Week - Issue #60 | Revue (getrevue.co)

 

Happy Friday all!
 
I’m out and about this week at an in-person conference at the Mall of America in Bloomington, MN. It’s been a fantastic week talking about Defender for Cloud and Microsoft Sentinel to a group of folks that aren’t normally focused on security. There’s real interest in how Microsoft security offerings can bolster a career and can be integrated with current workloads without overwhelming.
I’ll have more to share about this week’s experiences in next week’s newsletter.
We have a couple new surveys this week that I know is of interest to a large number of people.
For the first one, I published a Playbook template for sending a daily email of Sentinel Incidents recently that a lot of you found useful. We’re trying to simplify this capability because it is so popular and valuable.
 
From the product team:
Today, emails can be sent automatically when incidents and alerts are created using playbooks. There are playbook templates ready-to-use, which leverage the Outlook Logic Apps connector. 
Using playbooks for sending emails has great benefits: It allows full customization of the email message and advanced capabilities such as approvals. On the other hand, we hear customer challenges using this method.
We are looking to allow customers to easily send emails by Automation Rules. We are seeking to learn about real-life email-scenarios to make sure we design the feature to fit your needs.
We appreciate your feedback on our form. We are committed to reviewing every data point in detail and we will get back to you if we have questions. Please note that in some cases, platform limitations prevent us from developing an integration. Also, we may have limited resources, so not every request will be prioritized. 
 
Participate in the following survey: Send email from automation rules
 
The second one is focused on Microsoft Sentinel Fusion.
Microsoft Sentinel uses Fusion, a correlation engine based on scalable machine learning algorithms, to automatically detect multistage attacks by identifying combinations of anomalous behaviors and suspicious activities that are observed at various stages of the kill chain. On the basis of these discoveries, Microsoft Sentinel generates incidents that would otherwise be difficult to catch. These incidents comprise two or more alerts or activities. By design, these incidents are low-volume, high-fidelity, and high-severity.
As we continue to expand the Fusion coverage to help you detect emerging and advanced attacks, and improve the experiences to help you speed up the investigation, we’d like to learn more from you. In this survey, we’d like to get your perspectives on:
  • Fusion detection
  • Customization/configuration options for Fusion
You can participate in this one here: Microsoft Sentinel Fusion Survey
 
Lastly, I had awesome discussions with customers this week. Delivering Microsoft Sentinel sessions to a group of folks who have zero knowledge of the product was absolutely rewarding. I could see lightbulbs go off as I was describing the features and value. One individual - experienced with “other” SIEMs who is now sold on Sentinel - invented a new tagline which has now been turned into a T-shirt.
I present, the “My SOC Doesn’t SUC” T-shirt: https://cda.ms/4dB
All proceeds go to St. Jude.
 
That’s it for me for this week. It’s time to pack up and head home.
Talk soon.
0 Replies