User Profile
Cyb3rWard0g
Iron Contributor
Joined 6 years ago
User Widgets
Recent Discussions
No content to show
Recent Blog Articles
Enabling AD FS Security Auditing π‘ and Shipping Event Logs to Microsoft Sentinel π‘οΈ
Active Directory Federation Service (AD FS) enables Federated Identity and Access Management by securely sharing digital identity and entitlements rights across security and enterprise boundaries. AD...37KViews3likes0CommentsAutomating the deployment of Sysmon for Linux π§ and Azure Sentinel in a lab environment π§ͺ
Today, we celebrate 25 years of Sysinternals, a set of utilities to analyze, troubleshoot and optimize Windows systems and applications. Also, as part of this special anniversary, we are releasing Sy...200KViews2likes4CommentsAzure Sentinel To-Go! A Linux π§ Lab with AUOMS Set Up to Learn About the OMI Vulnerability π₯
In this post, I will show you how to automatically deploy a research lab environment with Azure Sentinel, a few Linux virtual machines and the Microsoft Audit Collection Tool (AUOMS) set up to unders...22KViews2likes1CommentTesting the New Version of the Windows Security Events Connector with Azure Sentinel To-Go!
Last week, on Monday June 14th, 2021, a new version of the Windows Security Events data connector reached public preview. This is the first data connector created leveraging the new generally availab...36KViews6likes10CommentsAzure Sentinel To-Go (Part2): Integrating a Basic Windows Lab π§ͺ via ARM Templates π
Most of the time when we think about the basics of a detection research lab, it is an environment with Windows endpoints, audit policies configured, a log shipper, a server to centralize security eve...17KViews6likes2CommentsAzure Sentinel To-Go (Part1): A Lab w/ Prerecorded Data π & a Custom Logs PipeΒ via ARM Templates π
In this post, I show you how to use ARM templates to deploy an Azure Sentinel solution and ingest pre-recorded datasets via a python script, Azure Event Hubs and a Logstash pipeline.68KViews20likes25Comments