AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

Andrew

  • Onboard a Single Subscription with Microsoft Defender for Cloud

    Onboard a Single Subscription with Microsoft Defender for Cloud

    In today’s post we will look at a targeted way to harness the full potential of your Azure security by integrating Microsoft Defender for Cloud with Microsoft Sentinel. This powerful combination allows for advanced threat detection, seamless monitoring, and a unified view of your security posture. We want to select our Sentinel data connectors while…

    Read article

  • Azure Updates – Number 106 – January 11, 2025

    Azure Updates – Number 106 – January 11, 2025

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Detecting Common Email Inbox Rule Manipulation

    Detecting Common Email Inbox Rule Manipulation

    This article dives deep into the world of Kusto Query Language (KQL) to show you how to create custom analytics rules for detecting high-volume email sends, both internal and external, that might indicate potential security breaches. By leveraging these KQL queries, you can gain valuable insights into your email traffic, identify suspicious patterns, and take…

    Read article

  • Building Custom KQL Analytics Rules in Sentinel

    Building Custom KQL Analytics Rules in Sentinel

    In this post I explore using Sentinel to detect, and respond to threats using custom analytics rules using Kusto Query Language (KQL).  This allows you to tailor threat detection to your organization’s specific needs, ensuring that no threat goes unnoticed and tuning the detections to exclude low value and noisy results that clutter up the…

    Read article

  • Azure Updates – Number 105 – December 28, 2024

    Azure Updates – Number 105 – December 28, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Merry Christmas from AzureTracks

    Merry Christmas from AzureTracks

    As the holiday season is nearly upon us, I want to extend my warmest wishes to all our readers and supporters. This year has been filled with exciting advancements and innovations in the world of Azure…

    Read article

  • Azure Updates – Number 104 – December 14, 2024

    Azure Updates – Number 104 – December 14, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Post High Severity Incidents in Sentinel to a Teams Channel

    Post High Severity Incidents in Sentinel to a Teams Channel

    Today we explore incident communication using Teams.  One of the great things about Microsoft Sentinel is the ability to integrate with Microsoft Teams, allowing for seamless collaboration and communication during high-severity incident responses.  We will take a look at getting Teams working using a step-by-step guide to post summary information from incidents directly to a…

    Read article

  • Azure Updates – Number 103 – November 30, 2024

    Azure Updates – Number 103 – November 30, 2024

    A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.

    Read article

  • Integrating Threat Intelligence in Microsoft Sentinel

    Integrating Threat Intelligence in Microsoft Sentinel

    Join me in exploring the essential topic of integrating Microsoft threat intelligence within Microsoft Sentinel.  In an era where cyber threats are becoming increasingly sophisticated, having a robust strategy to ingest and leverage threat intelligence is crucial for any SOC team.  Understanding how to implement and utilize threat intelligence in Sentinel, you can significantly enhance…

    Read article