incidents
-

Automated Triage in Microsoft Sentinel
In today’s post we will look at some different ways to automate incident triage in Microsoft Sentinel. Organizations face an ever-increasing volume of security threats. Cyberattacks are becoming more sophisticated, and the sheer number of alerts can overwhelm even the most seasoned security teams. Automated triage in Microsoft Sentinel emerges as a crucial solution, empowering…
-

Responding to Threats with Microsoft Sentinel
Knowing where to start with Sentinel Incidents speeds remediation and supports making better decisions. Today, let’s take a look at monitoring and responding to cyber threats using Microsoft Sentinel.
-

The case of the Duplicate Incidents in Microsoft Sentinel
This is the story about the case of the duplicate incidents in Microsoft Sentinel. Join me as we explore different ways to create incidents, and understand how incidents are created so that we can identify potential duplication.
-

Sentinel & Log Analytics – How to Create Incidents to Test with – Part 2 – The Automation Rule
Today, I’d like to talk about using Microsoft Sentinel and address a common question that many teams have when they are starting to work with the Sentinel SIEM/SOAR solution….Part 2 of How do I create incidents to test with? Today we look at the automation rule and how we can use it trigger our Playbook…
-

Sentinel & Log Analytics – How to Create Incidents to Test with – Part 1
Today, I’d like to talk about using Microsoft Sentinel and address a common question that many teams have when they are starting to work with the Sentinel SIEM/SOAR solution….Part 1 of How do I create incidents to test with?
