AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

investigation

  • Incident Response Foundations – Identity

    Incident Response Foundations – Identity

    In today’s post I talk about responding to a compromised identity in Microsoft Entra ID. There is a lot of advice floating around on what to do and how to respond; I’m bringing experiences and existing guidelines together to provide a solid foundational starting point for identity based incident response in this post.

    Read article

  • The case of the Duplicate Incidents in Microsoft Sentinel

    The case of the Duplicate Incidents in Microsoft Sentinel

    This is the story about the case of the duplicate incidents in Microsoft Sentinel. Join me as we explore different ways to create incidents, and understand how incidents are created so that we can identify potential duplication.

    Read article

  • Where to find Incident Investigation Artifacts in M365

    Where to find Incident Investigation Artifacts in M365

    A common challenge that security teams face is simply not knowing where all the artifacts can be found during an investigation. Microsoft Defender tools are capable of collecting a lot of data, and that can create questions during investigations of where is all this data and how do I find it quickly? Join me for…

    Read article