AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

logs

  • Detecting Common Email Inbox Rule Manipulation

    Detecting Common Email Inbox Rule Manipulation

    This article dives deep into the world of Kusto Query Language (KQL) to show you how to create custom analytics rules for detecting high-volume email sends, both internal and external, that might indicate potential security breaches. By leveraging these KQL queries, you can gain valuable insights into your email traffic, identify suspicious patterns, and take…

    Read article

  • Where to find Incident Investigation Artifacts in M365

    Where to find Incident Investigation Artifacts in M365

    A common challenge that security teams face is simply not knowing where all the artifacts can be found during an investigation. Microsoft Defender tools are capable of collecting a lot of data, and that can create questions during investigations of where is all this data and how do I find it quickly? Join me for…

    Read article

  • Setting Custom retention for AzureActivity and Usage data tables

    Setting Custom retention for AzureActivity and Usage data tables

    Today we look at configuring a custom retention period for AzureActivity and Usage data tables in Log Analytics workspaces. This allows us to keep only the data we want for the exact retention period that is needed.

    Read article