playbook
-

Azure Updates – Number 119 – August 30th, 2025
Ah, the long weekend: that magical time when inboxes slow down, coffee refills multiply, and developers everywhere pretend they’re “totally not checking logs” from the beach. Whether you’re deep in a hammock-induced coma or just pretending your home office is a cabin in the woods, we’ve got your back with a roundup of updates, insights,…
-

Azure Updates – Number 117 – July 26, 2025
A summary update on Azure news that includes updates released from Microsoft Azure related to Azure, Architecture, Compute, Security Copilot and Sentinel topics. Save time digging around to find recent releases and changes.
-

Using Threat Intelligence in Microsoft Sentinel to Enhance Incidents
In this article, we explore real world automation and improvements to Sentinel Incidents. Leveraging Microsoft Sentinel Playbooks you can streamline your SOC security operations and respond to incidents faster and with the information your Analysts need to make decisions. A key component of this process is the integration of Threat Intelligence (TI) to enrich incident…
-

Enhancing Microsoft Sentinel: Part 3 – Ongoing Optimization and Staying Ahead of Threats
Join me for the final article in the min-series on Enhancing Microsoft Sentinel. Today, we review ongoing optimizations and how to stay ahead of emerging threats.
-

Enhancing Microsoft Sentinel: Part 2 – Advanced Customization and Threat Hunting
Join me for Part 2 of 3 where we review advanced customizations in Microsoft Sentinel. We review some of the steps to advance your threat hunting and better protect your environment.
-

Enhancing Microsoft Sentinel: Part 1 – Building a Stronger Foundation
Join me for Part 1 of 3 where we review Building a Stronger Foundation in Microsoft Sentinel. We review the steps to help review and build a stronger SIEM solution together.
-

Responding to Incidents with Microsoft Sentinel – Part 5 – Take Action with Automation
In today’s article we will build on previous automation experiences to further develop your Microsoft Sentinel automation powers! Today we will look at remediating incidents and alerts automatically. We will explore auto-remediation using both playbooks and Sentinel Automation rules.
-

Responding to Incidents with Microsoft Sentinel – Part 4 – Automate Research
Today we take a detailed look at building our own Sentinel Playbooks and gathering information on an Incident automatically. Join me as we build automation to update Alerts with detailed IP lookup information as comments. With basic research done automatically, we can save a lot of time!
