AzureTracks

Practical Azure and Microsoft 365 security walkthroughs

tuning

  • Building Custom KQL Analytics Rules in Sentinel

    Building Custom KQL Analytics Rules in Sentinel

    In this post I explore using Sentinel to detect, and respond to threats using custom analytics rules using Kusto Query Language (KQL).  This allows you to tailor threat detection to your organization’s specific needs, ensuring that no threat goes unnoticed and tuning the detections to exclude low value and noisy results that clutter up the…

    Read article

  • Advanced Customization of Microsoft Sentinel Analytics Rules

    Advanced Customization of Microsoft Sentinel Analytics Rules

    Join me as we walk through creating a custom Microsoft Sentinel Analytics Rule using KQL to identify suspicious login patterns based on failed attempts. We will explore the different components of creating these custom rules, what tuning looks like, and creating incidents from the rules.

    Read article