Need to know if your organization is part of the most recent hack?
Image: https://www.pexels.com/photo/blur-chart-check-up-curve-415779/

Need to know if your organization is part of the most recent hack?

If so, then check out how to use SolarWinds Post-Compromise Hunting within Azure Sentinel

The Microsoft Threat Intelligence Center (MSTIC) has released several new hunting and detection queries for Azure Sentinel based on additional observations and research released by partners and the wider community. Azure Sentinel makes it easier to collect data from multiple data sources across different environments, both on-premises, and cloud, to connect that data more efficiently. The SolarWinds post-compromise hunting workbook is updated to include several new sections.

You can read in-depth details here: https://techcommunity.microsoft.com/t5/azure-sentinel/solarwinds-post-compromise-hunting-with-azure-sentinel/ba-p/1995095.

You can also access any of the "hunting workbooks" from the GitHub repository: https://github.com/Azure/Azure-Sentinel/tree/master/Workbooks.

If you want to get a more in-depth look at this attack, check out this great article provided by the Microsoft 365 Defender Research Team and the Microsoft Threat Intelligence Center (MSTIC)https://www.microsoft.com/security/blog/2020/12/18/analyzing-solorigate-the-compromised-dll-file-that-started-a-sophisticated-cyberattack-and-how-microsoft-defender-helps-protect.

Looking for some extra support and help with your Microsoft 365 Security? Then feel free to reach out :-)




要查看或添加评论,请登录

Liam Cleary的更多文章

  • CoPilot for Microsoft 365 Privacy

    CoPilot for Microsoft 365 Privacy

    Microsoft has taken a significant step forward by introducing CoPilot for Microsoft 365. This AI-powered technology…

  • Microsoft 365 CoPilot Security

    Microsoft 365 CoPilot Security

    Copilot for Microsoft 365 adheres to Microsoft's comprehensive standards in security, compliance, and privacy. Its…

  • Audit and Assessment Time?

    Audit and Assessment Time?

    So it is a new year, so what now? Back to work..

  • How many US-CERT security vulnerabilities recorded for 2020?

    How many US-CERT security vulnerabilities recorded for 2020?

    Before Christmas, I posted a poll on LinkedIn, asking if you knew how many Security Vulnerabilities US-CERT recorded…

  • Survey Update

    Survey Update

    A while back, I posted a survey asking about implementing Security controls. I thought it would be fun to review the…

  • Will 2021 be better?

    Will 2021 be better?

    Firstly, Happy New Year!! and welcome to 2021. Everyone is glad 2020 is done and behind us, and we are now all looking…

  • Is implementing Security Controls complicated, or is it a perceived complication?

    Is implementing Security Controls complicated, or is it a perceived complication?

    I have asked myself this question multiple times. Every time I perform a Microsoft 365 Security Assessment or Review…

  • What is Azure Sentinel?

    What is Azure Sentinel?

    Microsoft Azure Sentinel is a tool designed for security operation teams. It is a security information event management…

  • What is Microsoft Defender for Identity?

    What is Microsoft Defender for Identity?

    The Microsoft Defender for Identity tooling, formerly known as Azure ATP, is a cloud-based security solution. The…

  • Should you use CIS Benchmarks for Microsoft 365?

    Should you use CIS Benchmarks for Microsoft 365?

    My daily work involves reviewing Microsoft 365 Tenants and recommending specific Security Configurations and changes…

社区洞察

其他会员也浏览了