Working with Threat Intelligence in Azure Sentinel

Поділитися
Вставка
  • Опубліковано 2 лис 2024

КОМЕНТАРІ • 11

  • @prasantchettri133
    @prasantchettri133 Рік тому

    How does the TIP knows that it is connected to right registered app? Step 2 of MS article suggest - For the target product, specify Azure Sentinel. But I do not see that in app registration or Sentinel. Also, anomal website has now been shut and I cannot use it in the bicep anymore?

  • @nimaforoughi3008
    @nimaforoughi3008 3 роки тому +1

    Hi Jeroen, can you explain in a video how to automatically ingest the latest suspicious IP-Addresses or domains from Threat intelligence platforms or feeds into our Sentinel Analytics?

  • @deep001007
    @deep001007 Рік тому

    Best video on TI in Sentinel

  • @shanayshah4133
    @shanayshah4133 Рік тому

    How would you create a analytics query to search only new IOCs over a period of 90 days?

  • @amaurisrodriguez9914
    @amaurisrodriguez9914 3 роки тому

    Hi Jeroen, Have you found a way to import IOCs into Sentinel from a STIX file?...here in USA usually CISA provides downloadable copy of IOCs via a STIX file.

    • @AzureVlog
      @AzureVlog  3 роки тому +1

      Hi Amauris, I haven't done that yet. It does make sense to use STIX as it is becoming an industry standard. Let me figure out how STIX and Azure Sentinel can work together and let me get back to you.

    • @amaurisrodriguez9914
      @amaurisrodriguez9914 3 роки тому

      @@AzureVlog Thanks for the prompt response. Take your time, I am doing my research as well.

  • @antoniogomezmartin7455
    @antoniogomezmartin7455 2 роки тому

    There are Threat Intelligence services like Maltiverse that can be connected to Sentinel via TAXII connector. That works great

  • @nirmaal2255
    @nirmaal2255 7 місяців тому

    make video on MISP to Azure Sentinel Integration with diagram

    • @AzureVlog
      @AzureVlog  7 місяців тому +1

      That video might be on the backlog to create! Currently working on a integration of MISP with Sentinel :-)

    • @nirmaal2255
      @nirmaal2255 7 місяців тому

      @@AzureVlog Thank you