Build next-generation security operations with Azure Sentinel

Sharing is caring!

&NewLine;<p>Azure Sentinel detects data incidents from connected sources&comma; and then alerts you when action is necessary&period; You can use Azure Sentinel overviews&comma; dashboards&comma; and custom queries to gain insights into raw data and potentially malicious events&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>After Azure Sentinel retrieves the log data from the services&comma; it performs correlation across data sources&period; You can manage that data by using the Azure Monitor Log Analytics workspace&period; Built-in workbooks provide integrated data from your connected data sources&period; They let you examine the events that those services generate&period; The built-in workbooks include Azure AD&comma; Azure activity events&comma; and on-premises events&period; These on-premises events can include data from Windows events from servers or from Microsoft alerts&period;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<figure class&equals;"wp-block-image size-large"><img src&equals;"https&colon;&sol;&sol;www&period;thecloudxperts&period;co&period;uk&sol;wp-content&sol;uploads&sol;2020&sol;12&sol;image-1024x203&period;png" alt&equals;"" class&equals;"wp-image-709"&sol;><&sol;figure>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure Sentinel comes with a number of connectors<&sol;strong> for Microsoft and other solutions that are available out of the box&period; There are also <strong>built-in connectors to the broader security ecosystem for non-Microsoft solutions&period; <&sol;strong>You can also use Common Event Format &lpar;CEF&rpar;&comma; Syslog&comma; or a REST API to connect your data sources with Azure Sentinel&period;&nbsp&semi;There are connectors for&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p><strong>Azure Sentinel natively interoperates with these Azure and non-Azure services&colon;<&sol;strong><&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<div class&equals;"wp-block-wp-quads-adds">&NewLine;<&excl;-- WP QUADS v&period; 3&period;0&period;4 Shortcode Ad -->&NewLine;<div class&equals;"quads-location quads-ad" id&equals;"quads-ad" style&equals;"">&NewLine;<&sol;div>&NewLine;<&sol;div>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li>Azure Activity log<&sol;li><li>Azure AD &lpar;audit logs and sign-in logs&rpar;<&sol;li><li>Azure Security Center<&sol;li><li>Azure AD Identity Protection<&sol;li><li>Azure ATP<&sol;li><li>Amazon Web Services CloudTrail<&sol;li><li>Cloud App Security<&sol;li><li>Domain name servers<&sol;li><li>Office 365<&sol;li><li>Microsoft Defender ATP<&sol;li><li>Azure Web Application Firewall<&sol;li><li>Windows Defender Firewall<&sol;li><li>Windows security events<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>User and entity behavior analytics &lpar;UEBA&rpar; is natively built into Azure Sentinel targeting use-cases such as abuse of privileged identities&comma; compromised entities&comma; data exfiltration&comma; and insider threat detection&period; Azure Sentinel collects logs and alerts from all of its connected data sources&comma; then analyzes them and builds baseline behavioral profiles of your organization’s entities &lpar;users&comma; hosts&comma; IP addresses&comma; applications&comma; and more&rpar; across peer groups and time horizons&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Sentinel has built-in roles&comma; If the built-in Azure roles don&&num;8217&semi;t meet the specific needs of your organization&comma; you can create your own custom roles&period; Just like built-in roles&comma; you can assign custom roles to users&comma; groups&comma; and service principals for management-group&comma; subscription&comma; and resource-group scopes&period; You can also use Azure RBAC to create and assign <strong>roles in your SecOps team<&sol;strong>&period; Azure RBAC lets you grant appropriate access to Azure Sentinel&period; <&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<p>The following are the three dedicated&comma; built-in Azure Sentinel roles&colon;<&sol;p>&NewLine;&NewLine;&NewLine;&NewLine;<ul class&equals;"wp-block-list"><li><strong>Reader<&sol;strong>&colon; This role can review data&comma; incidents&comma; workbooks&comma; and other Azure Sentinel resources&period;<&sol;li><li><strong>Responder<&sol;strong>&colon; This role has all the permissions of the Reader role&period; Plus&comma; it can manage incidents by assigning or dismissing them&period;<&sol;li><li><strong>Contributor<&sol;strong>&colon; This role has all the permissions of the Reader and Responder roles&period; Also&comma; it can create and edit workbooks&comma; analytics rules&comma; and other Azure Sentinel resources&period; To deploy Azure Sentinel on your tenant&comma; you need Contributor permissions for the subscription where the Azure Sentinel workspace is deployed&period;<&sol;li><&sol;ul>&NewLine;&NewLine;&NewLine;&NewLine;<p>Azure Sentinel bills based on the volume of data that&&num;8217&semi;s ingested for analysis in Azure Sentinel and that&&num;8217&semi;s stored in the Log Analytics workspace&period; There are two ways to pay for the Azure Sentinel service&colon; Capacity Reservations and pay-as-you-go&period; Once Azure Sentinel is enabled on your Azure Monitor Log Analytics workspace&comma; every GB of data ingested into the workspace can be retained at no charge for the first 90 days&period; Retention beyond 90 days will be charged as per the standard&nbsp&semi;Azure Monitor Log Analytics&nbsp&semi;retention prices&period;<&sol;p>&NewLine;