Microsoft Security Insights provides information, news, tips on the Microsoft Security Solutions including Microsoft Sentinel, Microsoft 365 Defender, and Azure. Edward Walton, Frank Grimberg, Rod Trent, Brodie Cassell.
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Show Notes/Links * Forsyte IT’s website: https://forsyteit.com/ * Shihan Wijeyeratne's LinkedIn profile: https://www.linkedin.com/in/shihan-wijeyeratne-55804b8b/ * Copilot for Security plugins: https://github.com/rod-trent/Copilot-for-Security/tree/main/Plugins * Copilot for Security Prompting workshop: https://github.com/rod-trent/Copilot-for-Security/tree/main/Prompts/Workshop
Watch the live replay
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Notes/Links: * Critical Start website: https://www.criticalstart.com/ * Randy Watkins LinkedIn profile: https://www.linkedin.com/in/randy-watkins-19368513/ * Rod Trent on MS National Office Hours: https://forms.office.com/pages/responsepage.aspx?id=v4j5cvGGr0GRqy180BHbR1Yrd34zLbtMspVmu5kxHXhUM0lLSEQ4TUYzTzRPQ0U1VFNOREJWTFNQVy4u
Watch the live replay:
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Notes/Links: * Bulletproof website - https://bulletproofsi.com/ * Bulletproof CfS Webinar (May 2nd, 2024 | 11:00 AM - 12:00 PM ET ) - https://content.bulletproofsi.com/webinar-copilot-security * Christopher Simm LinkedIn Profile: https://www.linkedin.com/in/csimm/ * Jon Stewart On The False Promises of AI:
Watch the live replay
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Notes/Links: * Quorum Cyber website: https://www.quorumcyber.com/ * Graham Hosking LinkedIn profile: https://www.linkedin.com/in/grahamhosking/
Watch the live replay
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Notes/Links: * Sentinel Watchlist Plugin template: https://github.com/rod-trent/Copilot-for-Security/blob/main/Plugins/KQL_Plugin_TrustedUsersWatchlist.yaml * Copilot Labs: https://copilot.cloud.microsoft/prompts * Tanium Prompts for Copilot for Security: https://github.com/rod-trent/Copilot-for-Security/blob/main/Prompts/Plugins/Tanium.md * New Tanium-Microsoft partnership provides endpoint data to Copilot for Security: https://siliconangle.com/2024/04/01/new-tanium-microsoft-partnership-provides-endpoint-data-copilot-security/ * Tanium Integrates with Microsoft Copilot for Security - Changing the Game for Cybersecurity Teams: https://www.tanium.com/blog/microsoft-copilot-for-security-integration/
Watch the Live Show Replay
It's Partner month on the MSI Show! This year we're focused solely on our Copilot for Security partners. Stop by to learn more about Copilot for Security and how Microsoft's partners are building solutions around this new AI service for security.
Notes/Links: * Learn Lives: https://learn.microsoft.com/en-us/shows/learn-live/microsoft-copilot-for-security/ * Midwest Management Summit MOA: https://mmsmoa.com/registration/mms-2024-at-moa * Microsoft Build: https://build.microsoft.com/ * Copilot for Security Community Group: https://www.linkedin.com/groups/14345161/ * Copilot for Security pricing table: https://azure.microsoft.com/pricing/details/microsoft-copilot-for-security/#pricing * Copilot for Security pricing calculator: https://azure.microsoft.com/pricing/calculator/ * Public Plugin List: https://learn.microsoft.com/en-us/security-copilot/plugin-overview * Grant partners access to Microsoft Copilot for Security: https://learn.microsoft.com/en-us/security-copilot/grant-access-external-users * Prompt Library: https://github.com/rod-trent/Copilot-for-Security/tree/main/Prompts
Watch the Live Replay
Our final 2024 episode for Women in Cybersecurity Month 2024!
Show Notes/Links: * Experts Live Kenya: https://www.expertslive.ke/ * Cybergirls: https://cybergirls.cybersafefoundation.org/ * ADPList: https://adplist.org/ * Microsoft Build: https://build.microsoft.com/
Watch the live replay
Hey! It's our 200th episode! What better way to celebrate than highlighting and celebrating Women in Cybersecurity Month 2024!
Show Notes/Links * LATAM Women in Cybersecurity - https://womcy.org/ * Donate - https://womcy.org/product/donate-to-womcy/ * Smartless podcast - https://www.smartless.com/
Developers, Developers, Developers…
Watch the Live Replay
Show Notes/Links: * Women in Cloud: https://womeninCloud.com * MDE common deployment mistakes: https://lnkd.in/dEtk7rCB * Connect ServiceNow to Defender for Cloud https://lnkd.in/eGKrPHQ9 * Create a ticket in Defender for Cloud https://lnkd.in/ePqUdNH5 * Create automatic tickets with governance rules https://lnkd.in/exAcrQeF * Protect your resources with Defender CSPM https://lnkd.in/eBaeyH9y * Register now for the Microsoft Windows Server Summit 2024: https://www.microsoft.com/windows-server/blog/2024/03/11/register-now-for-the-microsoft-windows-server-summit-2024/
Watch the live replay
Stop by as we highlight and celebrate Women in Cybersecurity Month 2024 and learn a bit about Star Trek!
Show Notes/Links: Watch the live replay…
Stop by as we highlight and celebrate Women in Cybersecurity Month 2024!
Show Notes/Links: Watch the live replay…
We take a short break in the Women in Cybersecurity month festivities to celebrate something else. You don't want to miss this!
Show Notes/Links: * Copilot for Security announcement: https://techcommunity.microsoft.com/t5/microsoft-security-copilot-blog/microsoft-copilot-for-security-general-availability-details/ba-p/4079970 * Prompt Library: https://github.com/rod-trent/Security-Copilot/tree/main/Prompts * Wallpaper: https://github.com/rod-trent/Security-Copilot/tree/main/Images/WindowsBackgrounds
Watch the live replay…
Stop by as we highlight and celebrate Women in Cybersecurity Month 2024!
"Don't have to be a turd to flush the toilet" - Kate Proctor
Show Notes/Links: Catch us live on the next show: The Microsoft Security Insights Show - Women in Cybersecurity Month - March 2024
Watch the live replay…
Stop by as we highlight and celebrate Women in Cybersecurity Month 2024!
Show Notes/Links: * Maria Young on LinkedIn: https://www.linkedin.com/in/maria-verardi/ * Microsoft Pegasus: https://www.microsoft.com/startups/pegasus and https://foundershub.startups.microsoft.com/signup * Copilot for Security: https://www.microsoft.com/security/business/ai-machine-learning/microsoft-security-copilot * Must Learn KQL: https://aka.ms/MustLearnKQL * The Definitive Guide to KQL from Microsoft Press: https://amzn.to/3TlGKil * Microsoft Cybersecurity for Beginners – a curriculum: https://github.com/microsoft/Security-101 * CompTIA Security + Exam Guide (SYO-601): https://amzn.to/3Pb3jDM
Watch the live replay…
Stop by as we highlight and celebrate Women in Cybersecurity Month 2024!
Show Notes/Links: * Intern Program: https://www.microsoft.com/en-IE/earlycareers/internsapprenticeships * What went Generally Available (GA) since February 2024?
+ Granular filtering of Conditional Access (CA) policy list – CA policies can now be filtered on actor, target resources, conditions, grant control and session control. The granular filtering experience can help admins quickly discover policies containing specific configurations.
+ Microsoft Entra ID Protection: Suspicious API traffic detection for users – This new detection is reported when abnormal Microsoft Graph traffic or directory enumeration is observed by a user. Suspicious API traffic might suggest that a user is compromised and conducting reconnaissance in their environment.
+ Microsoft Entra ID Protection: Risk remediation on the Azure mobile app – Adds remediation capabilities of Microsoft Entra ID Protection which were previously only available in the Microsoft Entra portal to the Azure mobile app. This capability includes comprehensive reporting, offering insights into risky behaviors such as compromised user accounts and suspicious sign-ins, and includes the Risky users and Risky sign-ins report.New public previews
+ Authentication Flows for Conditional Access – Supports the ability to configure CA policies to restrict or block the usage of certain authentication flows. The first iteration of this feature is limited to device code flow and authentication transfer.
+ Conditional Access: Require reauthentication every time - Lets you require users to interactively provide credentials again before accessing critical applications and taking sensitive actions on any resource protected by CA.
+ Workbook for impact analysis of risk-based Conditional Access policies - The Microsoft ID Protection risk analysis workbook helps admins understand what would happen if you create and enable Microsoft Entra ID Protection risk based CA policies in your environment. Workbooks are a collection of information, including queries, tables, and visualizations over a period of time to help you make sense of underlying data from an existing Log Analytics workspace.
Watch the live replay…
Stop by to listen to the crew chat with Dan Chemistruck about what XDR means in the industry today.
Show Notes/Links: * Microsoft Build - May 21-23, 2024 PT (Save the date) in Seattle - https://build.microsoft.com/ * Microsoft Ignite - November 18–22, 2024 (Save the date) in Chicago - https://ignite.microsoft.com/ * Introducing our new 7-lesson open-source course, “Security for Beginners”. Small lessons that should take around 30-60 mins to complete and will teach you fundamental cybersecurity concepts. https://aka.ms/sec101-beginners * Welcome to multi-tenant management in Microsoft Defender: https://mto.security.microsoft.com/ * Women in Cyber Month - March - https://securityinsights.substack.com/p/the-microsoft-security-insights-show * Coming…Copilot for Security Partner Month - April
Watch the live replay…
Josh is a Senior Technical Specialist at Microsoft focused on Security in Healthcare and Life Sciences. That's a mouthful, but not at all boring. Stop by live as this discussion could go off the rails.
Show Notes/Links: * HIMSS - https://hde.himss.org/global-conference * March is Women in Cybersecurity month. We have a stacked deck. 2 shows per week:
https://securityinsights.substack.com/p/the-microsoft-security-insights-show * And then Partner month in April - leading up to RSA in San Francisco - but focused on Copilot for Security. * Upcoming Learn Lives with the MSI crew: https://learn.microsoft.com/en-us/shows/learn-live/microsoft-copilot-for-security/
Watch the live replay…
Stop by and catch up with New Zealander Andre Camillo, Technology Specialist - Security and Compliance at Microsoft.
Show Notes/Links: * Ninja Training: https://aka.ms/NinjaTraining * Microsoft Defender for Cloud Apps webinars: https://learn.microsoft.com/en-us/defender-cloud-apps/webinars * Microsoft Defender for Cloud Apps e-books: https://learn.microsoft.com/en-us/defender-cloud-apps/e-books * Learn Path - Secure cloud apps using Microsoft Defender for Cloud Apps: https://learn.microsoft.com/en-us/training/paths/m365-cloud-app-security-fundamentals/ * Extended Detection and Response (XDR) | Microsoft Security: https://www.microsoft.com/en-us/security/business/solutions/extended-detection-response-xdr * Detect and respond to modern attacks with unified SIEM and XDR capabilities: https://mslearn.cloudguides.com/en-us/guides/Investigate%20security%20incidents%20in%20a%20hybrid%20environment%20with%20Azure%20Sentinel * William 'Bill' Post, inventor of Pop-Tarts, dies at 96: https://www.nbcnews.com/news/us-news/william-bill-post-inventor-pop-tarts-dies-96-rcna138784
Change the way we do security and the way security gets done.
Watch the live replay…
Edward and Andrea are in Seattle. Brodie is back from the ski slopes. And Rod - well -- Rod is here, too. No telling what this episode might bring.
Heads-up: Unfortunately, someone hit the big red button that stops the live stream, so this episode is quite a bit shorter than normal. However, we covered a LOT of ground in a short period of time.
Show Notes/Links: * Experts Live Denmark - https://events.justattend.com/events/conference-hub/584b32f5 * Microsoft AI Tour - https://envision.microsoft.com * Tip from Andrea: WDAT Conditional Access Policy - disable to allow Sentinel to connect to Defender XDR connector over API * Microsoft AI Tour deck: Securing Generative AI applications * Microsoft Entra Verified ID introduces Face Check in preview - https://www.microsoft.com/en-us/security/blog/2024/02/06/microsoft-entra-verified-id-introduces-face-check-in-preview/ * Secure your resources with Microsoft-managed Conditional Access policies - Microsoft Entra ID | Microsoft Learn - https://learn.microsoft.com/en-us/entra/identity/conditional-access/managed-policies
Watch the live replay…
Sarahzin Shane and Andrew McMurray join us this week to talk about all things Microsoft Purview.
Show Notes/Links: * What is Microsoft Purview: https://learn.microsoft.com/en-us/purview/purview * Just in Time for Purview: https://learn.microsoft.com/en-us/purview/endpoint-dlp-using-jit-protection * Purview, turn on OCR capabilities: https://learn.microsoft.com/en-us/purview/ocr-learn-about * Join the preview for the Cold Data Crawl: https://aka.ms/JoinCCP
Watch the live replay…
Come meet Purav Desai! Purav talks about M365 Forensics and is the author of the DecipheringUAL Github series. This show, we'll talk about Microsoft Security across Defender, Sentinel and Purview Compliance.
Show Notes/Links: * DecipheringUAL GitHub Repo: https://github.com/PuravsPoint/DecipheringUAL * Purav on LinkedIn: https://www.linkedin.com/in/purav-da346393/
Watch the live replay…
After a last second cancellation (guests will be rescheduled), join us as we gather together to talk about current events.
Show Notes/Links: * Microsoft Copilot Pro: https://support.microsoft.com/en-us/copilot-pro * Discover, monitor and protect the use of Generative AI apps: https://techcommunity.microsoft.com/t5/microsoft-defender-xdr-blog/discover-monitor-and-protect-the-use-of-generative-ai-apps/ba-p/3999228 * Microsoft AI Tour: https://envision.microsoft.com * Microsoft is named a Leader in the 2023 Gartner® Magic Quadrant™ for Endpoint Protection Platforms: https://www.microsoft.com/en-us/security/blog/2024/01/12/microsoft-is-named-a-leader-in-the-2023-gartner-magic-quadrant-for-endpoint-protection-platforms/
Watch the live replay…
This episode we invite Steven Hosking, Senior Product Manager at Microsoft, to discuss using Intune to deliver the secure network configuration to client devices.
Show Links/Notes: Watch the live replay…
After a week off during the 2023 holiday season, the crew is back to catch up and discuss what's on tap for 2024.
Show Notes/Links: * Must Learn AI Security: aka.ms/MustLearnAISecurity * Must Learn Quantum Security: aka.ms/MustLearnQuantumSecurity
Watch the live video replay…
In our annual holiday episode, we've invited a few guests back from the past year to help share in the holiday spirit.
Show Notes/Links: * KQL Mysteries: https://aka.ms/KQLMysteries * Conquest Cyber: https://conquestcyber.com * BlueVoyant: https://bluevoyant.com * Eric Mannon’s Defender for Cloud Quickstart (GitHub): github.com/msdirtbag
Catch the live stream replay…
Stop by and hear from Kijo Girardi on advanced threat hunting techniques using KQL.
Show Notes/Links: * SC-200 Microsoft Security Operations Analyst blueprint survey link:
https://microsoftlearning.co1.qualtrics.com/jfe/form/SV_d9Z64dYi2oVFjWS * Kijo's GitHub repo: https://github.com/LearningKijo * Must Learn KQL: https://aka.ms/MustLearnKQL * SANS Kusto Detective: https://detective.kusto.io/sans2023 * KQL Search: https://www.kqlsearch.com/ * KC7: https://kc7cyber.com/ * The CentOS Project: https://www.centos.org/
Watch the video replay…
Brian Hooper and Phoebe Rogers stop by to talk about "A Day in the life of a Defender Experts for XDR analyst."
Show Notes/Links: Microsoft Defender Experts: https://learn.microsoft.com/en-us/microsoft-365/security/defender/defender-experts-for-hunting?view=o365-worldwide
Watch the live replay…
We're here, we're clear, and we're talking security - and Edward’s trip to Morrocco.
Show Notes/Links: Must Learn AI Security book on Amazon: https://amzn.to/47BkSEj
The Definitive Guide to KQL from MS Press: https://amzn.to/49WHEIp
Connect Microsoft Sentinel to Microsoft Defender XDR (preview): https://learn.microsoft.com/en-us/microsoft-365/security/defender/microsoft-sentinel-onboard?view=o365-worldwide
New Blogs section on site - Substack: https://securityinsights.substack.com/t/blogs
Catch the live replay to see the demos and photos…
Brodie has something planned and he won't tell us what it is. Are you as curious as we are?
Show Notes/Links: * Microsoft Ignite Books of News: https://aka.ms/book-of-news * Andrea's blog post - Using KQL in a Playbook for Sentinel: https://securityinsights.substack.com/p/using-kql-in-a-playbook-for-sentinel * KQL Mysteries: https://aka.ms/KQLMysteries * The Definitive Guide to KQL: Using Kusto Query Language for Operations, Defending, and Threat Hunting KQL: https://amzn.to/3uzi3Vz * After the Blog Episode 6: Security Copilot at Microsoft Ignite 2023: https://rodtrent.substack.com/p/episode-6-security-copilot-at-microsoft#details
For the on-screen visuals, catch the live replay…
It's Microsoft Ignite week! Edward and Rod are onsite in Redmond and Seattle and ready to report and discuss all the goodness. Hey…and Brodie is back!
Show Notes/Links: * Watch the keynotes and get all the latest photos, videos and more from Microsoft Ignite * The online event for Microsoft Ignite * Microsoft Ignite Book of News
Watch the live replay…
Fan favorite, Senior Product Manager for Sentinel, and avid live audience member, Gary Bushey, returns to the show to talk about a new tool he's developed to provide a way to document a Microsoft Sentinel environment.
Oh…and with Brodie, Andrea, and Rod on the lam, who will host this week? Thank heavens for Beth Bischoff!
Show Notes/Links: * Gary’s blog: https://garybushey.com/ * Create a Word document that describes your Microsoft Sentinel environment * Book on programming Microsoft Sentinel
Catch the live replay…
This episode we all try to congregate back together before a busy few weeks of travel and holiday festivities.
Catch the live event replay...
Join us this episode as Nathalia Borges and Tina Romeo guest to help celebrate 20 years of Cybersecurity Awareness Month!
Show Notes/Links * Microsoft Cybersecurity Awareness Website: https://aka.ms/cybersecurity-awareness * Security Insider: https://www.microsoft.com/en-us/security/business/security-insider/ * Further reading on the some of the cybersecurity awareness initiatives Tina and Nathalia are driving at Microsoft: https://www.microsoft.com/en-us/security/blog/2023/10/02/celebrate-20-years-of-cybersecurity-awareness-month-with-microsoft-and-lets-secure-our-world-together/
Catch the live video replay Subscribe to our YouTube channel: https://www.youtube.com/@microsoftsecurityinsights
Stop by this episode to hear from Joel Platek, Compromise Recovery Cybersecurity Consultant. Joel is a cybersecurity professional focused on Identity and Data Security! He deals with incidents and recovery from customers that have been completely breached with stories you’ve read about in the news.
Joel’s YouTube channel, IT Candor: https://www.youtube.com/@it-candor
Watch the live video replay…
Security Global Black Belt Beth Bischoff joins us to talk about technical certifications. Beth tells us about her latest SANS certification, and we'll discuss the value of certs. Do you love them? Hate them? Need them for your job?
This episode is affectionately what we’ll forever refer to as the Cliffhanger episode.
Show Notes/Links * Sans Sec540: https://www.sans.org/cyber-security-courses/cloud-security-devsecops-automation/ * Security Copilot Docs: https://aka.ms/SecurityCopilotDocs * MMS Miami: https://mmsmoa.com/registration/2023-miami.html * Microsoft Ignite: https://ignite.microsoft.com/home * Beth before Microsoft at CDW:
Catch the live video replay…
This week is a not miss episode as we sit down with Sameh Younis, Senior Security Solutions Architect at Microsoft, to talk about how to use a bit of creativity to make Microsoft's security portfolio easy to understand using graphics.
Show Links/Notes: * Follow Sameh Younis on LinkedIn: https://www.linkedin.com/in/samehyounis/
This is a graphic-heavy episode. Catch the live replay…
🔒 Introducing the Minecraft Education Cybersecurity Pathway: From Learning to Defending 🔒
🚀 Embark on an exciting journey with us as we unveil the groundbreaking Minecraft Education Cybersecurity Pathway! 🚀
We're thrilled to announce a comprehensive cybersecurity program designed to guide individuals from all walks of life, from kindergarten to professional experts with the specific focus on Cyber Defender (18+ Years Old). A strategic tower defense game where you need to guard your berry farm against waves of relentless intruders. Engage in thrilling gameplay while deepening your understanding of cybersecurity concepts & mastering defense in-depth tactics.
🎮 What to Expect: Join us for an immersive experience as we explore the fascinating world of cybersecurity through interactive activities, video presentations, and engaging discussions. Uncover the art of game creation with a cybersecurity twist and gain hands-on experience by playing CyberDefender, where you'll apply your knowledge to protect digital landscapes.
🌐 Amplify the Message: Help us spread the word about this innovative program! Share this exciting news with your friends, family, colleagues, and social networks. Together, let's build a safer digital world by empowering individuals with the skills needed to combat cyber threats.
Show Notes/Links Minecraft Education: https://education.minecraft.net/
Cyber Defender releases Tuesday, October 3rd at this link: aka.ms/CyberDefender
This episode is a much watch experience. Catch the video replay…
This episode…
Our original guest had fallen ill (and has already been rescheduled for October 11th) and Brodie couldn’t find a restroom, so Edward, Andrea, and Rod spent the time hitting a wide range of topic hotspots including:
Notes/Links: * Microsoft 365 Defender demonstrates 100 percent protection coverage in the 2023 MITRE Engenuity ATT&CK Evaluations: Enterprise https://www.microsoft.com/en-us/security/blog/2023/09/20/microsoft-365-defender-demonstrates-100-percent-protection-coverage-in-the-2023-mitre-engenuity-attck-evaluations-enterprise/ * Using Kali Linux and Hydra for Attack Testing and Alert Generation https://rodtrent.substack.com/p/using-kali-linux-and-hydra-for-attack * A day in the life of a Defender Experts for XDR analyst https://techcommunity.microsoft.com/t5/microsoft-security-experts-blog/a-day-in-the-life-of-a-defender-experts-for-xdr-analyst/ba-p/3932140 * Jean Claude Van Damme in Kickboxer https://www.imdb.com/title/tt0097659/
The full experience replay…
Join us this episode as we welcome Rod's teammate and security extraordinaire, Sarah Young. Sarah recently spent time attending and participating at Blackhat and Defcon in Las Vegas. With Microsoft proposing a bigger presence there next year, hear about the value of attending.
Show Notes/Links: * Sarah Young LinkedIn: https://www.linkedin.com/in/sarahyo16/ * Bsides link: http://www.securitybsides.com/w/page/12194156/FrontPage * BlackHat: https://www.blackhat.com/ * Defcon: https://defcon.org/ * KQL Hat: https://must-learn-kql.creator-spring.com/listing/keep-on-kqlin-trucker-s-hat?product=2172&variation=106057&size=7042
Catch the live experience replay…
This episode we've invited Steve Lee, Product Manager - Customer Experience Engineering (CxE), Security at Microsoft - to chat about the Defender Experts service. This is a relatively new offering, but there's already been lots of excitement about it.
Show Notes/Links: * Steve Lee on LinkedIn: https://www.linkedin.com/in/steve-lee/ * Microsoft Defender Experts for XDR aka.ms\DefenderExpertsforXDR * Defender Experts for Hunting and Defender Experts for mXDR: https://www.microsoft.com/en-us/security/blog/2023/07/24/microsoft-defender-experts-for-xdr-helps-triage-investigate-and-respond-to-cyberthreats/ * Endpoint Attack Notifications: https://learn.microsoft.com/en-au/microsoft-365/security/defender-endpoint/endpoint-attack-notifications?view=o365-worldwide
Catch the full live experience below. (and subscribe to our channel!)
Stop by this episode to see and hear what Angelica Faber, Security Architect at Microsoft, has been working on. Angelica has produced some great content and guidance using Azure OpenAI with Microsoft Sentinel to provide better efficiency and deeper knowledge for Security Operations teams.
Show Notes/Links: * Angelica's blog: https://myfabersecurity.com/ * Angelica on LinkedIn: https://www.linkedin.com/in/angelica-faber/ * Rubrick: https://www.rubrik.com/ * Microsoft Envision The Tour: https://envision.microsoft.com/ * Microsoft Sentinel Triage AssistanT (STAT): https://github.com/briandelmsft/SentinelAutomationModules
This is a demo-heavy episode. Catch the full experience with the live show video replay…
Join us this week as we talk with Merill Fernando, Principal Product Manager about all things Microsoft Entra. There's been lots of news and announcement recently. In this episode, Merill will attempt to explain them all. And maybe we can get his take on the rebranding of AAD.
Show Notes/Links: * Entra.News - Your weekly dose of Microsoft Entra
Entra.News - Your weekly dose of Microsoft Entra Entra.News is a weekly newsletter of the latest Microsoft Entra related news, blog posts and videos from Microsoft, MVPs and infosec experts, curated by Merill Fernando. To feature your content on Entra.News tag with #entra or mail hey@entra.news By Merill Fernando * **Merill's blog:** https://merill.net
Catch the full experience with the live show video replay…
Join us this week as we dig into some of the burning Microsoft Security topics of the day and listen to hear how many times the term 'AI' is used.
Show Notes/Links: * Microsoft Entra Management and Security Tools: https://www.cloud-architekt.net/links/ * How to Setup User Risk Reports to Email in Microsoft Entra: https://ourcloudnetwork.com/how-to-setup-user-risk-reports-to-email-in-microsoft-entra/ * Microsoft Defender for Identity expands its coverage with new AD CS sensor! https://techcommunity.microsoft.com/t5/microsoft-365-defender-blog/microsoft-defender-for-identity-expands-its-coverage-with-new-ad/ba-p/3894215 * AZ Mask Plugin for Masking: https://chrome.google.com/webstore/detail/az-mask/amobeamdmdnloajcaiomgegpakjdiacm * I AM AI Merch: https://must-learn-kql.creator-spring.com/listing/get-i-am-ai * After the Blog Episode 2: https://rodtrent.substack.com/p/episode-2-azure-openai-content-filtering#details
Catch the full experience with the live show video replay…
It's been a long, long while since we've not had a guest on the show. But there's been lots and lots of news, thoughts, and discussions we've wanted to catch you all up on. This is the episode for all of that! Come join us as we dig deep into the burning horizons of security at Microsoft. We live for audience questions!
Show Notes and Links * Azure Stack Sentinel Support - November 13, 2019: https://techcommunity.microsoft.com/t5/azure-stack-blog/the-latest-security-enhancements-for-azure-stack-hub/ba-p/1006241 * Help Protect your Exchange Environment With Microsoft Sentinel - https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/help-protect-your-exchange-environment-with-microsoft-sentinel/ba-p/3872527 * Last time we had a show without a guest - February 6, 2023 - https://microsoftsecurityinsights.com/microsoft-security-insights-show-episode-138-just-us-probably * KQL Datasets for Azure OpenAI Bot: https://github.com/rod-trent/OpenAISecurity/tree/main/Datasets * Must Learn AI Security series: https://aka.ms/MustLearnAISecurity
Catch the full experience with the live show video replay…
Join us as we discuss what was important enough for Matt Soseman to leave 11 years at Microsoft to join The Partner Masters as their CTO & Co-Founder. If you're a Microsoft partner struggling to take advantage of all that partnership has to offer or don't believe that your org is getting the best value, this episode will awaken you to the benefits of a managed partnership.
Show Notes/Links: * Must Learn AI Security: https://aka.ms/MustLearnAISecurity * The Partner Masters website: https://thepartnermasters.com/ * Matt Soseman LinkedIn: https://www.linkedin.com/in/mattsoseman/
There were no demos this episode, but make sure to catch the full experience with the live show video replay…
Welcome back Chris Stelzer! Chris was on the show recently but is back to show us how he's architected ChatGPT into SOC operations with Microsoft Sentinel. Now that ChatGPT has been updated with many new features - including functions - don't miss this live! Lots of demos.
Show Notes/Links: * WSUS News: https://techcommunity.microsoft.com/t5/windows-it-pro-blog/importing-updates-into-wsus-is-changing/ba-p/3882937 * Microsoft Security Insights Show Episode 136 - Chris Stelzer, Senior TS at Microsoft: https://microsoftsecurityinsights.com/microsoft-security-insights-show-episode-136-chris-stelzer-senior-ts-at-microsoft * Episode 127: Microsoft Sentinel StaT with Mike Palitto and Andrea Fisher https://microsoftsecurityinsights.com/episode-127-microsoft-sentinel-stat-with-mike-palitto-and-andrea-fisher * Chris' Postman page: https://www.postman.com/scstelz
There’s LOTS of demos this episode, so make sure to catch the live show video replay…
**Live show video replay:** https://www.youtube.com/live/\_JHXnkKcfq4?feature=share
Want to watch the live show? You can always go back and watch this episode and others on our YouTube channel. Subscribe today!
What a unique and valuable time. We chat with Philippe Humeau, the CEO and co-founder of CrowdSec (crowdsec.net).
CrowdSec is an open-source & collaborative IPS able to analyze visitor behavior by parsing logs & provide an adapted response to all kinds of attacks. The game-changer is that the solution also enables users to protect each other. Each time an IP is blocked, all community members are informed so they can also block it. That way, they are generating a real-time crowdsourced CTI database.
We’ll be working together to create an integration with Microsoft Sentinel. Stay tuned for a future update.
Show Notes/Links: * CrowdSec * Basic Steps to Create Your Own Simple Copilot * Bing Chat Enterprise, your AI-powered chat for work, available in Microsoft Edge sidebar * Microsoft adds a 'Security Copilot' to its AI assistant line-up * Microsoft puts a price tag on its AI "copilots" for business
Want to watch the live show? You can always go back and watch this episode and others on our YouTube channel. Subscribe today!
Join us this episode as we cover the burning, audience requested topic of Cybersecurity Insurance. John O'Neill, Sr. CIO at MFG is an expert in this area and speaks about it regularly at conferences and in webinars.
Show links * Azure AD is Becoming Microsoft Entra ID - Microsoft Community Hub * Microsoft Entra Internet Access Preview * Microsoft Incident Response
Join the crew as we chat with Morten Waltorp Knudsen, the hardest working Microsoft MVP around about some solutions he's developed. In this episode, we get a couple extra wonderful surprise in Nick Kiest, the PM for Data Collection Rules (DCRs), and Niclas Madson, Microsoft Community Connection Program Blackbelt!
Show Links:
This week we talk with Peter Morin about the differences between IT and OT (the Hatfield’s and the McCoys) and securing critical scale operations for manufacturing, energy, and the like. What a most interesting discussion! And of course, there were first-ever announcements. There are always announcements.
Show links: PSA: Migrate from the Threat Intelligence Platform Connector to the Threat Intelligence Solution in Microsoft Sentinel
KQL Queries Behind the Microsoft Sentinel Overview Page
In this episode, we catch up with friend of the show, Rin Ure, about his new role at Microsoft and how he sees AI changing the way SOCs operate. Rin runs the Cyber Defense Operations Center One Cloud SOC Triage and Analysis team in the US. They are the team that handles the triage and analysis SOC requests for Microsoft, it’s services and for their Cloud and AI customers.
Show Links: Weekly OpenAI Newsletter: https://rodtrent.com/jtl
Azure OpenAI community on LinkedIn: https://rodtrent.com/65g
Microsoft Cyber Defense Operations Center (CDOC): https://rodtrent.com/594
Microsoft Security Copilot: https://rodtrent.com/6pt
Microsoft Corporate, External, and Legal Affairs (CELA): https://rodtrent.com/hdy
Pluralsight AI learning: https://rodtrent.com/3i5
SANS (SEC595: Applied Data Science and AI/Machine Learning for Cybersecurity Professionals): https://rodtrent.com/1i3
Microsoft Security Insights Discord Server: https://discord.gg/2ktJHTrSAt
Join us as we endeavor to tap into Yuri Diogenes' vast knowledge and expertise in navigating the landscape of building a career in cybersecurity.
Show links: * Microsoft Defender in the Field all episodes: https://aka.ms/MDFCInTheField * Yuri's Overcome podcast: http://overcomepodcast.us/ * Defender for Cloud labs: https://aka.ms/MDCLabs * Cloud Security Posture Management (CSPM): https://rodtrent.com/8o3 * Cloud Security Customer Connection Program (CCP): https://www.aka.ms/prseccom * Overview of Defender for DevOps: https://rodtrent.com/738 * About Microsoft Defender for APIs: https://rodtrent.com/7jh * What's new in Microsoft Defender for Cloud: https://rodtrent.com/gv2 * RSS feed for Defender for Cloud What's New: https://aka.ms/mdc/rss * Entra integration with Defender for Cloud: https://youtu.be/dasixjOOldk
Come join us as we talk with Ed Fisher about all things Microsoft security.
Show links: * The Microsoft Defender for Office 365 Recommended Configuration Analyzer (ORCA): https://github.com/cammurray/orca * DMARCy MARC and the funky bunch: https://securityinsights.substack.com/p/dmarcy-marc-and-the-funky-bunch
Show Guest: Tim McCreight MSc - National Director, Market Development and Strategic Advisory & 2023 President - ASIS International Topic: Innovators will always search for the next solution to the challenges they’re faced with. However, in a world full of buzzwords and flavors of the week, it’s important to understand what ESRM truly is and how it supports the work of security professionals. From Tim’s perspective, ESRM is a philosophy and framework that will “change the way we operate as security professionals.”
-Show Links- Caffeinated Risk podcast (buzzsprout.com)
https://caffeinatedrisk.buzzsprout.com/
Essentials of Enterprise Security Risk Management (ESRM) Certificate Course (asisonline.org)
https://www.asisonline.org/professional-development/essentials-of-enterprise-security-risk-management-esrm-certificate-course/
Stop by as we talk with Ricky Simpson and Federico Charosky from Quorum Cyber - Managed & Professional Cyber Security Services.
Show notes and links:
Dale O'Grady joins us from Vectra AI, joins Rod and Brodie to demonstrate the integrations of Vectra’s capabilities within Microsoft Sentinel.
Show notes and links:
Vectra® uses artificial intelligence to automate real-time cyber attack detection and response – from network users and IoT devices to data centers and the cloud. All internal traffic is continuously monitored to detect hidden attacks in progress. Detected threats are instantly correlated with host devices that are under attack and unique context shows where attackers are and what they are doing. Threats that pose the biggest risk to an organization are automatically scored and prioritized based on their severity and certainty, which, enables security operations teams to quickly focus their time and resources on preventing and mitigating loss.
https://www.vectra.ai/ Microsoft Azure Marketplace - Vectra AI https://azuremarketplace.microsoft.com/en-us/marketplace/apps/vectraaiinc.ai_vectra_detect_mss?
Vectra AI Detect connector for Microsoft Sentinel https://learn.microsoft.com/en-us/azure/sentinel/data-connectors/vectra-ai-detect
Join Mia Reyes, Olivia Armstrong, and Richard Diver for a fun and informative discussion about the Foundational Security Team, and insights into how Microsoft’s marketing team works with both the product group and our customers to inform you on the latest and greatest in cybersecurity, and more.
Show notes and links:
See how Microsoft customers can take advantage of out-of-the-box security and be secure from the start. https://aka.ms/BuiltInSecurity
Read the Azure Built-In Security Series to discover how Microsoft evolves our defense in depth approach to security to keep customers safe in the cloud. https://aka.ms/AzureBuiltinSecurity
Excellence is as Excellence Does
It’s MISA Month and this is our last episode of an amazing series. Just off winning MISA award “MSSP Partner of the Year,” Mona ‘Excellence’ Ghadiri with BlueVoyant joins us for an amazing discussion.
Show notes and links:
https://www.bluevoyant.com/
Join us as we prepare for RSA conference with a chat with MISA partner Senserva. Mark Shavlik, long time Microsoft security vet who has created a number of widely used security products will talk about the state of Azure Security from a product creator’s perspective. We'll also ask to find out why Senserva has opted to for the Midwest Management Summit instead of RSA this year.
Show links:
https://www.senserva.com/ * Midwest Management Summit at the Mall of America (MMSMOA) https://mmsmoa.com/registration/mms-2023-at-moa.html * Arthur Hailey's Hotel: https://www.imdb.com/title/tt0085032/ * Bing Chat’s info on Cyber insurance: https://sl.bing.net/ikGoWneQftc
Join us as we prepare for RSA conference with a chat with MISA partner Ontinue. Drew Perry joins the MSI Show crew to catch us up on Ontinue’s super-cool Microsoft Teams-based SIEM solution how to catch demos and Sentinel cost discussions at RSA.
Show links: * The Ontinue website:
https://www.ontinue.com/ * Request a demo: https://get.ontinue.com/demo-request/
Join us as we prepare for RSA conference with a chat with MISA partner Difenda. Juliana Zaremba from Difenda joins the MSI Show crew to catch us up on Difenda’s valued and valuable offerings and how to catch them at RSA.
Meet Difenda at RSA! Register for a meeting and be entered to win a fantastic LEGO Technic Land Rover Defender!
Register here: https://insights.difenda.com/meet-difenda-at-rsa-2023
Show links:
Welcome to Women in Cybersecurity month!
Join us for our last episode in the Women in Cybersecurity month series for 2023 as we chat with Elizabeth Stephens, Director Data Center Cyber Risk Intelligence.
In this episode, hear Elizabeth talk about her passion in Cybersecurity that is driven by the needful things.
Show links:
We hope these discussions with leaders in the Cybersecurity industry will help drive your excitement in sharing the message.
Welcome to Women in Cybersecurity month!
In our fourth episode in the series for Women in Cybersecurity month Future and Lara stop by to chat about Microsoft Defender for Cloud (a CNAPP Solution). If you listen in, you may also learn about leg presses.
Show links:
To learn more about critical upcoming CNAPP innovations in Microsoft Defender for Cloud, register to join me at Microsoft Secure, our free, virtual Microsoft Security event on March 28, 2023: https://secure.microsoft.com
And don’t forget to stay tuned the entire month for more!
Our remaining Women in Cybersecurity month 2023 schedule:
We hope you’ll join us live or listen to the replays. But more than that, we hope these discussions with leaders in the Cybersecurity industry will help drive your excitement in sharing the message.
Welcome to Women in Cybersecurity month!
In our third episode in the series for Women in Cybersecurity month, CVP at Microsoft SCI, Ann Johnson, joins us to chat about filling the skills gap in cybersecurity and how Artificial Intelligence (AI) is positioned to change this industry.
Show links:
And don’t forget to stay tuned the entire month for more!
Our remaining Women in Cybersecurity month 2023 schedule:
We hope you’ll join us live or listen to the replays. But more than that, we hope these discussions with leaders in the Cybersecurity industry will help drive your excitement in sharing the message.
It's Women in Cybersecurity month 2023!
To kick-off this event, we visit with Maria Thomson, Microsoft Intelligent Security Association lead. Hear how Maria went from dance instructor to the lead of Microsoft's partner association.
And don’t forget to stay tuned the entire month for more!
Our remaining Women in Cybersecurity month 2023 schedule:
We hope you’ll join us live or listen to the replays. But more than that, we hope these discussions with leaders in the Cybersecurity industry will help drive your excitement in sharing the message.
It's Women in Cybersecurity month 2023!
To kick-off this event, we visit with Maria Thomson, Microsoft Intelligent Security Association lead. Hear how Maria went from dance instructor to the lead of Microsoft's partner association.
And don’t forget to stay tuned the entire month for more!
Our remaining Women in Cybersecurity month 2023 schedule:
We hope you’ll join us live or listen to the replays. But more than that, we hope these discussions with leaders in the Cybersecurity industry will help drive your excitement in sharing the message.
Jake Mowrer talks about Security in the Microsoft partner space. He also gives us his thoughts around writing SC exam books.
Links from the show:
Microsoft Security Insights Show Episode 140 - Tony Sims, Threat Intelligence Specialist
Listen in as Tony talks about his role at Microsoft in Cyber Threat Intelligence.
We also discuss:
Links from the show:
Join us as we talk with Josh Bregman, his role at Microsoft, his superpowers, and the things he's working on.
Microsoft Security Insights Show Episode 138 - Just us, probably
Our regularly scheduled guest, Ann Johnson, was sick for today’s show. We wish Ann the best and hope she recovers quickly.
Ann will be joining us in March during Women in Cybersecurity month.
Show links:
Microsoft Security Insights Show Episode 137 - The One Where Craig Fretwell's Grandma is an MVP
Show links:
The Microsoft Security Insights Show Substack: https://securityinsights.substack.com/
Welcome to our January 2023 Microsoft Reactor edition episode where we talk with Chris Stelzer, Senior Technical Specialist at Microsoft.
Listen in as Chris digs into how to use service principles for automation in Microsoft Sentinel. Lots of great knowledge to glean.
Show links:
What's up with Nathan? Nathan has been working on some awesome security stuff since we last checked in. Join us as we catch-up with all the Nathan awesomeness.
Show Links…
Nathan’s stuff:
Book recommendation:
Tribe of Hackers book: https://amzn.to/3ZvrtNa
Welcome to 2023! In this episode, catch up with your hosts, hear Ed ramble on (as usual) about his year-end trip, and listen in on musings about Microsoft security in the new year.
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug All profits go to charity https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at: http://microsoftsecurityinsights.com/
The last show of 2022, we bring in several of our favorite guests from the past year in our "Spirits of Security Shows Past" episode.
Here from folks like Michelle Jackman, Vishal Amin, Nathan Swift, and Ingrid Rodriguez as we cover a wide range of security topics from the past year and the new year ahead.
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug All profits go to charity https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at: http://microsoftsecurityinsights.com/
This week we've put together a panel of participants from the Microsoft Security Private Preview program. Let by the wonderfully famous Kristina Quick, the Microsoft Security Private Preview program is a highly successful test bed for products, features, and feedback. Most of what you can experience in Microsoft security platform products today have come through this unique and valuable program.
Find out how it works and how easy it is to get involved.
Join the Microsoft Security Private Preview program: https://aka.ms/SecurityPRP
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug All profits go to charity https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at: http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug All profits go to charity https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at: http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Microsoft Sentinel StaT
Link: aka.ms/MSTAT
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
BlueVoyant
https://www.bluevoyant.com/
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Paul Schnackenburg
Blog: https://tellitasitis.com.au/
Twitter: @paulschnack
E-Book - Microsoft 365 Security Checklist:
https://rodtrent.com/cz7
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Tanium
https://rodtrent.com/4k4
Cybersecurity Awareness Month
https://www.microsoft.com/en-us/security/business/cybersecurity-awareness?rtc=1
Microsoft Purview Insider Risk Management Solution
https://rodtrent.com/wzl
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Microsoft Private Security Community
http://aka.ms/prseccom
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Show Links:
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
podcast website:
http://microsoftsecurityinsights.com/
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Website
http://microsoftsecurityinsights.com/
Show Links:
http://microsoftsecurityinsights.com/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Gary's blog:
https://www.garybusheyllc.com/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Nicolas website: https://www.inthenicoftime.us/ and https://p1.dso.mil
Leverage new and existing features to optimize cost in Microsoft Sentinel
https://www.youtube.com/watch?v=0cIYB92Qb60&feature=youtu.be
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Microsoft Learn Cloud Games
https://docs.microsoft.com/en-us/learn/certifications/cloud-games
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Everything You Ever Wanted to Know About Using the New Azure Monitor Agent (AMA) with Microsoft Sentinel
YouTube: https://youtu.be/Tvs-5JbGK-c
Deck: https://1drv.ms/b/s!AnEPjr8tHcNmkVMcK42jaoKocz9Z?e=Itj8px
Microsoft Defender for Cloud Price Estimation Dashboard
https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/microsoft-defender-for-cloud-price-estimation-dashboard/ba-p/3247622
Security posture management and server protection for AWS and GCP are now generally available
https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/security-posture-management-and-server-protection-for-aws-and/ba-p/3271388
Update Microsoft Sentinel VIP Users Watchlist from Azure AD group using playbooks
https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/update-microsoft-sentinel-vip-users-watchlist-from-azure-ad/ba-p/3100184
Common scenarios using Watchlists (with query examples)!
https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/common-scenarios-using-watchlists-with-query-examples/ba-p/3259393
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
365 Days of KQL Scavenger Hunt
https://forms.office.com/pages/responsepage.aspx?id=2UMuhG9dY0uckAjsv2sRQM1VCVAgs1lCl3wwGmNzlMtUMjA4Tk9CTzNOTzlQMFBKVTFLUlpBOVZBMS4u
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: https://aka.ms/DwaynesBooks
Microsoft Identity and Access Administrator
Exam Guide: Implement IAM solutions with Azure AD, build an identity governance strategy, and pass the SC-300 exam
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
https://github.com/redcanaryco/atomic-red-team
https://microsoftsecurityinsights.com/053-risk-management-with-ingrid-rodriguez
1:04:35 - "innovative risk officer"
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Microsoft Security Operations Analyst Exam Ref SC-200 Certification Guide: Learn how to mitigate threats using the Microsoft Security Stack and achieve the SC-200 certification
by Trevor Stuart (Author), Joe Anich (Author)
Microsoft 365 Security & Compliance User Group
https://www.meetup.com/m365sandcug
Show Links: Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Microsoft Security Operations Analyst Exam Ref SC-200 Certification Guide: Learn how to mitigate threats using the Microsoft Security Stack and achieve the SC-200 certification
by Trevor Stuart (Author), Joe Anich (Author)
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Must Learn KQL - MSI Podcast Coffee Mug
All profits go to charity
https://must-learn-kql.creator-spring.com/listing/microsoft-security-insights-po
Show Links:
Red Canary: https://redcanary.com/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Overview of the SOC Process Framework
https://www.youtube.com/watch?v=hBHo22Fl3lc
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
The Must Learn KQL series home page: https://aka.ms/MustLearnKQL
Book version: https://cda.ms/3mT
Series merch store (all proceeds to St. Jude's): https://cda.ms/3vg
Hands-On KQL Practice with the new Microsoft Sentinel Workbook: https://cda.ms/3Cw
Microsoft Sentinel Docs Training and Skilling Resources: https://cda.ms/3Cx
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Angela Harris
https://angelavharris.com/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Hosted by Edward Walton, Frank Grimberg, Rod Trent, Brodie Cassell
Sreedhar Ande
Github: https://github.com/andedevsecops
https://aka.ms/asnew --> up to date info on the improvements we make in the product
NRT Rules considerations Detect threats quickly with near-real-time (NRT) analytics rules in Microsoft Sentinel | Microsoft Docs
https://docs.microsoft.com/en-us/azure/sentinel/near-real-time-rules#considerations
Analytical Rules Health
a. Playbook : Azure-Sentinel/Playbooks/Send-AnalyticalRulesHealthNotifications at master · Azure/Azure-Sentinel (github.com)
https://github.com/Azure/Azure-Sentinel/tree/master/Playbooks/Send-AnalyticalRulesHealthNotifications
b. Blog: Monitoring Microsoft Sentinel Analytical Rules – Push Health Notifications - Microsoft Tech Community
https://techcommunity.microsoft.com/t5/microsoft-sentinel-blog/monitoring-microsoft-sentinel-analytical-rules-push-health/ba-p/2793694
Guide to build Microsoft Sentinel Solutions
a. Webinar: Create Your Own Microsoft Sentinel Solutions
https://youtu.be/oYTgaTh_NOU
b. Azure-Sentinel/Solutions at master · Azure/Azure-Sentinel (github.com)
https://github.com/Azure/Azure-Sentinel/tree/master/Solutions#guide-to-building-microsoft-sentinel-solutions
Microsoft Sentinel Repositories demo
a. Managing security content as code - Microsoft Sentinel in the Field #1 - YouTube
https://www.youtube.com/watch?v=vqLqJhaFNBk
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Nathan Swift Info:
https://www.youtube.com/channel/UCwFmix7vM-Awcgxku8pHxQg
https://linktr.ee/swiftsolves
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
https://aka.ms/sentinelhybrid
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
https://aka.ms/appgovernancedocs
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Simple Row-Based Access Workbook: Lab Walk-Through with Azure Sentinel and Azure Data Explorer (ADX)
https://techcommunity.microsoft.com/t5/azure-sentinel/simple-row-based-access-workbook-lab-walk-through-with-azure/ba-p/2804446
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Azure Sentinel Information Model
https://docs.microsoft.com/en-us/azure/sentinel/normalization
https://www.youtube.com/watch?v=WoGD-JeC7ng
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Rod Trent
Azure Cloud & AI Domain Blog
https://azurecloudai.blog/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Thomas Maurer
https://www.thomasmaurer.ch/
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Guest Hosts:
Rod Trent
Brodie Cassell
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Guest Hosts:
Rod Trent
Nathan Swift
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-soc-process-framework-workbook/ba-p/2339315
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Guests:
TJ Banasik
Lili Davoudian
Brodie Cassell
Announcing the Azure Sentinel: Zero Trust (TIC3.0) Workbook
https://techcommunity.microsoft.com/t5/public-sector-blog/announcing-the-azure-sentinel-zero-trust-tic3-0-workbook/ba-p/2313761
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Azure Sentinel webinar: Using Azure Data Explorer as Your Long Term Retention Platform of AS Logs
https://www.youtube.com/watch?v=UO8zeTxgeVw
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Twitch: https://www.twitch.tv/microsoftsecurityinsights
Discord: https://discord.gg/thCAR7RMUe
Show Links:
Ninad Doshi
Azure Security Lead – US Financial Services Customer Success Unit
Ninad is a Security Architect on Microsoft’s Customer Success team partnering with customers to secure their operations in Azure as well as use Azure services to secure their hybrid operations. Some of work includes whitepapers like he co-authored on Incident Management Implementation Guidance: Azure and Office 365
https://www.linkedin.com/in/ninaddoshi/
Show Notes:
Twitch
https://www.twitch.tv/microsoftsecurityinsights
Guests:
Chris Boehm
Senior Program Manager – Customer Experience Engineering Team
Microsoft
Jing Nghik
Security and Compliance Technology Specialist
Microsoft
https://www.youtube.com/c/TeachJing/featured
Show Links:
Matt Lowe
Program Manager 2, Azure Sentinel
Tech enthusiast from Chicago, now living in Boston. Former college hire Support Engineer for Azure Security in Dallas. Big fan of food, video games, hockey, and working out. Bad at self summaries.
https://www.linkedin.com/in/matthew-lowe-13b61990
Show Links:
Azure Sentinel EUBA
Cristhofer Romeo Munoz
Program Manager II , Cloud Security Engineering Team at Microsoft
Short Bio: Cristhofer Muñoz is a Program Manager II part of the Cloud and Artificial Intelligence division focusing on cloud security, explicitly Azure Sentinel. Cristhofer is passionate about directly working with organizations to strengthen their resilience and helping organizations reduce information security risks by embracing cybersecurity. IT industry certifications that Cristhofer currently holds are CISSP, E|CEH, E|CHFI, CompTIA CySa+, Security+. When he is not working with organizations, you can catch him surfing the web at a local café in NYC!
LinkedIn: linkedin.com/in/crisrmunoz
Show notes can be found on the podcast website at:
http://microsoftsecurityinsights.com/
Twitch
https://www.twitch.tv/microsoftsecurityinsights
Matt Egen is a Global Black Belt and Principal Technical Specialist in Microsoft’s Security Solutions Area. He has a large number of years of experience in cybersecurity, development, and infrastructure operations. He has a cat, Sweetpea, who is a Pigeon Threat Analyst.
Follow Matt on twitter: https://twitter.com/FlyingBlueMonki
Show Links:
Strengthen your hybrid identity with these new Azure AD Connect releases
Announcing the Cybersecurity Maturity Model Certification (CMMC) Workbook Public Preview
Extending threat and vulnerability management to more devices
Windows Virtual Desktop support is now generally available
Show Links:
Rod Trent
Cybersecurity Customer Engineer and Global Azure Sentinel SME at Microsoft
LinkedIn Profile
Show Links:
Twitch
YouTube Playlist
Hunt for Azure Active Directory sign-in events
Microsoft Defender for Endpoint: Automation defaults are changing
Microsoft Teams DLP Playbook!!!
Microsoft Defender for Identity expands support to AD FS servers
What’s new: Dedicated clusters for Azure Sentinel
Handling ingestion delay in Azure Sentinel scheduled alert rules
The Ninja Training 2021 edition is out!
Show Links:
Azure Active Directory audit logs now available in Advanced Hunting (public preview)
Microsoft Defender for Office 365 investigation improvements coming soon
Investigate Azure Security Center alerts using Azure Sentinel
Announcing EDR in block mode general availability
SolarWinds Post-Compromise Hunting with Azure Sentinel
Microsoft Cloud App Security (MCAS) Activity Log in Azure Sentinel
Show Links:
YouTube Playlist
https://techcommunity.microsoft.com/t5/azure-sentinel/how-to-setup-a-canarytoken-and-receive-incident-alerts-on-azure/ba-p/1964076
Show Links:
Top 5 Azure Security Best Practices
1) Encrypt
2) Restrict access to your databases
3) … to your VMs
4) Protect Application Secrets
5) Use Azure Security Center to monitor and improve
6) BONUS tips!!! WAF, using a separate Subscription for production.
Michael Crump works at Microsoft on the Microsoft Learn team focusing on security, compliance and identity. He is a coder, blogger, live-streamer and speaker of various security and cloud development topics. He’s passionate about helping developers understand the benefits of the cloud in a no-nonsense way. You can reach him on Twitter at mbcrump or by checking out his Twitch channel at https://twitch.tv/mbcrump
Links:
https://docs.microsoft.com/en-us/learn/roles/security-engineer
https://twitch.tv/mbcrump
https://youtube.com/mbcrump
Show Links:
YouTube Playlist
EDR for Linux is now available in public preview
MCAS Ninja: What’s a CASB and Why Do I Need One?
Secure your GitHub deployment using Microsoft Cloud App Security
Using Advanced Audit to improve your forensic investigation capability
Show Links:
YouTube Playlist
Improved incident queue in Microsoft 365 Defender
Microsoft Insider Risk Management & Communication Compliance Webinar
The Microsoft Cloud App Security (MCAS) Ninja Training is Here!
What's new: Monitoring your Logic Apps Playbooks in Azure Sentinel
Microsoft Defender for Identity - Azure ATP Daily Operation
Show Links:
YouTube Playlist
SOC Prime O365 rules and more now offered free, exclusively to Azure Sentinel users
Guided UEBA Investigation Scenarios to empower your SOC
Azure Sentinel All-In-One Accelerator
What’s new – Announcing new Azure Sentinel data residency locations: Japan, UK and Canada
Show Links:
YouTube Playlist
Do you have what it takes to become the security hero you’ve always been destined to be?
Azure Sentinel roadmap - data collection
Advancing Password Spray Attack Detection
Introducing a new threat and vulnerability management report
Announcing the Investigation Insights Workbook
Advanced Incident Management for Office and Endpoint DLP using Azure Sentinel
LinkedIn Group: Azure Sentinel - Cloud Native SIEM
How to be Notified When Azure Sentinel Data Stops Flowing
Show Links:
YouTube Playlist
Connect data from Microsoft 365 Defender to Azure Sentinel
What’s New: Entity Insights for Convenient Investigation Checks is Now in Public Preview
Microsoft 365 Defender enriches the Microsoft Defender for Identity experience
https://www.wintools.info/
Show Links:
YouTube Playlist
Announcing the Zero Trust Deployment Center
Security Admins, MCAS, and BLOCK!
What's new: New Fusion detections and BYOML in public preview!
Aggregating Insider Risk Management Information via Azure Sentinel
What's new: Watchlist is now in public preview!
Show Links:
YouTube Playlist
Announcing Attack Simulation Training in Microsoft Defender for Office 365
Stay ahead of threats with new innovations from Azure Sentinel
Auditing Azure Sentinel activities
How to integrate vulnerability management in Azure Sentinel
Announcing Priority Account Protection in Microsoft Defender for Office 365
Show Links:
YouTube Playlist
ZeroLogon is now detected by Microsoft Defender for Identity (CVE-2020-1472 exploitation)
Customizing Endpoint Protection Recommendation in Azure Security Center
Security Center | Cloud connectors (Preview)
Enriching Windows Security Events with Parameterized Function
Analysing Web Shell Attacks with Azure Defender data in Azure Sentinel
Show Links:
YouTube Playlist
Azure Sentinel webinar: KQL part 3 of 3 - Optimizing Azure Sentinel KQL queries performance
What’s new: Office 365 Advanced Threat Protection connector in Public Preview
How to Protect Office 365 with Azure Sentinel
What’s New: Cross-workspace Analytics Rules
Show Links:
YouTube
Sentinel:
What’s new: Azure DDoS Protection connector in Public Preview for Azure Sentinel
What’s new: Microsoft Teams connector in Public Preview
What’s New: Azure Firewall Connector in Public Preview!
Remediate Vulnerable Secure Channel Connections with the Insecure Protocols Workbook
MCAS
Auto-Triage Infrequent Country Alerts using MCAS & Power Automate
Azure ATP
Mitigating vulnerabilities with identity security posture assessments
Microsoft Defender ATP
How behavioral blocking & containment stops post-exploitation tools like BloodHound, Kerberoasting
Azure Security Center
Automation to Block Brute-force Attacked IP detected by Azure Security Center
Become an Azure Security Center Ninja
Show Links:
YouTube Playlist
ALERT! New Blog Series: Automation in Cloud App Security
Accelerate your Azure Sentinel Deployment with this Azure DevOps Boards Template
A new look for threat analytics
Webinar: How to maximize Microsoft Defender ATP configuration using attack simulations
Microsoft Defender ATP Ninja Training: August 2020 update
Show Links:
YouTube Playlist
SANS Data Incident 2020 - Technical Details Webcast
What’s New: Query line numbering, Azure Sentinel in the schema pane
Microsoft Threat Protection now uses more descriptive incident names
Hunt for threats using events captured by Azure ATP on your domain controller
Introducing EDR in block mode: Stopping attacks in their tracks
Show Links:
YouTube Playlist: https://www.youtube.com/playlist?list=PLdmduxBoVz1qt-KtGDMuSt3ZEgAHM4evN
Show Links:
YouTube Playlist
New: Per data type retention is now available for Azure Sentinel
Welcome to the new community home for Microsoft Threat Protection (MTP)
Webinar series: Unleash the hunter in you!
Microsoft Endpoint Manager: Create & Audit an ASR Policy
SolarWinds announces collaboration with Microsoft to enhance monitoring and management for MSPs
Fileless Attack Detection for Linux Preview is Expanding
Show Links:
YouTube Playlist
Announcing Microsoft Security’s #CyberContest
Azure Security Center in the Field - YouTube Series
See how consolidated incidents improve SOC efficiency through this attack sprawl simulation
Announcing public preview of Double Key Encryption for Microsoft 365
Protecting against insider risks in an uncertain environment
Announcing general availability of the new version of Microsoft Secure Score
Show Links:
End of mainstream support for Advanced Threat Analytics January 2021
Multi-tenant access for Managed Security Service Providers
Announcing public preview of Microsoft Endpoint Data Loss Prevention
New Azure Sentinel connectors
What's New: Cross Workspace Hunting is now available!
What's New: Azure Sentinel Machine Learning Behavior Analytics: Anomalous RDP Login Detection
Pivot fast and investigate freely with go hunt & other advanced hunting enhancements
Microsoft 365 E5 Security can replace up to 26 other security vendors
Show Links:
Categorizing Microsoft alerts across data sources in Azure Sentinel
Microsoft Defender ATP awarded a perfect 5-star rating by SC Media
Webinar series: Unleash the hunter in you!
Microsoft Threat Protection advanced hunting cheat sheet
Introducing event timeline – an innovative, new way to manage your security exposure
Introducing Project Freta
13Cubed - Linux Memory Forensics - Memory Capture and Analysis
Show Links:
Webinar: How to get started with Microsoft Defender ATP
https://techcommunity.microsoft.com/t5/microsoft-defender-atp/webinar-how-to-get-started-with-microsoft-defender-atp/ba-p/1484869
Show Links:
Maximizing your Identity Security Posture with Azure Advanced Threat Protection
https://techcommunity.microsoft.com/t5/microsoft-security-and/maximizing-your-identity-security-posture-with-azure-advanced/ba-p/750784
Safe Documents is Generally Available
https://techcommunity.microsoft.com/t5/microsoft-365-blog/safe-documents-is-generally-available/ba-p/1480401
Show Links:
https://www.microsoft.com/security/blog/2020/06/10/the-science-behind-microsoft-threat-protection-attack-modeling-for-finding-and-stopping-evasive-ransomware/
The science behind Microsoft Threat Protection: Attack modeling for finding and stopping evasive ransomware
https://techcommunity.microsoft.com/t5/microsoft-defender-atp/say-hello-to-the-new-alert-page-in-microsoft-defender-atp/ba-p/1463673
Say hello to the new alert page in Microsoft Defender ATP
https://techcommunity.microsoft.com/t5/azure-sentinel/move-your-azure-sentinel-logs-to-long-term-storage-with-ease/ba-p/1407153
Move Your Azure Sentinel Logs to Long-Term Storage with Ease
https://techcommunity.microsoft.com/t5/azure-sentinel/protecting-your-github-assets-with-azure-sentinel/ba-p/1457721
Protecting your GitHub assets with Azure Sentinel
https://techcommunity.microsoft.com/t5/microsoft-security-and/remote-working-fewer-people-working-on-premises-doesn-t-mean/ba-p/1430963
Remote Working: Fewer people working on-premises doesn’t mean less risk to their identities
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-azure-sentinel-threat-hunting-enhancements/ba-p/1433396
What’s New: Azure Sentinel Threat Hunting Enhancements
https://techcommunity.microsoft.com/t5/azure-data-explorer/how-to-stream-microsoft-defender-atp-hunting-logs-in-azure-data/ba-p/1427888
How to stream Microsoft Defender ATP hunting logs in Azure Data Explorer
https://techcommunity.microsoft.com/t5/microsoft-security-and/mip-and-compliance-v-blog-part-1-setting-up-a-secure/ba-p/1441759
MIP and Compliance V-blog part 1 - Setting up a secure collaboration environment
What’s New: Improved Incident Closing Experience is now Available!
https://techcommunity.microsoft.com/t5/azure-sentinel/what-s-new-improved-incident-closing-experience-is-now-available/ba-p/1278807#
Protecting your organization against password spray attacks
https://www.microsoft.com/security/blog/2020/04/23/protecting-organization-password-spray-attacks/
Azure ATP now detects SMBGhost
https://techcommunity.microsoft.com/t5/security-privacy-and-compliance/azure-atp-now-detects-smbghost/ba-p/1300658
This Week:
Threat hunting simplified with Microsoft Threat Protection
Short & sweet educational videos on Microsoft Defender ATP
Protecting Your (Microsoft) Teams with Azure Sentinel
This week:
Azure Windows Virtual Desktop update
Harden endpoint security for COVID-19 and working from home with Threat & Vulnerability Management
Microsoft Threat Protection will automatically turn on for eligible license holders
Become an Azure Sentinel Ninja: The complete level 400 training
Azure Sentinel To-Go and Defending SMBs with M365 Business.
This week Edward and Frank discuss Microsoft Tech Community articles:
Azure Sentinel To-Go: Sentinel Lab w/ Prerecorded Data
Defending SMBs from cyber threats with Microsoft 365 Business
In this episode we discuss Azure Windows Virtual Desktop, Cloud App Security, and Azure Information Protection.
Welcome to the Microsoft Security Insights Podcast hosted by Edward Walton and Frank Grimberg. This episode introduces the podcast and the hosts.