97. Microsoft Azure Sentinel

Content type
Video

97. Microsoft Azure Sentinel

Jelle and Gerben talk about Microsoft Azure Sentinel. They discuss how to set up monitoring and incident response, demonstrating how Sentinel can be used to centralize security data from Azure activity logs for better visibility and automated response. Key points include ingesting logs into a Log Analytics workspace, using content packs for data connectors and analytics rules, and scanning data at the subscription or resource group level. They also show how logs can be analyzed for potential threats using queries and custom alerts. Their discussion emphasizes starting small, continuously improving rules and workbooks over time based on detected signals, and considering red team testing to evaluate detection capabilities.

Links for more information:

More videos

Stay up to date with our Betatalks and tech updates!

Sign up and receive a biweekly update with the latest knowledge and developments.