{"id":63217,"date":"2022-01-12T08:00:03","date_gmt":"2022-01-12T16:00:03","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/devops\/?p=63217"},"modified":"2022-01-11T07:53:22","modified_gmt":"2022-01-11T15:53:22","slug":"azurefunbytes-episode-64-building-soc-efficiency-with-azure-sentinel-with-rodtrent","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/devops\/azurefunbytes-episode-64-building-soc-efficiency-with-azure-sentinel-with-rodtrent\/","title":{"rendered":"AzureFunBytes Episode 64 &#8211; Building SOC Efficiency with @Azure Sentinel with @rodtrent"},"content":{"rendered":"<p>AzureFunBytes is a weekly opportunity to learn more about the fundamentals and foundations that make up Azure. It&#8217;s a chance for me to understand more about what people across the Azure organization do and how they do it. Every week we get together at 11 AM Pacific on <a href=\"https:\/\/cda.ms\/226\">Microsoft LearnTV<\/a> and learn more about Azure.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/res.cloudinary.com\/practicaldev\/image\/fetch\/s--Z7BxBMz1--\/c_limit%2Cf_auto%2Cfl_progressive%2Cq_66%2Cw_880\/https:\/\/dev-to-uploads.s3.amazonaws.com\/uploads\/articles\/j2xzw2g664tj31jij13t.gif\" alt=\"AzureFunBytes animation\" \/><\/p>\n<p>It&#8217;s been a few weeks but AzureFunBytes is back with a new episode all about mitigating risk in the cloud by using tools provided by Azure.  If you&#8217;re currently deploying workloads in the cloud, how they handle potential intrusions and attacks is crucial.  By preventing these security incidents you can build trust with those who may access your applications and IT solutions.<\/p>\n<p><a href=\"https:\/\/cda.ms\/3xS\">Microsoft documentation defines the role of the security operation teams<\/a> (also known as Security Operations Center (SOC), or SecOps) is to detect, prioritize, and triage potential attacks.  The central SecOps team monitors and analyses security-related telemetry data. Any communication, investigation, or hunting actions must be coordinated with the application team.<\/p>\n<p>This week we&#8217;ll investigate the use cases for implementing the first cloud-native Security and Event Management service (SIEM) <a href=\"https:\/\/cda.ms\/3xP\">Microsoft Sentinel<\/a>.  Microsoft Sentinel includes a number of connectors for Microsoft solutions that are ready to use and provide real-time integration, such as Microsoft 365 Defender (formerly Microsoft Threat Protection) solutions and Microsoft 365 sources such as Office 365, Azure AD, Microsoft Defender for Identity (formerly Azure ATP), and Microsoft Defender for Cloud Apps, among others. There are also built-in interfaces for non-Microsoft security solutions to the broader security ecosystem. You can also link your data sources to Microsoft Sentinel using common event formats, Syslog, or REST-API.<\/p>\n<p>Microsoft Sentinel exists today, in part, because of the gaps in existing tools that were identified as Microsoft began its own journey to the cloud. One of those gaps is around efficiency and scale. In this session, we\u2019ll talk about how Microsoft Sentinel was intentionally and mindfully developed to allow security teams to do more things more quickly without a drain on resources.<\/p>\n<p>With Sentinel we can:<\/p>\n<ul>\n<li>Collect data at cloud scale<\/li>\n<li>Detect threats<\/li>\n<li>Investigate threats<\/li>\n<li>Respond to incidents<\/li>\n<\/ul>\n<p>To help me with my journey into deploying Microsoft Sentinel I&#8217;ll be joined by Microsoft Senior Cloud Security Advocate <a href=\"https:\/\/twitter.com\/rodtrent\">Rod Trent<\/a> this week to see how we can build SOC efficiency with Microsoft Sentinel.  Rod will help me better understand how Microsoft Sentinel delivers <strong>intelligent security analytics and threat intelligence<\/strong> across the enterprise<\/p>\n<p><iframe title=\"AzureFunBytes Episode 64 - Building SOC Efficiency with @Azure Sentinel with @rodtrent\" width=\"500\" height=\"281\" src=\"https:\/\/www.youtube.com\/embed\/wuqCjUmOFV0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p><a href=\"https:\/\/youtu.be\/wuqCjUmOFV0\">00:00:00 &#8211; Intro<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=195\">00:03:15 &#8211; Welcome back to AzureFunBytes<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=315\">00:05:15 &#8211; Let&#8217;s meet Rod Trent<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=376\">00:06:16 &#8211; So how&#8217;d you get here?<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=532\">00:08:52 &#8211; Four pillars of Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=703\">00:11:43 &#8211; How does our SOC fit in?<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=814\">00:13:34 &#8211; Let&#8217;s learn about Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1269\">00:21:09 &#8211; SLAs<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1330\">00:22:10 &#8211; Daily Must-do&#8217;s<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1430\">00:23:50 &#8211; Current SOC Efficiency Hunt Complaints<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1574\">00:26:14 &#8211;  A look at what&#8217;s in the demo<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1707\">00:28:27 &#8211; Can Microsoft Sentinel integrate with other Microsoft security tools?<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1840\">00:30:40 &#8211; Does Microsoft Sentinel only work with Microsoft products and clouds?<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=1962\">00:32:42 &#8211; What can be automated in Microsoft Sentinel?<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=2222\">00:37:02 &#8211; Demo time!<\/a><br>\n<a href=\"https:\/\/youtu.be\/wuqCjUmOFV0?t=3076\">00:51:16 &#8211; Must Learn KQL<\/a><\/p>\n<p>Our agenda includes:<\/p>\n<ul>\n<li>Azure Sentinel is the Tofu tool for monitoring security for the entire environment.<\/li>\n<li>Azure Sentinel is the sluice box of the Microsoft security platform.<\/li>\n<li>Azure Sentinel is the Cyclorama for the connected entities. <\/li>\n<\/ul>\n<p>About Rod Trent:<\/p>\n<p><em>Rod Trent is a Senior Cloud Security Advocate for Microsoft and an Azure Sentinel global SME helping customers migrate from existing SIEMs to #AzureSentinel to achieve the promise of better security through improved efficiency without compromise. He is a husband, dad, and first-time grandfather (so speak slow and loud). He spends his spare time (if such a thing does truly exist) simultaneously watching Six Million Dollar Man TV show episodes and writing KQL queries.<\/em><\/p>\n<hr \/>\n<p>Learn about Azure fundamentals with me!<\/p>\n<p>Live stream is normally found on Twitch, YouTube, and <a href=\"https:\/\/cda.ms\/226\">LearnTV<\/a> at 11 AM PT \/ 2 PM ET Thursday. You can also find the recordings here as well:<\/p>\n<p><a href=\"https:\/\/twitch.tv\/azurefunbytes\">AzureFunBytes on Twitch<\/a><br>\n<a href=\"https:\/\/aka.ms\/jaygordononyoutube\">AzureFunBytes on YouTube<\/a><br>\n<a href=\"https:\/\/www.youtube.com\/channel\/UC-ikyViYMM69joIAv7dlMsA\">Azure DevOps YouTube Channel<\/a><br>\n<a href=\"https:\/\/twitter.com\/azurefunbytes\">Follow AzureFunBytes on Twitter<\/a><br><\/p>\n<p>Useful Docs:<br>\n<a href=\"https:\/\/cda.ms\/219\">Get $200 in free Azure Credit<\/a><br>\n<a href=\"https:\/\/cda.ms\/243\">Microsoft Learn: Introduction to Azure fundamentals<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xS\">Security Operations in Azure<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xR\">Microsoft Sentinel Overview<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xP\">What is Microsoft Sentinel?<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xY\">Microsoft Learn: Introduction to Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xZ\">Microsoft Learn: SC-200: Configure your Microsoft Sentinel environment<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xX\">Pre-deployment activities and prerequisites for deploying Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xQ\">Quickstart: On-board Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/cda.ms\/3y1\">Best practices for Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xT\">Tutorial: Use playbooks with automation rules in Microsoft Sentinel<\/a><br>\n<a href=\"https:\/\/cda.ms\/3xW\">Tutorial: Create a Power BI report from Microsoft Sentinel data<\/a><br>\n<a href=\"https:\/\/cda.ms\/3y0\">Forrester: The Total Economic Impact\u2122 Of Microsoft Azure Sentinel<\/a><br>\n<a href=\"https:\/\/aka.ms\/SentinelNewsletter\">Weekly Microsoft Sentinel newsletter<\/a><br>\n<a href=\"https:\/\/aka.ms\/SentinelLinkedIn\">Microsoft Sentinel community on LinkedIn<\/a><br>\n<a href=\"https:\/\/aka.ms\/AzureSentinelBlog\">Microsoft Sentinel product blog<\/a><br>\n<a href=\"https:\/\/aka.ms\/RodsBlog\">Rod Trent&#8217;s blog<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>This week we\u2019ll investigate the use cases for implementing the first cloud-native Security and Event Management service (SIEM) Microsoft Sentinel. <\/p>\n","protected":false},"author":39313,"featured_media":63218,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[224,251],"tags":[],"class_list":["post-63217","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","category-security"],"acf":[],"blog_post_summary":"<p>This week we\u2019ll investigate the use cases for implementing the first cloud-native Security and Event Management service (SIEM) Microsoft Sentinel. <\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/63217","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/users\/39313"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/comments?post=63217"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/posts\/63217\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media\/63218"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/media?parent=63217"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/categories?post=63217"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/devops\/wp-json\/wp\/v2\/tags?post=63217"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}