<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Azure security Archives - Erjen Rijnders</title>
	<atom:link href="https://erjenrijnders.nl/category/azure-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://erjenrijnders.nl/category/azure-security/</link>
	<description>Microsoft Azure/EMS blog</description>
	<lastBuildDate>Thu, 04 Apr 2019 16:12:21 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.6.2</generator>
	<item>
		<title>Azure Sentinel &#8211; The reinvented SIEM</title>
		<link>https://erjenrijnders.nl/2019/03/20/azure-sentinel-the-reinvented-siem/</link>
					<comments>https://erjenrijnders.nl/2019/03/20/azure-sentinel-the-reinvented-siem/#comments</comments>
		
		<dc:creator><![CDATA[Erjen]]></dc:creator>
		<pubDate>Wed, 20 Mar 2019 15:54:06 +0000</pubDate>
				<category><![CDATA[Azure]]></category>
		<category><![CDATA[Security and Compliance center]]></category>
		<category><![CDATA[Azure security]]></category>
		<guid isPermaLink="false">http://erjenrijnders.nl/?p=75888</guid>

					<description><![CDATA[<p>Why Azure Sentinel Azure Sentinel &#8211; Data connectors Azure Sentinel &#8211; Analytics Azure Sentinel &#8211; Cases Azure Sentinel &#8211; Overview [&#8230;]</p>
<p>The post <a href="https://erjenrijnders.nl/2019/03/20/azure-sentinel-the-reinvented-siem/">Azure Sentinel &#8211; The reinvented SIEM</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<ol class="wp-block-list"><li><a href="#WhyAzureSentinel"><strong>Why Azure Sentinel</strong></a></li><li><strong><a href="#AzureSentinelDataConnectors">Azure Sentinel &#8211; Data connectors</a></strong></li><li><strong><a href="#AzureSentinelAnalytics">Azure Sentinel &#8211; Analytics</a></strong></li><li><strong><a href="#AzureSentinelCases">Azure Sentinel &#8211; Cases</a></strong></li><li><strong><a href="#AzureSentinelOverview">Azure Sentinel &#8211; Overview page</a></strong></li></ol>



<h2 class="wp-block-heading" id="WhyAzureSentinel">Why Azure Sentinel</h2>



<p>Azure Sentinel is the latest, security related, innovation from Microsoft. Microsoft calls it a “reinvented SIEM” solution. Well, it’s not really innovation, it’s more of a combination of all security products of Microsoft. We have Cloud App Security, Azure Advanced Threat Protection, Security Events, Windows Firewall, Windows Azure Firewall etc. etc.<br><br>Azure Sentinel has not only built-in AI (which we expect from nowadays products from Microsoft), but it transcends the AI, already available in the product itself (like the AI in Identity Protection), but it creates an extra AI layer, on top of the already existing AI infrastructure which makes it really cool. So the AI of Sentinel doesn’t have to know the underlaying AI technology, it just needs to combine the output of every separate AI and create valuable input. Microsoft already uses this technique for years and because of their experience, it’s now broadly available.<br><br>Azure Sentinel has not only built-in AI (which we expect from nowadays products from Microsoft), but it transcends the AI, already available in the product itself (like the AI in Identity Protection), but it creates an extra AI layer, on top of the already existing AI infrastructure which makes it really cool. So the AI of Sentinel doesn’t have to know the underlaying AI technology, it just needs to combine the output of every separate AI and create valuable input. Microsoft already uses this technique for years and because of their experience, it’s now broadly available.<br><br>Let’s have a look at Azure Sentinel. Go to the Azure Portal and search for “Azure Sentinel”. As you can see it’s still in preview.</p>



<p>You need to
create a Log Analytics Workspace for Sentinel to work. As long as Sentinel is
in preview, you won’t pay anything, except costs like storage which you will
make creating a workspace.</p>



<figure class="wp-block-image"><img fetchpriority="high" decoding="async" width="876" height="417" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/create-azure-log-analytics-workspace-1.png" alt="" class="wp-image-75892" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/create-azure-log-analytics-workspace-1.png 876w, https://erjenrijnders.nl/wp-content/uploads/2019/03/create-azure-log-analytics-workspace-1-300x143.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/create-azure-log-analytics-workspace-1-768x366.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/create-azure-log-analytics-workspace-1-600x286.png 600w" sizes="(max-width: 876px) 100vw, 876px" /></figure>



<h2 class="wp-block-heading" id="AzureSentinelDataConnectors">Azure Sentinel &#8211; Data connectors</h2>



<p>The first page you see is the &#8220;Getting started&#8221; page. Click on &#8220;Collect data&#8221; to start collecting data.</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="384" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1-1024x384.png" alt="" class="wp-image-75893" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1-1024x384.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1-300x113.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1-768x288.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1-600x225.png 600w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-getting-started-1.png 1231w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>You will see an overview of all the data you connect. It&#8217;s already a nice list of services you can connect. If you are already full onboarded in Azure/Office 365, you will have many relevant products to connect!</p>



<figure class="wp-block-image"><img decoding="async" width="1024" height="539" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors-1024x539.png" alt="" class="wp-image-75896" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors-1024x539.png 1024w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors-300x158.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors-768x404.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors-600x316.png 600w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-data-connectors.png 1577w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>Of course, we are going to connect &#8220;Azure Information Protection&#8221; first. You need to go to the &#8220;Azure Information Protection&#8221; tab Click &#8220;Azure Information Protection&#8221; and click &#8220;connect to your Azure Sentinel workspace&#8221;. </p>



<figure class="wp-block-image"><img decoding="async" width="951" height="683" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP.png" alt="" class="wp-image-75898" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP.png 951w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-300x215.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-768x552.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-600x431.png 600w" sizes="(max-width: 951px) 100vw, 951px" /></figure>



<p>Click on the Azure Sentinel workspace, you need to reconfigure the AIP log so that it stores the AIP information in the Azure Sentinel workspace (if you don&#8217;t see any, you should go to Azure Information Protection&#8221; and enable logging there) and also check the deeper analytics checkbox to see sensitive information types as well.</p>



<figure class="wp-block-image"><img decoding="async" width="829" height="135" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-sensitive.png" alt="" class="wp-image-75899" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-sensitive.png 829w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-sensitive-300x49.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-sensitive-768x125.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-AIP-sensitive-600x98.png 600w" sizes="(max-width: 829px) 100vw, 829px" /></figure>



<p>Now connect everything you want to connect, like Azure AD. Cool thing is that if you connect Office 365, you can connect multiple tenants! So I expect that more data connectors are going to be multi-tenant which mean we really have the reinvented SIEM.</p>



<figure class="wp-block-image"><img decoding="async" width="503" height="461" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-Azure-AD.png" alt="" class="wp-image-75901" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-Azure-AD.png 503w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-connect-Azure-AD-300x275.png 300w" sizes="(max-width: 503px) 100vw, 503px" /></figure>



<h2 class="wp-block-heading" id="AzureSentinelAnalytics">Azure Sentinel &#8211; Analytics</h2>



<p>If you click in the Azure Sentinal tab on &#8220;Analytics&#8221;, you can create rules when you want to be alerted. For example you can create an alert when a virtual machine is created or updated. For more information, check the code example from <a href="https://docs.microsoft.com/en-us/azure/sentinel/tutorial-detect-threats">Microsoft Docs</a> as well.</p>



<pre class="wp-block-code">

<div class="codecolorer-container text twitlight" style="overflow:auto;white-space:nowrap;border:1px solid #9F9F9F;width:435px;"><table cellspacing="0" cellpadding="0"><tbody><tr><td style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap;text-align:center;color:#888888;background-color:#EEEEEE;border-right: 1px solid #9F9F9F;"><div>1<br />2<br />3<br />4<br />5<br /></div></td><td><div class="text codecolorer" style="padding:5px;font:normal 12px/1.4em Monaco, Lucida Console, monospace;white-space:nowrap;">AzureActivity<br />
&nbsp;| where OperationName == &quot;Create or Update Virtual Machine&quot; or OperationName == &quot;Create Deployment&quot;<br />
&nbsp;| where ActivityStatus == &quot;Succeeded&quot;<br />
| extend AccountCustomEntity = ResourceGroup<br />
| extend IPCustomEntity = TenantId</div></td></tr></tbody></table></div>

</pre>



<p>You can create a lot of rules, but in my opinion it&#8217;s not that simple to configure the alerts you need. Especially if you need many specific rules. But this is still a preview version, I expect more options and simplifications in the general available version.</p>



<figure class="wp-block-image"><img decoding="async" width="580" height="816" src="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-ip.png" alt="" class="wp-image-75915" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-ip.png 580w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Azure-Sentinel-ip-213x300.png 213w" sizes="(max-width: 580px) 100vw, 580px" /></figure>



<h2 class="wp-block-heading" id="AzureSentinelCases">Azure Sentinel Cases</h2>



<p>A case in Sentinel is automatically created, once an event is triggered. Soon I will update this with more data.</p>



<h2 class="wp-block-heading" id="AzureSentinelOverview">Azure Sentinel Overview page</h2>



<p>In the “Overview” section, you have a nice dashboard of everything that is going on. See an example here below. It&#8217;s not much data yet, but this is from just a few hours. I will update this dashboard once I have more detailed information.</p>



<figure class="wp-block-image"><img decoding="async" width="852" height="412" src="http://erjenrijnders.nl/wp-content/uploads/2019/03/Sentinel-overview.png" alt="" class="wp-image-75924" srcset="https://erjenrijnders.nl/wp-content/uploads/2019/03/Sentinel-overview.png 852w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Sentinel-overview-300x145.png 300w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Sentinel-overview-768x371.png 768w, https://erjenrijnders.nl/wp-content/uploads/2019/03/Sentinel-overview-600x290.png 600w" sizes="(max-width: 852px) 100vw, 852px" /><figcaption>Sentinel-overview</figcaption></figure>
<p>The post <a href="https://erjenrijnders.nl/2019/03/20/azure-sentinel-the-reinvented-siem/">Azure Sentinel &#8211; The reinvented SIEM</a> appeared first on <a href="https://erjenrijnders.nl">Erjen Rijnders</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://erjenrijnders.nl/2019/03/20/azure-sentinel-the-reinvented-siem/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
	</channel>
</rss>
