A quick introduction to Sentinel Repositories.
Tag Archives: SIEM
Safely integrate playbooks with custom APIs when there is no pre-built Logic App connector.
How to create a custom logic app connector, so you can store your API key securely and use it within your playbooks, when there is no pre-built connector.
Azure Lighthouse and Sentinel: Assigning access to managed identities in the customer tenant
MSSP – To trigger playbooks in the customer tenants sometimes you need to assign the managed identities of those playbooks permissions to execute actions within the customer tenant. This post covers the steps to configure the access required to assign those roles and the steps to assign the roles as well.
Delegate access using Azure Lighthouse for a Sentinel POC
Steps to delegate access to users on another tenant for a Sentinel POC using Azure Lighthouse.
Disguising data
Testing the new ingestion time transformation features in Microsoft Sentinel.
Leave it open and they will come
A story of how I left an RDP port wide open (oops!) and MDC and Sentinel came to my rescue when my resource was attacked.
Sorting out the Azure Activity Connector in Microsoft Sentinel
Just a few tips and tricks for configuring the Azure Activity Connector in Microsoft Sentinel.