An attack kill chain in XDR and SIEM
As we can see from Figure 5.1, Microsoft’s security solutions provide comprehensive visibility for a wide range of attack techniques, including both external and internal threat scenarios. You can also see in Figure 5.1 how the Extended Detection and Response (XDR) and SIEM solutions share signals between each other and work together to defend across common attack chains.
Figure 5.1 – An illustration of how XDR + Sentinel tools work together to keep organization secure
As we highlighted in Chapter 3, these capabilities can provide enhanced threat detections for organizations as well as automated investigation and response capabilities.
Identity threat detection and response
Identity Threat Detection and Response (ITDR) is a relatively new term that was invented to meet the need of having a security category in place to identify, reduce, and respond to potential identity-based threats. Based on Gartner...