Monitoring on-premises servers and Azure IaaS VMs using Microsoft Sentinel
Microsoft Sentinel is a cloud-based Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) solution that provides threat intelligence and security analytics at scale. Arguably one of my favorite tools to work with, this single-pane collection of solutions, dashboards, playbooks, notebooks, hunting, analytics, and, most importantly, data source connectors make this tool unbelievably powerful for threat response and security analytics in your organizations.
Highly customizable with custom alerts, immersive dashboard design, community components available, and built off the Kusto Query Language (KQL) to help with data queries and manipulation, Microsoft Sentinel brings an arsenal of tools and great community support to help everyone achieve their desired threat detection and response goals. It’s only right to share the following great KQL resources...