Search icon CANCEL
Subscription
0
Cart icon
Your Cart (0 item)
Close icon
You have no products in your basket yet
Save more on your purchases! discount-offer-chevron-icon
Savings automatically calculated. No voucher code required.
Arrow left icon
Explore Products
Best Sellers
New Releases
Books
Videos
Audiobooks
Learning Hub
Free Learning
Arrow right icon
Arrow up icon
GO TO TOP
 Microsoft Defender for Identity in Depth

You're reading from   Microsoft Defender for Identity in Depth An exhaustive guide to ITDR, breach prevention, and cyberattack response

Arrow left icon
Product type Paperback
Published in Dec 2024
Publisher Packt
ISBN-13 9781835884485
Length 380 pages
Edition 1st Edition
Arrow right icon
Author (1):
Arrow left icon
Pierre Thoor Pierre Thoor
Author Profile Icon Pierre Thoor
Pierre Thoor
Arrow right icon
View More author details
Toc

Table of Contents (16) Chapters Close

Preface 1. Part 1:Mastering the Fundamentals of Microsoft Defender for Identity FREE CHAPTER
2. Chapter 1: Introduction to Microsoft Defender for Identity 3. Chapter 2: Setting up Microsoft Defender for Identity 4. Chapter 3: Leveraging MDI PowerShell for Automation and Management 5. Part 2: Advanced Configuration, Integration, and Threat Detection
6. Chapter 4: Integrating MDI with AD FS, AD CS, and Entra Connect 7. Chapter 5: Extending MDI Capabilities Through APIs 8. Chapter 6: Mastering KQL for Advanced Threat Detection in MDI 9. Part 3: Operational Excellence with Microsoft Defender for Identity
10. Chapter 7: Investigating and Responding to Security Alerts 11. Chapter 8: Utilizing MDI Action Accounts Effectively 12. Chapter 9: Building a Resilient Identity Threat Detection and Response Framework 13. Chapter 10: Navigating Challenges: MDI Troubleshooting and Optimization 14. Index 15. Other Books You May Enjoy

Advanced KQL techniques for deep threat detection

In the realm of cybersecurity, Active Directory (AD) remains a prime target for attackers seeking to exploit enterprise networks. Understanding known attack paths in Active Directory and leveraging powerful query languages to detect these threats is crucial for defending against sophisticated cyber threats. This section of the chapter delves into advanced KQL techniques for deep threat detection using MDI and Microsoft Defender XDR. We’ll start by exploring the basics of common AD attack paths, gradually advancing to complex detection methodologies, and examining how MDI implements detections across various phases of an attacker’s kill chain.

Understanding attack paths in AD

AD is a critical component in many organizational IT infrastructures, providing authentication and authorization services. Many IT professionals are saying that AD is a legacy IAM solution, but it is still used at scale and hard to get away from...

lock icon The rest of the chapter is locked
Register for a free Packt account to unlock a world of extra content!
A free Packt account unlocks extra newsletters, articles, discounted offers, and much more. Start advancing your knowledge today.
Unlock this book and the full library FREE for 7 days
Get unlimited access to 7000+ expert-authored eBooks and videos courses covering every tech area you can think of
Renews at $19.99/month. Cancel anytime
Banner background image