Microsoft Sentinel
Microsoft Sentinel is Microsoft’s cloud-based SIEM and Security Orchestration, Automation, and Response (SOAR) tool. It provides security data aggregation, threat analysis, and response across public cloud and on-premises environments. This service is your bird’s-eye view of centralized security data and events across an organization, using integrated AI for large-scale threat analysis and response.
A SIEM solution collects “security log data”—security signalling—and examines it for patterns that could indicate an attack. Then, it correlates event information to identify potentially abnormal activity. Finally, any issues are alerted, and this automates responses and remediation. Figure 6.7 illustrates this relationship between the security analytics of Microsoft Sentinel and the security signalling collected from the security tooling of the security data sources:
Figure 6.7 – The relationship...