Azure Sentinel Internals: Incidents

In my experience, people – due to a lack of knowledge or plain laziness (and I am one of them) sometimes mix-up terms like Events, Alerts, Alarms and Incidents in their conversations. In addition, different tools have different terms for the objects they are displaying in their GUIs. With this article, we will go through all those entities in Sentinel and take a deep dive into their correlations.

Read more

Manage office atp alerts like a boss

Let’s face it: Sometimes you get false positives in Office ATP phishing Emails. Either this is caused by the system or you have scheduled a phishing simulation from a third party provider that cannot be properly whitelisted. I have created a PowerShell script that connects to the Office 365 Management API and grabs all the needed information from the investigations and from the alerts and displays it in ONE Excel table.

Read more
« Older Entries