Azure Sentinel: set up
automated threat
responses in Azure
through Logic Apps
Thanks to
AGENDA
• Azure Sentinel main features
• Respond to incidents rapidly with built-in orchestration
and automation
• DEMO
Expanding digital estate
Too many
disconnected
products
76%
report increasing
security data*
3.5M
unfilled security
jobs in 2021
Lack of
automation
44%
of alerts are
never investigated
IT deployment &
maintenance
Sophistication
of threats
Security operations challenges
Introducing Azure Sentinel
intelligent, cloud-native SIEM
Uses AI and automation to
improve effectiveness
Scales to support your
growing digital estate
Delivers instant value to
your defenders
End-to-end solution for security operations
Analytics
DetectCollect
Incidents AutomationVisibility Hunting
Investigate Respond
Powered by community + backed by Microsoft’s security experts
Visibility
Collect security data at cloud scale from any
source
Use workbooks to power interactive
dashboards
Choose from a gallery of workbooks
Customize or create your own
workbooks using queries
Take advantage of rich visualization
options
Gain insight into one or more data
sources
Analytics
Leverage analytics to detect threats
Choose from more than 100 built-in
analytics rules
Customize and create your own rules
using KQL queries
Correlate events with your threat
intelligence and now with Microsoft
URL intelligence
Trigger automated playbooks
Tap into the power of ML increase your catch rate
without increasing noise
Use built–in models – no ML experience
required
Detects anomalies using transferred learning
Fuses data sources to detect threats that span
the kill chain
Simply connect your data and learning begins
Bring your own ML models (coming soon)
Hunting
Start hunting over security data with fast, flexible
queries
Run built-in threat hunting queries -
no prior query experience required
Customize and create your own
hunting queries using KQL
Integrate hunting and investigations
Use bookmarks and live stream to manage your
hunts
Bookmark notable data
Start an investigation from a
bookmark or add to an existing
incident
Monitor a live stream of new threat
related activity
Use Jupyter notebooks for advanced hunting
Run in the Azure cloud
Save as sharable HTML/JSON
Query Azure Sentinel data
Bring external data sources
Use your language of choice - Python,
SQL, KQL, R, …
Incidents
Start and track investigations from prioritized,
actionable security incidents
Use incident to collect related alerts,
events, and bookmarks
Manage assignments and track status
Add tags and comments
Trigger automated playbooks
Visualize the entire attack to determine scope and
impact
Navigate the relationships between
related alerts, bookmarks, and entities
Expand the scope using exploration
queries
View a timeline of related alerts, events,
and bookmarks
Gain deep insights into related entities –
users, domains, and more
Automation
Automate and orchestrate security operations
using integrated Azure Logic Apps
Build automated and scalable
playbooks that integrate across tools
Choose from a library of samples
Create your own playbooks using 200+
built-in connectors
Trigger a playbook from an alert or
incident investigation
Example playbooks
Assign an Incident to an Analyst
Open a Ticket (ServiceNow/Jira)
Keep Incident Status in Sync
Post in a Teams or Slack Channel
Lookup Geo for an IP
Trigger Defender ATP Investigation
Send Validation Email to User
Block an IP Address
Block User Access
Trigger Conditional Access
Isolate Machine
Incident Management Enrichment+ Investigation Remediation
Community
Hundreds of contributions, including
data connectors, workbooks, analytics
rules, queries, notebooks, parsers,
functions, and playbooks are available
on GitHub.
Take actions today—Get started with Azure
Sentinel
To learn more, visit https://aka.ms/AzureSentinel
Create Azure Sentinel
instance
Connect
data sources
Start
Microsoft Azure trial
Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat responses in Azure through Logic Apps
Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat responses in Azure through Logic Apps
Thank You!!!
Thanks to

More Related Content

PPTX
Azure sentinel
PDF
Azure DDoS Protection Standard
PPTX
Remediate and secure your organization with azure sentinel
PPTX
Threat Hunting on AWS using Azure Sentinel
PDF
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
PPTX
Adam ochs sentinel
PPTX
Protect Office 365 with Azure Sentinel
PPTX
Azure sentinal
Azure sentinel
Azure DDoS Protection Standard
Remediate and secure your organization with azure sentinel
Threat Hunting on AWS using Azure Sentinel
Haal de mist uit de monitoring van je cloud met System Center 2012 R2 Operati...
Adam ochs sentinel
Protect Office 365 with Azure Sentinel
Azure sentinal

What's hot (20)

PDF
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
PDF
Microsoft Azure Security Overview
PDF
Extending Amazon GuardDuty with Cloud Insight Essentials
PPTX
CSS 17: NYC - Building Secure Solutions in AWS
PDF
ATT&CKing the Sentinel – deploying a threat hunting capability on Azure Senti...
PDF
CSS17: Houston - Azure Shared Security Model Overview
PPTX
Shared Security Responsibility for the Azure Cloud
PPTX
Journey to Azure Sentinel
PDF
Govern Your Cloud: The Foundation for Success
PDF
Azure vm introduction
PPTX
Microsoft Azure News - April 2021
PDF
The Intersection of Security & DevOps
PPTX
CSS 17: NYC - Protecting your Web Applications
PPTX
CSS 17: NYC - Realities of Security in the Cloud
PPTX
DEVNET-1123 CSTA - Cisco Security Technical Alliances, New Program for Ecosys...
PPTX
CSS 17: NYC - The AWS Shared Responsibility Model in Practice
PDF
Managed Threat Detection and Response
PPTX
#ALSummit: Alert Logic & AWS - AWS Security Services
PPT
Cisco Security Technical Alliance
PDF
Extending Amazon GuardDuty with Cloud Insight Essentials
ISC2 Secure Summit EMEA - Top Microsoft Azure security fails and how to avoid...
Microsoft Azure Security Overview
Extending Amazon GuardDuty with Cloud Insight Essentials
CSS 17: NYC - Building Secure Solutions in AWS
ATT&CKing the Sentinel – deploying a threat hunting capability on Azure Senti...
CSS17: Houston - Azure Shared Security Model Overview
Shared Security Responsibility for the Azure Cloud
Journey to Azure Sentinel
Govern Your Cloud: The Foundation for Success
Azure vm introduction
Microsoft Azure News - April 2021
The Intersection of Security & DevOps
CSS 17: NYC - Protecting your Web Applications
CSS 17: NYC - Realities of Security in the Cloud
DEVNET-1123 CSTA - Cisco Security Technical Alliances, New Program for Ecosys...
CSS 17: NYC - The AWS Shared Responsibility Model in Practice
Managed Threat Detection and Response
#ALSummit: Alert Logic & AWS - AWS Security Services
Cisco Security Technical Alliance
Extending Amazon GuardDuty with Cloud Insight Essentials
Ad

Similar to Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat responses in Azure through Logic Apps (20)

PDF
Azure Sentinel Tips
PPTX
Modernize your Security Operations with Azure Sentinel
PPTX
Azure Sentinel with Office 365
PPTX
Azure Sentinel Jan 2021 overview deck
PDF
L400-P1 Overview.pdf
PPTX
Microsoft Sentinel and Its Components.pptx
PPTX
Azure Sentinel.pptx
PDF
Planning and implementing. Unveiling the advanced technology of Microsoft Azu...
PDF
Microsoft Azure Sentinel
PPTX
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
PPTX
TechTalksUtah-Sentinel-20191108.pptx
PDF
Introduction to Azure Sentinel
PPTX
NVS_Sentinel
PPTX
SEIM-Microsoft Sentinel.pptx
PDF
introduction to Azure Sentinel
PPTX
Azure Sentinel
PDF
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
PDF
7 Experts on Implementing Azure Sentinel
PDF
Gill C. Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 2...
PDF
Microsoft Sentinel- a cloud native SIEM & SOAR.pdf
Azure Sentinel Tips
Modernize your Security Operations with Azure Sentinel
Azure Sentinel with Office 365
Azure Sentinel Jan 2021 overview deck
L400-P1 Overview.pdf
Microsoft Sentinel and Its Components.pptx
Azure Sentinel.pptx
Planning and implementing. Unveiling the advanced technology of Microsoft Azu...
Microsoft Azure Sentinel
07 - Defend Against Threats with SIEM Plus XDR Workshop - Microsoft Sentinel ...
TechTalksUtah-Sentinel-20191108.pptx
Introduction to Azure Sentinel
NVS_Sentinel
SEIM-Microsoft Sentinel.pptx
introduction to Azure Sentinel
Azure Sentinel
SBA Security Meetup - Deploying and managing azure sentinel as code by Bojan ...
7 Experts on Implementing Azure Sentinel
Gill C. Configuring Windows Server Hybrid Advanced Services Exam Ref AZ-801 2...
Microsoft Sentinel- a cloud native SIEM & SOAR.pdf
Ad

More from azuredayit (14)

PDF
Azure Day Rome Reloaded 2019 - ML.NET Model Lifecycle with Azure DevOps
PDF
Azure Day Rome Reloaded 2019 - Reactive Systems with Event Grid
PDF
Azure Day Rome Reloaded 2019 - Building serverless microservices in azure
PDF
Azure Day Rome Reloaded 2019 - Cloud Journey – FastTrack for Azure
PDF
Azure Day Rome Reloaded 2019 - Azure: a cloud with a purpose
PDF
Azure Day Rome Reloaded 2019 - Getting Started with Unity, AR/VR and Azure Co...
PDF
Azure Day Rome Reloaded 2019 - Azure Application Insights Overview
PDF
Azure Day Rome Reloaded 2019 - Deconstructing Kubernetes using AKS
PDF
Azure Day Rome Reloaded 2019 - Python, Azure Cosmos DB, Docker and Azure Cont...
PDF
Azure Day Rome 2019 Reloaded - Strangle(r pattern) your legacy application ru...
PDF
Azure Day Rome 2019 Reloaded - Effettuare il provisioning su Azure utilizzand...
PDF
Azure Day Rome 2019 Reloaded - Utilizzare Azure Kubernetes Service per i nost...
PDF
Azure Day Rome Reloaded 2019 - Ingestion nel datalake passando tramite API Ma...
PDF
Azure Day Rome Reloaded 2019 - Azure Cognitive Search Deep Dive
Azure Day Rome Reloaded 2019 - ML.NET Model Lifecycle with Azure DevOps
Azure Day Rome Reloaded 2019 - Reactive Systems with Event Grid
Azure Day Rome Reloaded 2019 - Building serverless microservices in azure
Azure Day Rome Reloaded 2019 - Cloud Journey – FastTrack for Azure
Azure Day Rome Reloaded 2019 - Azure: a cloud with a purpose
Azure Day Rome Reloaded 2019 - Getting Started with Unity, AR/VR and Azure Co...
Azure Day Rome Reloaded 2019 - Azure Application Insights Overview
Azure Day Rome Reloaded 2019 - Deconstructing Kubernetes using AKS
Azure Day Rome Reloaded 2019 - Python, Azure Cosmos DB, Docker and Azure Cont...
Azure Day Rome 2019 Reloaded - Strangle(r pattern) your legacy application ru...
Azure Day Rome 2019 Reloaded - Effettuare il provisioning su Azure utilizzand...
Azure Day Rome 2019 Reloaded - Utilizzare Azure Kubernetes Service per i nost...
Azure Day Rome Reloaded 2019 - Ingestion nel datalake passando tramite API Ma...
Azure Day Rome Reloaded 2019 - Azure Cognitive Search Deep Dive

Recently uploaded (20)

PDF
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
PPTX
assetexplorer- product-overview - presentation
PPTX
Patient Appointment Booking in Odoo with online payment
PPTX
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
DOCX
How to Use SharePoint as an ISO-Compliant Document Management System
PPTX
CNN LeNet5 Architecture: Neural Networks
PPTX
Oracle Fusion HCM Cloud Demo for Beginners
PDF
Salesforce Agentforce AI Implementation.pdf
PDF
Wondershare Recoverit Full Crack New Version (Latest 2025)
PPTX
Computer Software - Technology and Livelihood Education
DOCX
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
PPTX
Trending Python Topics for Data Visualization in 2025
PPTX
"Secure File Sharing Solutions on AWS".pptx
PPTX
Advanced SystemCare Ultimate Crack + Portable (2025)
PPTX
Cybersecurity: Protecting the Digital World
PDF
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
PDF
MCP Security Tutorial - Beginner to Advanced
PDF
Autodesk AutoCAD Crack Free Download 2025
PPTX
Weekly report ppt - harsh dattuprasad patel.pptx
PPTX
Why Generative AI is the Future of Content, Code & Creativity?
Top 10 Software Development Trends to Watch in 2025 🚀.pdf
assetexplorer- product-overview - presentation
Patient Appointment Booking in Odoo with online payment
Log360_SIEM_Solutions Overview PPT_Feb 2020.pptx
How to Use SharePoint as an ISO-Compliant Document Management System
CNN LeNet5 Architecture: Neural Networks
Oracle Fusion HCM Cloud Demo for Beginners
Salesforce Agentforce AI Implementation.pdf
Wondershare Recoverit Full Crack New Version (Latest 2025)
Computer Software - Technology and Livelihood Education
Modern SharePoint Intranet Templates That Boost Employee Engagement in 2025.docx
Trending Python Topics for Data Visualization in 2025
"Secure File Sharing Solutions on AWS".pptx
Advanced SystemCare Ultimate Crack + Portable (2025)
Cybersecurity: Protecting the Digital World
How AI/LLM recommend to you ? GDG meetup 16 Aug by Fariman Guliev
MCP Security Tutorial - Beginner to Advanced
Autodesk AutoCAD Crack Free Download 2025
Weekly report ppt - harsh dattuprasad patel.pptx
Why Generative AI is the Future of Content, Code & Creativity?

Azure Day Rome Reloaded 2019 - Azure Sentinel: set up automated threat responses in Azure through Logic Apps

  • 1. Azure Sentinel: set up automated threat responses in Azure through Logic Apps
  • 3. AGENDA • Azure Sentinel main features • Respond to incidents rapidly with built-in orchestration and automation • DEMO
  • 5. Too many disconnected products 76% report increasing security data* 3.5M unfilled security jobs in 2021 Lack of automation 44% of alerts are never investigated IT deployment & maintenance Sophistication of threats Security operations challenges
  • 6. Introducing Azure Sentinel intelligent, cloud-native SIEM Uses AI and automation to improve effectiveness Scales to support your growing digital estate Delivers instant value to your defenders
  • 7. End-to-end solution for security operations Analytics DetectCollect Incidents AutomationVisibility Hunting Investigate Respond Powered by community + backed by Microsoft’s security experts
  • 9. Collect security data at cloud scale from any source
  • 10. Use workbooks to power interactive dashboards Choose from a gallery of workbooks Customize or create your own workbooks using queries Take advantage of rich visualization options Gain insight into one or more data sources
  • 12. Leverage analytics to detect threats Choose from more than 100 built-in analytics rules Customize and create your own rules using KQL queries Correlate events with your threat intelligence and now with Microsoft URL intelligence Trigger automated playbooks
  • 13. Tap into the power of ML increase your catch rate without increasing noise Use built–in models – no ML experience required Detects anomalies using transferred learning Fuses data sources to detect threats that span the kill chain Simply connect your data and learning begins Bring your own ML models (coming soon)
  • 15. Start hunting over security data with fast, flexible queries Run built-in threat hunting queries - no prior query experience required Customize and create your own hunting queries using KQL Integrate hunting and investigations
  • 16. Use bookmarks and live stream to manage your hunts Bookmark notable data Start an investigation from a bookmark or add to an existing incident Monitor a live stream of new threat related activity
  • 17. Use Jupyter notebooks for advanced hunting Run in the Azure cloud Save as sharable HTML/JSON Query Azure Sentinel data Bring external data sources Use your language of choice - Python, SQL, KQL, R, …
  • 19. Start and track investigations from prioritized, actionable security incidents Use incident to collect related alerts, events, and bookmarks Manage assignments and track status Add tags and comments Trigger automated playbooks
  • 20. Visualize the entire attack to determine scope and impact Navigate the relationships between related alerts, bookmarks, and entities Expand the scope using exploration queries View a timeline of related alerts, events, and bookmarks Gain deep insights into related entities – users, domains, and more
  • 22. Automate and orchestrate security operations using integrated Azure Logic Apps Build automated and scalable playbooks that integrate across tools Choose from a library of samples Create your own playbooks using 200+ built-in connectors Trigger a playbook from an alert or incident investigation
  • 23. Example playbooks Assign an Incident to an Analyst Open a Ticket (ServiceNow/Jira) Keep Incident Status in Sync Post in a Teams or Slack Channel Lookup Geo for an IP Trigger Defender ATP Investigation Send Validation Email to User Block an IP Address Block User Access Trigger Conditional Access Isolate Machine Incident Management Enrichment+ Investigation Remediation
  • 24. Community Hundreds of contributions, including data connectors, workbooks, analytics rules, queries, notebooks, parsers, functions, and playbooks are available on GitHub.
  • 25. Take actions today—Get started with Azure Sentinel To learn more, visit https://aka.ms/AzureSentinel Create Azure Sentinel instance Connect data sources Start Microsoft Azure trial