Hybridbrothers.com

Operationalizing MITRE ATT&CK to support Microsoft Sentinel …

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors are …

Actived: 4 days ago

URL: https://hybridbrothers.com/operationalizing-mitre-att-ck-to-support-microsoft-sentinel-deployments-and-detections/

Defender for Identity NNR and health monitoring

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Category:  Health Go Health

From hybrid / fully joined devices to Entra ID

WEBIn this blog post, I wanted to talk about how adversaries can use Entra ID Joined or Hybrid Joined devices to move laterally to the cloud, using EntraID SSO …

Category:  Health Go Health

Deploy sentinel analytic rules with bicep and PowerShell

WEBThe deploy-rules.bicep file is eventually the file where analytic rules get deployed. Below you find the steps of the bicep file: We first read the parameters for the …

Category:  Health Go Health

Demystifying Data Collection Rules and Transformations

WEBData Collection Rules are Azure resources that define the data collection process in Azure Monitor. It defines the details of a particular data collection scenario …

Category:  Health Go Health

Using Managed Identities in Logic App HTTP triggers

WEBEnable Managed Identity. Before we proceed, we will need to enable a Managed Identity for the Logic App that will be sending requests to the HTTP Endpoint. …

Category:  Health Go Health

Mapping MDE and Windows Security Events overlap

WEBTo create the MDE mapping, I use the following commands: # Microsoft Defender for Endpoint layer techniques = get_mitre_techniques_by_filter …

Category:  Health Go Health

Using WDAC to ingest missing MDE events and detect token …

WEBHere we need to remove all pre-populated rules, and create a new one: Create a new deny FilePath rule for MicrosoftAccountTokenProvider.dll in usermode. …

Category:  Health Go Health

Microsoft Sentinel

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Category:  Health Go Health

Robbe Van den Daele

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Category:  Health Go Health

AitM detection with Sentinel via custom CSS

WEBBelow you find the CSS file I used to trigger the Logic App. Once you have this CSS file, you need to upload the file in the portal by going to Company branding > …

Category:  Health Go Health

Get control over corporate networks with device discovery

WEBDevice Discovery. Device Discovery is a feature in Defender for Endpoint that helps you discover unmanaged devices on your corporate networks without the …

Category:  Health Go Health