Mastering Microsoft Sentinel Playbooks for Enhanced Security
Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) platform. Being in the cloud, it is heavily scalable. With Sentinel, security…
Passed CCAK Exam: Certificate of Cloud Auditing Knowledge Guide
Companies are rapidly migrating workloads from data centers to the cloud, leveraging technologies such as serverless computing, containers, AI, and machine learning to achieve greater efficiency, improved scalability, and faster…
Optimize Costs Using Ingestion-Time Transformation for Fortinet Logs in Microsoft Sentinel
Updated — 01/04/2025 — Starting 1 May 2025, Microsoft will begin billing for queries and search jobs on logs ingested into the Auxiliary Logs plan. Querying Auxiliary Logs will be…
Effective Approach To Collect Linux Logs to Microsoft Sentinel
Centralized logging is crucial for effectively managing Linux systems. Organizations can streamline their log management processes by using tools like Rsyslog/Syslog-ng and integrating with platforms like Microsoft Sentinel. This approach…
Automate Stop and Start of Azure Firewall for Efficiency
Azure Firewall is a managed stateful firewall that works from the Open Systems Interconnection (OSI) Layer 3 to Layer 7 perspective. It is an excellent PaaS service, but it is…
Effective Solution To Monitor Data Connectors in Microsoft Sentinel
Like all SIEM systems, the Microsoft Sentinel SIEM/XDR product relies heavily on the consistent flow of logs and data from relevant security sources. A typical Microsoft Sentinel workspace can include…
Azure Storage Actions Deep Dive
Updated – 07/05/2025 – Microsoft announced the general availability of Azure Storage Actions, a fully managed platform that transforms how organizations automate data management tasks for Azure Blob and Data…
System Center 2025 Features
With the general availability of Windows Server 2025, Microsoft also released System Center 2025, which introduces updates that reflect a shift in IT infrastructure management and security. These changes align with current…
Set Device Extension Attributes in Microsoft Entra ID
Extension attributes in Microsoft Entra ID provide a powerful method to add custom details to objects, including devices, in your tenant. They allow you to store unique data about each…
Effective Approach To Collect Windows Firewall Events to Microsoft Sentinel
The built-in Windows Firewall is a great security feature for the Windows client and server operating systems. While not every organization actively uses Windows Firewall (they may have a third-party…
Update Microsoft Sentinel Workbooks Efficiently at Scale (In Bulk)
Microsoft Sentinel comes with Content Hub, which you can use out-of-the-box to get content value and start on Microsoft Sentinel quickly. Solutions in Microsoft Sentinel Content Hub provide a consolidated…
Integrating Defender EASM with Microsoft Sentinel Guide
Microsoft Defender External Attack Surface Management (EASM) provides organizations with a comprehensive view of their digital attack surfaces. It discovers known and unknown resources, from web pages to IP addresses…












