Working with Analytics rules Part 4 – Create Microsoft Security Rule

Introduction In this last post of the series, we will look at creating a Microsoft Security Analytics rule.  These are the ones that will raise an alert that has been generated from a different Azure security product.  As of right now, those products are: Azure Active Directory Identity Protection Microsoft Defender Advanced Threat Protection Azure […]

Working with Analytics rules Part 3 – Create Fusion / ML Rule

Introduction In the previous posts I spoke about the Azure Sentinel Analytics rule templates.   You may be wondering why I did that.  The reason is that in this post, I will be discussing creating  new Fusion and ML rules and in order to do that you need to have a rule template’s ID.  You will […]

Working with Analytics rules Part 2 – The rules

Introduction So far in this series, we have looked at the Rule templates.  Now we will look at the Analytics rules that we are currently using. Listing all the Analytic Rules Much like looking at the Analytic rule templates, we can make a REST call to look at all the rules we are using. The […]

Introduction to Azure Sentinel REST APIs

Microsoft has stated that they will be releasing the official version of the AzureSentinel APIs “soon”.   While they may not be official, the APIsare publishing on GitHub and, as far as I can tell, seem to be workingperfectly well.  This post will introduce you to the APIs and how to usethem using PowerShell. Why […]