Skip to main content

Posts

Showing posts with the label Azure

Microsoft Sentinel : KQL extend operator

Used to extend the current dataset to columns as per the requirement. In this example, a new column named “ BootSince_newColumn ” is added to the output using the extend operator. This new variable calculates the time difference since boot time and now.   The output shows the newly added column  BootSince_newColumn with the value 2342, which is the number of hours since the boot time. For a more commonly applicable real world example, extend operator can be used to calculate the number of days since the last login date.

Microsoft Sentinel : KQL project operator

Project operator is used to customize the query result output as per your needs. This doesn't remove or modify any logs. It only affects how it is presented for that particular query, for that particular run. To keep only one particular column details instead of all available columns. If you wish to remove only a column and keep all other available columns, then use project-away   project-rename option can be used to rename the column name. Here in this example, the column with name "Computer" is renamed to "device". To reorder the columns, use project-reorder To summarize, Operator Description project Determines the columns to include, rename, or drop, and insert new computed columns. project-away Determines which columns from the input should be excluded from the output. project-keep Determine what columns from the input to keep in the output using a column name pattern match. project-rename Renames columns in the output project-reorder Reorder columns in the ...

Microsoft Sentinel : KQL search query with examples

Search operator To search for all logs that contain a particular keyword. This is useful when you are unsure about a table. search “keyword” And, or combining with the search operator. search “admin” and “login” search “admin” and (“login” or “logout”) To search only on particular tables. search in (SigninLogs ,SecurityEvent) "failed" Typically the search is case insensitive. To Search with case sensitive, use search kind=case_sensitive “admin” Lets try another case sensitive search, Return no result as intended. We can also use wildcards (*) if we are unsure about the exact table name. Performing more granular search. Look for particular keywords in specific columns in a table. search UserName contains “admin” or UserName contains “admin”

Free resources to learn Kusto Query Language (KQL) for Microsoft Sentinel

  Free resources to learn Kusto Query Language (KQL) for Microsoft Sentinel 1) Must learn KQL This repository from Rod-Trent contains the code, queries, and a free eBook included as part of the Must Learn KQL series.There is also a YouTube playlist related to this.  https://github.com/rod-trent/MustLearnKQL 2) Udemy: Learn KQL for Microsoft Sentinel An Udemy free course created by Samik Roy, designed to refresh your KQL learning and help you to boost your application for Sentinel   https://www.udemy.com/course/learn-kql-for-microsoft-sentinel/ 3) SC-200: Create queries for Microsoft Sentinel using Kusto Query Language (KQL) Microsoft Learn path. Write Kusto Query Language (KQL) statements to query log data to perform detections, analysis, and reporting in Microsoft Sentinel. This learning path will focus on the most used operators. The example KQL statements will showcase security related table queries.   https://learn.microsoft.com/en-us/training/paths/sc-200-u...

Ingest Data in Microsoft Sentinel

After deploying Sentinel by creating/assigning a Log Analytics Workspace, next phase is to ingest logs in to Log Analytics Workspaces using data connectors. Data connectors are used to get logs from various sources. This includes the cloud native sources as well as third party sources. Microsoft Sentinel Content hub enables you to discover and install out of the box solutions for Sentinel. This solution is like a package that includes analytics rules, data connectors, playbooks etc pertaining to that particular product or solution. So, when a solution is deployed from the content hub, these associated components will also get installed. If the entire contents are not required then we can opt for a stand-alone content source. Lets install Microsoft Entra ID solution from Content hub. Click on Install. We can see, there are 64 analytics rules, 1 data connector, 11 playbooks and 2 workbooks in this solution. Click on Manage to configure. We can click on each content and configure separate...

Log Analytics Workspace and Microsoft Sentinel

Log Analytics workspaces is a type of Azure service where the logs can be collected and stored for analysis and retention. Logs from various sources can be piped to the Log Analytics Workspace and it is one of the crucial components for Microsoft Sentinel. Log Analytics Workspace serves as the centralised repository for the logs. The logs are piped using connectors and agents. A retention policy can be set on Log Analytics workspace for compliance requirements. The logs are then used for analysis using Kusto Query Language (KQL). KQL helps to query, filter data to identify patterns, anomalies and potential threats in the environment. In addition to log storage, Log Analytics workspaces offers dashboards and data visualisation options using queries and metrics. Log Analytics can be integrated with Microsoft Sentinel and with Microsoft Defender for Cloud. Sentinel utilises the data stored in Log Analytics workspaces to perform analysis, threat detection, threat hunting and for incident i...

About Microsoft Sentinel

A Security Operations Centre is a centralised unit that monitors traffic, triage alerts, participates in incident response, perform threat hunting and often performs vulnerability assessments. The individuals who work in a SOC are often referred to as SOC analysts. When it comes to Microsoft Azure SOC, the analysts work predominantly on Microsoft Security, Compliance and identity products and solutions such as Microsoft 365, Defender for Cloud, Microsoft 365 Defender, Sentinel etc. Let's go through the top two products that are critical for a SOC. SIEM and SOAR. A SIEM or Security Information and Event Management provides a centralised management and a holistic view of all events happening in the organisation by collecting and analysing logs from different sources across. SIEM uses correlation to detect anomalies and create alerts based on the conditions. Whereas a SOAR or Security Orchestration Automation and Response helps to handle incidents efficiently and automatically by inte...

Microsoft best practices for ransomware protection

Microsoft best practices for ransomware protection 1) Prepare your recovery plan   This is the first phase, planning your recovery in the event of a ransomware attack. This will help the organization in limiting the damage and handle the situation efficiently and reduce the monetary loss. Ensure procedure to make accessing and disrupting the systems harder.   Identify and categorize your business-critical systems and apply best practices. Ensure that you have a working backup. For this make use of the Azure Backup services. It also provides built-in monitoring and alerting capabilities to view and configure actions for events related to Azure Backup. Make sure to implement steps to protect the integrity of the backup, implement principle of least privilege and adding an extra layer of authentication for critical operations, you're prompted to enter a security PIN before modifying online backups.   2) Limit the scope of the damage   Assume breach scenario. In the even...

Adobe Flash EOL and Microsoft Update KB4577586

Adobe stopped supporting Flash Player beginning December 31, 2020. After this data, Adobe will not release new Flash Player updates or security patches and strongly recommends the users to uninstall Flash Player immediately from their machines. To help secure your system, major browser vendors have already disabled Flash Player from running. As part of the end of support for Adobe Flash, KB4577586 is now available as an optional update from Windows Update (WU) and Windows Server Update Services (WSUS). Installing KB4577586 will remove Adobe Flash Player permanently from your Windows device. Once installed, you cannot uninstall KB4577586 . This update only removes Adobe Flash Player that was installed by your version of Windows. If you installed Adobe Flash Player manually from another source, it will not be removed.  Ref : https://support.microsoft.com/en-us/topic/kb4577586-update-for-the-removal-of-adobe-flash-player-october-27-2020-931521b9-075a-ce54-b9af-ff3d5da047d5

What is BitLocker To Go and BitLockerAutoUnlock?

BitLocker To Go is BitLocker Drive Encryption on removable data drives. This includes the encryption of USB flash drives, SD cards, external hard disk drives, and other drives formatted by using the NTFS, FAT16, FAT32, or exFAT file systems.As with BitLocker, drives that are encrypted using BitLocker To Go can be opened with a password or smart card on another computer by using BitLocker Drive Encryption in Control Panel. BitLockerAutoUnlock can be configured to automatically unlock volumes that do not host an operating system. After a user unlocks the operating system volume, BitLocker uses encrypted information stored in the registry and volume metadata to unlock any data volumes that use automatic unlocking.   Read more on Microsoft 365 and Azure Source : https://docs.microsoft.com/en-us/windows/security/information-protection/bitlocker/bitlocker-overview

How to Integrate Microsoft Office 365 Threat Intelligence and Windows Defender ATP?

From the Security & Compliance admin center (https://protection.office.com) , select Threat management, and then select Explorer. From the upper righer corner, click on MDE settings ( As highlighted in the image below). Then in the Microsoft Defender ATP connection dialog box, turn on Connect to Windows ATP. Note: To turn on this connection, your organization must have a Microsoft Defender for Endpoint subscription and security analysts must have access to Defender for Office 365 P2 and Microsoft Defender for Endpoint.  

Azure Information Protection (AIP) classic client and Label Management in the Azure Portal are being deprecated as of March 31, 2021

As per recent announcement from Microsoft, with label management in the Microsoft 365 compliance center now at parity with the AIP portal experience, Microsoft will sunset label management in the Azure portal as of March 31, 2021.Means, Azure Information Protection classic client and Label Management in the Azure Portal will be deprecated on March 31, 2021.     Step by step guide to transition to MIP If you are an existing AIP customer, Microsoft recommends the following steps to transition to MIP: Activate unified labeling from the Azure portal and migrate labels to the Microsoft 365 compliance center to apply policies uniformly across on-premises, Microsoft 365 cloud services and more. This transition has no impact on existing AIP clients, and administrators can perform this step right away. The process takes only a few minutes, depending on the number of labels and complexity  Copy the policies to the Microsoft 365 compliance center or create new policies there....

Azure Cloud Security # Consolidated Notes and Documentations.

Consolidated list of documentations and tutorials related to Microsoft Azure Cloud Security. Can be used to perform a deep dive on Azure security and for the preparation of Azure Security certification. Feel free to share. Happy learning. Preparation Notes Microsoft Azure Services #Index Scaling Up/Vertical Scaling vs Scaling Out/Horizontal Scaling. What are Azure availability sets? Difference between Azure management groups, Subscriptions and Resource groups Azure Active Directory : Overview. Azure Active Directory User Types and RBAC built-in roles Azure Active Directory User Source of Authority (SoA) Application Registration in Azure Active Directory Azure Active Directory Identity Protection. Azure AD Connect Overview. Azure Front Door : Overview. Hardening your Azure cloud platform and best practices.   Security Documentation Glossary. Azure Well-Architected Framework Introduction to Azure security Azure security documentation Using customer-managed keys in Azure Key Vault w...

Azure Front Door : Overview #CloudScribblings

Azure Front Door is a combination of Load-balancer and Web Application Firewall (WAF). It is a routing service that helps to accelerate the application access availability and performance and works at the Application layer. Azure Front Door service can be considered when you have a pool of application servers at the back-end and you need to load-balance the client requests and enhance the security. When you implement this service, it will route the client requests to the fastest and most available application back-end. These requests can be distributed to the back-end pool based on Weight-age and Priority. Azure Front Door service features, 1) URL based routing 2) Maintaining session affinity 3) SSL termination 4) Web Application Firewall Features. You can configure Azure Front Door in three steps. Search Front Door service from your Azure dashboard. 1) Add the front-end hosts / Domain name. Configure the front-end URL. User requests will hit here. You can enable affinity and WAF at th...

Azure Active Directory : Overview #CloudScribblings

Azure Active Directory is an Identity store in the Cloud. You can create users,groups and service principles in the Azure AD. When you create an Azure account, an Azure AD directory is automatically created by default. You mention all your identities in the directory and is used to authenticate and authorize the users to access a resource in the Azure Cloud. If you want to drill-down the access permission, then you can make use of Role Based Access Control (RBAC) which is different from the Azure AD roles.Using Azure AD, you can enable a lot of security features for authentication & authorization such as Multi-Factor Authentication (MFA), Conditional Access, Privileged Identity Management (PIM) etc. When it comes to billing, Azure AD is different from your Subscription billing. Normally all your resource usage will be billed against your subscription. But for Azure AD, you need to purchase the license separately from Microsoft Office 365 portal using a Work/school account. The l...

Azure AD Connect Overview #CloudScribblings

The Azure AD Connect synchronization service is used to synchronize identity data between your on-premise environment and Azure Active Directory. There are two components for this service Azure AD Connect sync component – This is installed on the on-premise environment, recommended to be installed on a domain joined separate server and not on AD server directly. Azure AD Connect sync service – This service runs in Azure AD. Prerequisites for Configuring the Azure AD connect. An Azure AD tenant You need to add and verify your domain in Azure AD The Azure AD Connect sync component must be installed on a Windows Server 2012 Standard or later (On-Premises). The server must have the full GUI installed. The server must be domain joined.Recommended no to install in the AD DC server directly. The Azure AD Connect sync component requires a SQL Server database for storing identity data. By default , the installation of Azure AD Connect will install SQL Server 2012 Express LocalDB.During the conf...

Azure Active Directory Identity Protection #CloudScribblings

Azure Active Directory Identity Protection is used to , Automate the detection of any identity-based risks. It can also be used to investigate any risks to using reports data in the portal It can be used to expose risk detection data to third-party utilities for further analysis. Also possible to auto remediate the risks To use this feature fully fledged, Azure AD Premium P2 license is required. The tool can detect the following risk factors, Leaked credentials - If a user's credentials are leaked , AD Identity protection can get the intelligence and block the access. Sign-ins from anonymous IP addresses - These are user sign-ins that are originated from an IP address that has been identified as an anonymous proxy IP address or VPN. Logins from atypical locations - User sign-in occurs from geographically distant locations, where at least one of the locations may also be atypical for the user. For example, the user is login from New York and in the next hour another login request...

Application Registration in Azure Active Directory #CloudScribblings

When you register an application in Azure AD , you need to specify the application details and the permission details that the application should have when it access the Azure Services. The application can authenticate through the Microsoft Identity platform. The Microsoft Identity platform uses OAuth 2.0 authorization service that enables a third-party application to access web-hosted resources. Once the application object is registered in Azure AD, it is called as a service principle. When you register an application in Azure AD, you need to keep note of two things. 1) Application or Client Identity. 2) Directory or Tenant ID. These ID's are automatically generated during the application registration. Normally, these two information are required to be specified at the application end. After the registration, you may required to generate a client secret and that can be done from the AD -> Certificates & Secrets section. Note that once the secret is generated, you must copy ...

Azure Active Directory User Source of Authority (SoA) #cloudscribblings

Source of Authority (SoA) describes where the user is primarily defined. This can be classified in to four categories. A user can be defined in, 1) Azure Active Directory This is a native cloud user account also known a member. 2) External Azure Active Directory Invited user from another azure tenant. If you invite a user from another tenant to your tenant, the user's SoA will be External Azure Active Directory. 3) Microsoft Account A person who creates the subscription (Subscription owner) with a Microsoft account (live, hotmail etc) will have the SoA of Microsoft Account. 4) Local Active Directory Synchronized user accounts with an on-premises Active directory will have the SoA of Local Active Directory.

Azure Active Directory User Types and RBAC built-in roles #CloudScribblings

Azure Active Directory has two types of Users. 1) Member A member is a normal cloud user. An Active Directory member can read all directory information and can invite external users. They can also manage their own profile information and can register applications in the AD. 2) Guest Restricted user  who can manage only their own profile data. Cannot browse the directory and cannot register applications in the AD. RBAC built-in roles (Top 4) Owner Role : Lets you manage everything, including access to resources.The owner can add permission, perform actions such as delete, stop the resources. Contributor Role : This role allows a user to manage all types of resources, but does not allow the user to grant access to resources.To allow a user to have the ability to grant access to resources, the user must be assigned with either the User Access Administrator Role or the Owner Role User Access Administrator Role : In this role, the user can manage the access to resources. The user woul...