Blue Square Security

Microsoft Sentinel w/ Lightstream_Ep. 7

June 22, 2023 Greg Wartes, David Driggers, Michael Vitale Season 1 Episode 7
  • Ep. 7:   Sentinel with Microsoft partner Lightstream.  
  • Introductions: Lightstream 
  • SEIM:  Collection > Detection > Investigation > Response 
  • Investigation:  trends, fine tuning SEIM, SOC teams, funding 
  • Automation:  Playbooks, AI, Co-Pilot, does not replace Tier 1
  • Attack surface 
  • Bookmarks 
  • Multi-Cloud 
  • Defender for Threat Intelligence 
  • Ingestion:  log collection, Frameworks, garbage in-garbage out
  • Detection:  dwell time, risk based alerting patterns
  • Light Stream Azure Health Check:  Security focused, strengthen security posture, documentation,  roadmap for success