You might have heard of the North Sentinel Island in the middle of Bay of Bengal that hosts the most isolated tribe in the world. Despite several attempts to break in or contact the island, it was always defended violently by the natives and the island still remains untouched. It is considered to be one of the most secured places on planet earth guarded both by the local tribes and the government. When it came to naming the most powerful weapon in Azure cloud security arsenal, Microsoft have chosen the right name for it- Azure Sentinel.
You might have heard of the North Sentinel Island in the middle of Bay of Bengal that hosts the most isolated tribe in the world. Despite several attempts to break in or contact the island, it was always defended violently by the natives and the island still remains untouched. It is considered to be one of the most secured places on planet earth guarded both by the local tribes and the government. When it came to naming the most powerful weapon in Azure cloud security arsenal, Microsoft have chosen the right name for it- Azure Sentinel.
You might have heard of the North Sentinel Island in the middle of Bay of Bengal that hosts the most isolated tribe in the world. Despite several attempts to break in or contact the island, it was always defended violently by the natives and the island still remains untouched. It is considered to be one of the most secured places on planet earth guarded both by the local tribes and the government. When it came to naming the most powerful weapon in Azure cloud security arsenal, Microsoft have chosen the right name for it- Azure Sentinel.
What’s Azure sentinel under the hood?
- Azure Log Analytics Workspace and Azure Monitor for Collecting, Storing and analyzing log, Metrics and Telemetry data
- KQL(Kusto Query Language) to query and Interact with data
- Azure Logic Apps for running Logic workflows helps to schedule, orchestrate and automate tasks
- Azure Machine learning Studio for advanced supervised and unsupervised machine learning
- Azure Fusion for multistage attack detection
- Azure Workbooks for Visualization
- Many security features like Azure Security Center, DDOS protection, Advanced Threat protection, etc.
Azure natively provides a variety of features when it comes to data analysis and security, that includes by not limited to
Azure Sentinel Features
- Cost of Onboarding
- Ease of deployment
- Data Collection and Processing
- Data Analysis
- Threat Intelligence
- Machin Learning
- How to crack passwords
- User and Entity Behavior analysis
- Dashboards
- Reporting
When it comes to On-Prem SIEM Solutions, Deploying the solution to the network itself is a complex process that includes procuring and Provisioning hardware or VM, installing the host OS and necessary application, Licensing, setting up the networking, etc. Sentinel being a SaaS platform, deploying it is as easy as few clicks and couple of minutes of waiting for the solution to be deployed ready to use.
What’s Azure sentinel under the hood?
- Azure Log Analytics Workspace and Azure Monitor for Collecting, Storing and analyzing log, Metrics and Telemetry data
- KQL(Kusto Query Language) to query and Interact with data
- Azure Logic Apps for running Logic workflows helps to schedule, orchestrate and automate tasks
- Azure Machine learning Studio for advanced supervised and unsupervised machine learning
- Azure Fusion for multistage attack detection
- Azure Workbooks for Visualization
- Many security features like Azure Security Center, DDOS protection, Advanced Threat protection, etc.
Azure Sentinel Features
Let’s take a ride through the various features Sentinel provides in order to make it the newfound favorite in Security market. We will analyze the following Standard SIEM features provided by sentinel based on their availability and complexity.
- Cost of Onboarding
- Ease of deployment
- Data Collection and Processing
- Data Analysis
- Threat Intelligence
- Machin Learning
- How to crack passwords
- User and Entity Behavior analysis
- Dashboards
- Reporting
See also: