Download - Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Transcript
Page 1: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Azure Sentinel

Use Cases

Page 2: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Overview

• In this module you will learn

where Azure Sentinel can be

used.

Pre-

requisites

• Azure Sentinel Overview

module.

Page 3: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Sentinel use cases and value proposition

Page 4: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Log

management

Detection

Single pane

of glass

Alert

handling

Investigation

& hunting

Incident

management

Response

Page 5: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Traditional SIEMReal time correlation

Ingest time parsing

Search based SIEMScheduled queries

Query time parsing

Page 6: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

• Auto-scales

• Easy collection from cloud sources

• Avoid sending cloud telemetry downstream

• Key log sources are free

No brainer Advantages

• DevOps deployment and enforcement

• Distributed

• Cloud native-schema

But there is more!

• The cloud security team

Use

• Side by side deployment with current SIEM

Requirements

Cloud SIEM

Page 7: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

“Azure Sentinel works

seamlessly with Office 365

and other Azure services and

security tools. Compared to

other SIEMS I have used, it’s

much easier to connect our

data sources to Azure

Sentinel. There are built-in

connectors not just for

Microsoft but also for other

major security vendors.”

Jay Vaidya

Senior Security Analyst, Brewin Dolphin

Page 8: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

AP

Is • Graph

Security API

• Management

• Data ingest

• Data queryD

ep

loym

en

t

• ARM

• DevOps

integration

• Azure policy Serv

ele

ss • Logic Apps

• Azure

functions

• Lambda

functions….

X

Page 9: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 10: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Upstream

Downstream

Events Alerts

Page 11: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 12: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

• Effortless infinite scale

• Ease of integration

• Effective and integrated SOAR

• Microsoft research and ML

• SIEM and data lake in one

Advantages

• SIEM replacement

Use

• On prem-collection

Requirements

Next Gen SIEM

Page 13: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

▪ $1B

Page 14: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 15: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 16: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

(Optional)

Collector

Proxy

OS events, DNS, Windows FW, DHCP

agent agent

CEF or Syslog

connector

Syslog (TLS, TCP, UDP)

Branch Office

CEF/Syslog

connector

WEF

Connector

HTTPS

WEC

Logstash

Custom

Connectors

Page 17: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

• Easy collection from cloud sources.

Advantages

• Cost prohibitive.

*No* Opportunity

• Stream events to on-prem SIEM.

Requirements

Cloud Collector

Page 18: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Pricing

Page 19: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to

Annual ingress: GB/d x 365

Price per GB: $2.53 + $0.1 Add Months

Total annual cost: Annual ingress x Price per GB

Page 20: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 21: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to
Page 22: Azure Sentinel Use Cases...“Azure Sentinel works seamlessly with Office 365 and other Azure services and security tools. Compared to other SIEMS I have used, it’s much easier to