Hybridbrothers.com

Defender for Identity NNR and health monitoring

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Actived: 2 days ago

URL: https://hybridbrothers.com/mdi-nnr-health/

Operationalizing MITRE ATT&CK to support Microsoft Sentinel …

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors are …

Category:  Health Go Health

Mapping MDE and Windows Security Events overlap

WEBWhat we have learned during this post is that there are some overlaps of data in both MDE and Windows Security Events. This means that enabling both MDE …

Category:  Health Go Health

Demystifying Data Collection Rules and Transformations

WEBData Collection Rules are Azure resources that define the data collection process in Azure Monitor. It defines the details of a particular data collection scenario …

Category:  Health Go Health

From hybrid / fully joined devices to Entra ID

WEBIn this blog post, I wanted to talk about how adversaries can use Entra ID Joined or Hybrid Joined devices to move laterally to the cloud, using EntraID SSO …

Category:  Health Go Health

Using Managed Identities in Logic App HTTP triggers

WEBEnable Managed Identity. Before we proceed, we will need to enable a Managed Identity for the Logic App that will be sending requests to the HTTP Endpoint. …

Category:  Health Go Health

Robbe Van den Daele

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Category:  Health Go Health

Using WDAC to ingest missing MDE events and detect token …

WEBHere we need to remove all pre-populated rules, and create a new one: Create a new deny FilePath rule for MicrosoftAccountTokenProvider.dll in usermode. …

Category:  Health Go Health

Microsoft Sentinel

WEBIntroduction Defender for Identity is a very important sensor to detect threats in an Active Directory environment. Therefore, it is important to make sure the sensors …

Category:  Health Go Health

Deploy sentinel analytic rules with bicep and PowerShell

WEBThe deploy-rules.bicep file is eventually the file where analytic rules get deployed. Below you find the steps of the bicep file: We first read the parameters for the …

Category:  Health Go Health

AitM detection with Sentinel via custom CSS

WEBBelow you find the CSS file I used to trigger the Logic App. Once you have this CSS file, you need to upload the file in the portal by going to Company branding > …

Category:  Health Go Health

Ghost blogging on Azure Container Apps

WEBAnd finally the compute side, the Container App Environment and the App itself. At this moment we use the Ghost image directly from the Docker Hub registry, for …

Category:  Health Go Health

Get control over corporate networks with device discovery

WEBDevice Discovery. Device Discovery is a feature in Defender for Endpoint that helps you discover unmanaged devices on your corporate networks without the …

Category:  Health Go Health