Microsoft Security Operations Analyst flashcards
150 free flashcards. Tap a card to flip it.
Microsoft Sentinel Automation Rules
Flip cardA feature in Microsoft Sentinel that allows security teams to automate responses to incidents or alerts by defining conditions and actions.
- Can be triggered by incident creation or updates.
- Can run playbooks, suppress alerts, or change incident properties.
- Essential for streamlining incident response and reducing manual effort.
Memory trick: Automation rules are the 'traffic cops' for incidents, directing them to the right actions.
Microsoft Sentinel Data Residency
Flip cardThe requirement for an organization to store its data within specific geographic boundaries (e.g., a country or region) to comply with legal or regulatory obligations.
- Achieved by deploying Log Analytics workspaces in the desired Azure region.
- Resources must be configured to send data to the appropriate regional workspace.
- Crucial for compliance with regulations like GDPR.
Memory trick: Think of data residency like 'national borders' – data must stay within its assigned territory.
Azure Activity Data Connector
Flip cardA Microsoft Sentinel data connector that ingests subscription-level events and audit logs from Azure into a Log Analytics workspace.
- Collects administrative, service health, resource health, and security events.
- Essential for monitoring operations within Azure subscriptions.
- Supports connecting multiple subscriptions to a single Sentinel instance.
Memory trick: Connectors are the 'pipes' that bring data into Sentinel's 'brain'.
Kusto Query Language (KQL)
Flip cardA powerful, read-only query language used to explore, analyze, and visualize data in Azure Data Explorer and Azure Monitor Log Analytics, including Microsoft Sentinel.
- Used for analytics rules, hunting queries, workbooks, and interactive log searches.
- Designed for large datasets and time-series analysis.
- Features rich operators for filtering, aggregation, and joining data.
Memory trick: KQL is the 'universal translator' for all your Sentinel data questions.
Microsoft Sentinel Data Ingestion Cost
Flip cardThe primary cost component of Microsoft Sentinel, based on the volume of data ingested into the underlying Log Analytics workspace.
- Priced per GB ingested, with regional variations.
- Includes a small free tier (e.g., 5 GB/month).
- Can be optimized using data filtering, exclusion, and commitment tiers.
Memory trick: Think of data ingestion as a 'metered water supply' – you pay for what you use, minus a free sip.
Microsoft Sentinel Investigation Graph
Flip cardA visual tool within Microsoft Sentinel incidents that displays the relationships between different entities (users, hosts, IPs, etc.) and alerts involved in an incident.
- Helps analysts understand the scope and impact of an attack.
- Provides an interactive timeline and entity details.
- Facilitates pivoting between related entities for deeper analysis.
Memory trick: Think of the Investigation Graph as the 'detective's corkboard' where all clues are connected.
Microsoft Sentinel Incident Grouping
Flip cardA feature in Microsoft Sentinel analytics rules that controls how multiple alerts generated by a rule are combined into a single incident.
- Reduces alert fatigue and improves incident management efficiency.
- Can group alerts based on entities, custom fields, or all alerts into one.
- Configured within the 'Incident settings' section of an analytics rule.
Memory trick: Grouping is like putting all the related 'puzzle pieces' of an attack into one box.
Microsoft Sentinel Log Archiving
Flip cardThe process of moving older, less frequently accessed security logs from a Log Analytics workspace to a more cost-effective storage solution like Azure Blob Storage for long-term retention.
- Addresses compliance requirements for extended data retention.
- Significantly reduces storage costs compared to Log Analytics interactive retention.
- Archived data can be restored or queried using specific methods if needed.
Memory trick: Think of retention like a library: some books are on the active shelves (Log Analytics), others in deep storage (Blob Archive).
Microsoft Sentinel Scheduled Query Analytics Rules
Flip cardCustom detection rules in Sentinel that run a Kusto Query Language (KQL) query at specified intervals to identify security threats or anomalies.
- Offer flexibility for complex detection logic.
- Can aggregate data over a defined lookback period.
- Generate alerts and incidents based on query results.
Memory trick: Each rule type is a different 'detective' with a unique way of finding clues.
Microsoft Sentinel Playbooks (Logic Apps)
Flip cardAutomated, scalable, serverless workflows built on Azure Logic Apps that can be triggered by Sentinel incidents or alerts to perform response actions.
- Integrate with various services, including Microsoft Teams, ServiceNow, etc.
- Can perform complex actions like enriching incidents, blocking IPs, or sending notifications.
- Run automatically via Sentinel Automation Rules.
Memory trick: Playbooks are the 'robot assistants' that take action when an incident happens.
Azure Monitor Agent (AMA) for Sentinel
Flip cardThe unified agent for Azure Monitor that collects telemetry from Azure and non-Azure machines and sends it to Log Analytics workspaces, including for Microsoft Sentinel.
- Replaces the legacy Log Analytics agent (MMA).
- Uses Data Collection Rules (DCRs) for granular control over collected data.
- Required for modern Windows Security Events ingestion into Sentinel.
Memory trick: Think of AMA as the 'new postman' for your on-premise logs, delivering them to the cloud 'mailroom'.
Microsoft Sentinel Hunting Queries
Flip cardKusto Query Language (KQL) queries used by security analysts to proactively search for threats, anomalies, or suspicious activities within their ingested data, often leading to new detection rules.
- Designed for interactive and iterative exploration of data.
- Helps discover 'unknown unknowns' that automated rules might miss.
- Can be saved and shared as hunting queries or converted into analytics rules.
Memory trick: Think of it as a 'fishing expedition' – you're actively casting a net to see what you catch.
MDCAS Session Policies
Flip cardMDCAS Session Policies allow real-time control over user sessions in cloud apps, enabling actions like blocking uploads/downloads of sensitive data, or monitoring specific activities.
- Enforces control during an active session.
- Can block specific actions (e.g., upload, download, copy/paste).
- Integrates with Conditional Access App Control.
Memory trick: To control what happens *during* a session, you need a 'Session' policy, like a traffic cop for your cloud apps.
MDCAS Session Policy (Block & Redirect)
Flip cardA Microsoft Defender for Cloud Apps policy that allows real-time, granular control over user sessions with cloud applications, including blocking specific actions like downloads and redirecting users to alternative URLs.
- Operates in real-time during user sessions.
- Can block downloads of sensitive content.
- Can redirect users to approved services or URLs.
Memory trick: To control a live session, you need a 'session' policy; it's the only one that can redirect.
Advanced Hunting - IdentityLogonEvents
Flip cardThe IdentityLogonEvents table in Advanced Hunting contains information about user logon activities, including NTLM and Kerberos authentications.
- Records authentication type (NTLM, Kerberos).
- Includes source workstation, target server, and user details.
- Crucial for investigating credential theft and lateral movement.
Memory trick: To see who 'logged on' and how, check 'IdentityLogonEvents'.
Defender for Office 365 - Safe Attachments
Flip cardSafe Attachments is a feature in Microsoft Defender for Office 365 that provides zero-day protection to safeguard messaging systems from malicious attachments.
- Detonates attachments in a virtual environment.
- Can quarantine malicious attachments.
- Supports 'Dynamic Delivery' to deliver email body while scanning attachment.
Memory trick: Attachments need a 'Safe' place to be opened, links need to be 'Safe' before clicking.
MDE Security Recommendations (TVM)
Flip cardSecurity recommendations, part of Threat and Vulnerability Management (TVM) in MDE, identifies security misconfigurations and vulnerabilities on endpoints.
- Provides actionable recommendations to improve security posture.
- Tracks compliance against security baselines.
- Helps prioritize remediation efforts.
Memory trick: To know if you're 'secure' and 'compliant', you need 'recommendations' from TVM, not just a list of devices.
MDE Security Baselines
Flip cardA capability in Microsoft Defender for Endpoint that allows organizations to enforce and monitor security configurations on devices based on industry best practices (e.g., CIS benchmarks, Microsoft security baselines), identifying and recommending remediation for deviations.
- Ensures consistent security configurations across endpoints.
- Compares current configurations against predefined baselines.
- Provides recommendations to bring non-compliant devices into line.
Memory trick: Baselines keep endpoints in line.
AIR Automation Levels
Flip cardSettings in Microsoft Defender for Endpoint that define how much human intervention is required for automated investigation and remediation actions.
- Ranges from 'No automated remediation' to 'Full - remediate threats automatically'.
- Semi-full levels allow for approval processes based on severity or for all actions.
- Impacts the speed of response versus the need for human oversight.
Memory trick: Automation levels are like a robot's leash: short, long, or off.
MDCAS Activity Log
Flip cardThe Microsoft Defender for Cloud Apps Activity log provides a granular, searchable record of all user and admin activities performed across connected cloud applications.
- Captures a wide range of activities (logins, file access, downloads, admin actions).
- Centralized view across all monitored cloud apps.
- Essential for forensic investigations and auditing.
Memory trick: To see *everything* a user did, you need to check the full 'Activity Log', not just a summary or alerts.
Defender for Identity Exclusion Rules
Flip cardConfigurations within Microsoft Defender for Identity that allow specific entities (users, computers, or groups) to be excluded from certain detections to reduce false positives for legitimate activities.
- Reduces false positives.
- Targets specific entities or activities.
- Maintains detection for other entities.
Memory trick: Don't throw out the baby with the bathwater; exclude the noisy parts, keep the protection.
File Page (M365 Defender)
Flip cardA dedicated entity page in the Microsoft 365 Defender portal that provides aggregated intelligence and context for a specific file across the entire Defender ecosystem.
- Shows file reputation and global prevalence.
- Lists associated alerts, incidents, and observed behaviors.
- Helps determine if a file is malicious and its impact.
Memory trick: Entity Pages Provide Deep Dive Context.
KQL: IdentityLogonEvents for Kerberos
Flip cardThe `IdentityLogonEvents` table in Microsoft Defender XDR Advanced Hunting is the primary source for detailed information on Kerberos authentication events (including Event ID 4769), providing insights into encryption types, account names, and device context.
- Captures Kerberos ticket request events (4769).
- Contains 'KerberosEncryptionType' and other relevant fields.
- Crucial for investigating Kerberos-related credential theft.
Memory trick: For Kerberos tickets, you need 'LogonEvents' – that's where all the authentication details, including encryption types, are stamped.
Microsoft Defender for Cloud Apps (MDCAS)
Flip cardA Cloud Access Security Broker (CASB) that provides comprehensive visibility, control, and protection for cloud applications, both sanctioned and unsanctioned.
- Monitors user activities in cloud apps.
- Detects anomalous behavior and threats.
- Enforces data loss prevention (DLP) policies for cloud apps.
Memory trick: To see inside cloud apps, you need the Defender that's 'for Cloud Apps'.
Safe Attachments Policy
Flip cardA Microsoft Defender for Office 365 policy that detonates and analyzes email attachments in a virtual sandbox environment to detect unknown malware and zero-day exploits before they reach user inboxes.
- Protects against unknown malware and zero-day threats.
- Scans attachments in a separate, isolated environment.
- Can block, replace, or monitor attachments based on policy.
Memory trick: Safe Attachments gives suspicious files a 'safe' place to explode.
MDE Streaming API (SIEM Integration)
Flip cardA Microsoft Defender for Endpoint API that enables continuous, real-time streaming of raw security events and alerts directly to external Security Information and Event Management (SIEM) systems or other data repositories.
- Provides raw event data.
- Supports direct integration with SIEMs.
- Does not require Azure Event Hubs as an intermediary.
Memory trick: To 'stream' data directly, use the 'Streaming API', not pull or old protocols.
Defender for Endpoint SIEM Integration
Flip cardThe process of forwarding security alerts and raw event data from Microsoft Defender for Endpoint to a Security Information and Event Management (SIEM) system.
- Enables centralized security monitoring and correlation.
- Best achieved using dedicated data connectors or streaming services.
- Microsoft Sentinel offers native connectors.
Memory trick: Connector Streams Data Reliably to SIEM.
Microsoft Defender for Cloud
Flip cardA cloud-native security solution that provides comprehensive security posture management and threat protection across your cloud and hybrid environments.
- Covers Azure, AWS, GCP, and on-premises resources.
- Offers Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWPP).
- Helps ensure compliance with regulatory standards.
Memory trick: For all things 'cloud', use the Defender that's 'for Cloud'.
AIR Automation Level: Semi-full
Flip cardAn Automated Investigation and Remediation (AIR) automation level in Microsoft Defender for Endpoint where the system automatically investigates detected threats but requires explicit approval from a security analyst before performing any remediation actions.
- Provides automatic investigation without automatic remediation.
- Requires human approval for all remediation actions.
- Suitable for critical systems where human oversight is essential.
Memory trick: Semi-full: Investigate, then ask for permission.
Attack Surface Reduction (ASR) Rules
Flip cardA set of capabilities in Microsoft Defender for Endpoint that target specific behaviors and software functions commonly abused by malware, such as ransomware, to prevent attacks.
- Blocks actions like launching executables from email clients or untrusted locations.
- Reduces the attack surface of devices.
- Configurable with audit, block, or warn modes.
Memory trick: To prevent ransomware, build strong walls and reduce entry points.
Vulnerability Management (MDE)
Flip cardA capability within Microsoft Defender for Endpoint that continuously assesses endpoints for vulnerabilities and misconfigurations, providing prioritized recommendations.
- Discovers software vulnerabilities and misconfigurations.
- Prioritizes risks based on threat landscape and organizational context.
- Provides actionable remediation recommendations.
Memory trick: Vulnerability Management Finds Weaknesses First.
Session Policy (MDCAS)
Flip cardA real-time control policy in Microsoft Defender for Cloud Apps that monitors and governs user actions within a cloud application session.
- Enforces granular controls like 'block download' or 'protect on download'.
- Uses reverse proxy architecture for real-time monitoring.
- Ideal for managing access from unmanaged or risky devices.
Memory trick: Session Policies Guard Data During App Use.
Advanced Hunting: IdentityLogonEvents
Flip cardAn Advanced Hunting table in Microsoft Defender XDR that contains detailed information about identity-related logon and authentication activities (e.g., NTLM, Kerberos, interactive logons) across the network, collected by Microsoft Defender for Identity.
- Crucial for investigating identity-based attacks and suspicious logon activities.
- Includes details like account name, source/destination device, protocol, and logon type.
- Aggregates data from domain controllers and other identity sensors.
Memory trick: Identity logon events reveal who tried to log on.
MDCAS Activity Policy
Flip cardA Microsoft Defender for Cloud Apps policy used to monitor specific user activities within cloud applications and generate alerts based on predefined conditions.
- Monitors activities like logins, downloads, uploads, and administrative actions.
- Can be configured to alert, but not necessarily block.
- Applies to sanctioned and unsanctioned apps.
Memory trick: Activity policies watch what you DO, not just where you go or what you touch.
Security Recommendations (TVM)
Flip cardA feature within Threat and Vulnerability Management (TVM) in Microsoft Defender for Endpoint that identifies security misconfigurations and provides actionable advice to improve an organization's security posture.
- Prioritizes recommendations based on risk.
- Integrates with Microsoft Intune for remediation.
- Helps achieve compliance and reduce attack surface.
Memory trick: To build a strong endpoint, follow the architect's security recommendations.
Defender for Identity Remediation
Flip cardActions taken within or in conjunction with Microsoft Defender for Identity to mitigate identity-based threats, often focusing on isolating or disabling compromised accounts.
- Focuses on Active Directory accounts.
- Aims to prevent lateral movement and privilege escalation.
- Integrates with other Defender products for coordinated response.
Memory trick: When an identity is compromised, cut off its power source first.
Advanced Hunting: CloudAppEvents Table
Flip cardThe CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about activities performed in cloud applications discovered or connected to Microsoft Defender for Cloud Apps, including user logins, file activities, and administrative actions.
- Primary source for investigating cloud application activity.
- Captures events from connected apps like Office 365, Azure AD, and third-party SaaS apps.
- Includes details like activity type, user, IP address, device, and application.
Memory trick: CloudAppEvents tracks everything happening inside your cloud apps.
Advanced Hunting (Defender for Identity)
Flip cardA query-based threat hunting tool in Microsoft Defender XDR that allows security teams to proactively inspect data from Defender for Identity and other Defender services.
- Uses Kusto Query Language (KQL).
- Provides access to raw security event data.
- Enables complex searches for specific threats and behaviors.
Memory trick: Hunting for Identity Clues Requires Deep Queries.
KQL 'contains' operator
Flip cardA Kusto Query Language operator used to search for a specified substring within a column value, performing a case-insensitive match.
- Case-insensitive by default.
- Useful for partial string matching.
- Can be less performant than 'has' for large datasets if exact term matching is possible.
Memory trick: Contains checks if the string has a bit of what you're looking for, anywhere.
MDCAS Cloud Discovery
Flip cardCloud Discovery in Microsoft Defender for Cloud Apps identifies all cloud applications in use across an organization, assesses their risk, and helps manage 'Shadow IT'.
- Uses traffic logs from firewalls/proxies.
- Identifies sanctioned and unsanctioned apps.
- Provides risk assessment and usage insights.
Memory trick: To 'discover' all the apps, you need 'Cloud Discovery', like a radar for your cloud environment.
DLP in Microsoft 365 (MDO context)
Flip cardData Loss Prevention (DLP) in the Microsoft 365 ecosystem, managed via the compliance center, provides capabilities to identify, monitor, and protect sensitive information across Microsoft 365 services like Exchange Online, SharePoint Online, and OneDrive for Business.
- Detects sensitive info types (e.g., credit card numbers).
- Can apply actions like blocking, encrypting, or alerting.
- Protects data at rest and in transit.
Memory trick: DLP in M365 is your data bodyguard for emails and documents.
MDE IoC - URL/Domain
Flip cardMicrosoft Defender for Endpoint allows security teams to create custom Indicators of Compromise (IoCs) for URLs and domains to block access to known malicious web resources.
- Blocks access to specified URLs/domains at the endpoint level.
- Works across browsers and applications.
- Provides immediate containment for identified threats.
Memory trick: To block a bad URL everywhere, you need 'Endpoint' to enforce it at the device level.
Activity Policies (MDCAS)
Flip cardPolicies in Microsoft Defender for Cloud Apps that detect anomalous user behavior and activities across connected cloud applications, often indicating compromised accounts or insider threats.
- Monitors login activities, file access, and administrative actions.
- Can detect impossible travel, unusual locations, and excessive failed logins.
- Generates alerts and can trigger automated actions.
Memory trick: To detect unusual cloud activities, you need a keen eye on every activity.
MDE Threat and Vulnerability Management (TVM)
Flip cardA Microsoft Defender for Endpoint capability that continuously discovers, prioritizes, and provides actionable recommendations for remediating software vulnerabilities and misconfigurations across endpoints.
- Continuously scans for vulnerabilities.
- Prioritizes based on threat landscape and organizational context.
- Provides actionable security recommendations.
Memory trick: TVM is like a diligent health check for your endpoints, finding weaknesses and telling you how to fix them.
IoC: File Hash
Flip cardAn Indicator of Compromise (IoC) type in Microsoft Defender XDR that allows security teams to define and enforce blocking or alerting rules based on the unique cryptographic hash of a malicious file.
- Blocks specific files.
- Uses SHA1 or SHA256 hashes.
- Applied across Defender for Endpoint managed devices.
Memory trick: To stop a specific file, you need its unique 'hash' fingerprint.
Automated Investigation and Remediation (AIR)
Flip cardA capability within Microsoft Defender for Endpoint that automatically investigates alerts, applies remediation actions, and resolves security threats without requiring manual intervention.
- Reduces alert fatigue for security teams.
- Speeds up incident response.
- Can be configured with various automation levels.
Memory trick: Auto-Investigate, Remediate, Resolve – AIR is your security robot.
Advanced Hunting - DeviceProcessEvents
Flip cardThe DeviceProcessEvents table in Microsoft Defender XDR Advanced Hunting contains information about processes created and terminated on devices.
- Includes process command line, user, device, and parent process information.
- Essential for detecting malicious process execution patterns.
- Used to track execution of scripts and applications.
Memory trick: Processes are like recipes, and DeviceProcessEvents holds all the recipe steps (command lines).
MDE IoC (URL/Domain)
Flip cardMicrosoft Defender for Endpoint's Indicators of Compromise feature allows defining specific URLs or domain names as malicious, enabling automatic blocking or auditing of network connections to them across all managed endpoints.
- Provides immediate, proactive blocking.
- Applies to all managed endpoints.
- Supports 'Block' and 'Audit' actions.
Memory trick: IoC is the 'No Entry' sign for known bad guys, like a domain.
KQL: DeviceProcessEvents & FolderPath
Flip cardThe 'DeviceProcessEvents' table in Advanced Hunting captures process execution data, and the 'FolderPath' column within it specifies the directory from which the process was launched. Used with `!in` to exclude known good paths.
- Records process creation and termination.
- FolderPath identifies the execution directory.
- Crucial for detecting anomalous program launches.
Memory trick: To track an 'exe' running, you need 'ProcessEvents' and its 'FolderPath' to see where it came from.
Microsoft 365 DLP Policy (MDO context)
Flip cardA Data Loss Prevention (DLP) policy in Microsoft 365 helps prevent sensitive information from being accidentally or intentionally shared outside the organization by identifying, monitoring, and protecting sensitive data across Microsoft 365 services.
- Identifies sensitive information using built-in or custom sensitive info types, keywords, or patterns.
- Enforces rules on content based on location (Exchange, SharePoint, OneDrive, Teams).
- Can block sharing, encrypt content, or notify users/admins.
Memory trick: DLP policies are the 'Do Not Pass Go' for sensitive data to outsiders.
MDCAS Session Policy
Flip cardA policy type in Microsoft Defender for Cloud Apps that enables real-time monitoring and control over user sessions with cloud applications, allowing for granular actions like blocking downloads, uploads, or specific activities based on user, device, and content.
- Operates in real-time during a user session.
- Requires integration with a reverse proxy or conditional access app control.
- Can enforce download/upload restrictions, content inspection, and data protection.
Memory trick: Sessions need real-time supervision.
Microsoft Defender Antivirus Exclusions
Flip cardA setting in Microsoft Defender Antivirus that allows administrators to specify files, folders, processes, or file types that should not be scanned or detected as threats.
- Used to prevent false positives for legitimate applications.
- Can be configured for files, folders, file types, and processes.
- Should be used cautiously to avoid creating security blind spots.
Memory trick: Exclude the good, catch the bad.
Device Discovery (MDE)
Flip cardA Microsoft Defender for Endpoint capability that actively finds unmanaged devices connected to an organization's network and provides options for onboarding them.
- Identifies workstations, servers, and network devices.
- Helps achieve comprehensive endpoint coverage.
- Facilitates onboarding for continuous monitoring.
Memory trick: Device Discovery is like a network detective, finding all the hidden endpoints.
Threat Explorer (MDO)
Flip cardA powerful reporting tool in Microsoft Defender for Office 365 that allows security teams to investigate and remediate email-borne threats.
- Provides granular search capabilities for email flow.
- Identifies malicious emails that bypassed filters.
- Enables remediation actions like soft delete or hard delete from mailboxes.
Memory trick: Explorer's Scope Finds Every Email Trail.
Microsoft Defender XDR Incidents
Flip cardThe central feature in Microsoft Defender XDR that automatically correlates related alerts from various Defender products into a single, comprehensive attack story, providing context and streamlining investigation.
- Aggregates alerts across Endpoint, Identity, Office 365, and Cloud Apps.
- Shows the full attack chain, affected assets, and user accounts.
- Enables unified investigation and remediation.
Memory trick: To see the full attack picture, you need to piece together all the incidents.
Activity Policy (MDCAS)
Flip cardA type of policy in Microsoft Defender for Cloud Apps that allows granular control over user activities within connected cloud applications.
- Monitors specific user actions (e.g., upload, download, share).
- Can enforce actions like block, alert, or require justification.
- Applies to sanctioned and unsanctioned apps.
Memory trick: MDCAS Policies Actively Control App Data.
Microsoft Defender for Cloud (MDC)
Flip cardA Microsoft Defender XDR component providing Cloud Security Posture Management (CSPM) and Cloud Workload Protection (CWP) across Azure, hybrid, and multi-cloud environments (AWS, GCP).
- Monitors security posture across clouds.
- Provides security recommendations based on benchmarks.
- Protects workloads in IaaS, PaaS, and hybrid setups.
Memory trick: Defender for Cloud is the big umbrella for all your cloud and hybrid security, no matter where your servers are floating.
Advanced Hunting: CloudAppEvents
Flip cardThe CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema records comprehensive activity data from connected cloud applications. It's crucial for understanding user behavior, detecting anomalies, and investigating incidents within cloud services.
- Contains events from Microsoft 365 services (Exchange, SharePoint, Teams, Azure AD) and third-party cloud apps.
- Includes details like activity type, user, IP address, device, application, and object involved.
- Essential for investigating cloud-based compromises and insider threats.
Memory trick: CloudAppEvents is your 'CCTV' for what users do in cloud apps.
Threat Explorer (Defender for Office 365)
Flip cardA powerful security operations tool in Microsoft Defender for Office 365 that allows security teams to proactively investigate, hunt for, and remediate email-related threats across all mailboxes.
- Provides detailed views of email, attachments, and URLs.
- Enables filtering and searching across various email attributes.
- Supports remediation actions like soft deleting messages.
Memory trick: Threat Explorer is your email detective, searching everywhere for clues.
Security Baselines (MDE)
Flip cardStandardized, pre-configured security settings that can be deployed to devices to ensure a consistent and hardened security posture across the organization.
- Ensures consistent security configuration.
- Applied automatically to onboarded devices.
- Based on industry best practices.
Memory trick: Baselines build the secure foundation, not just fight the current fire.