Microsoft Security Operations Analyst flashcards
150 free flashcards. Tap a card to flip it.
KQL 'has' operator
Flip cardA Kusto Query Language operator used for efficient, case-insensitive substring matching within text columns. It is generally faster than 'contains' for whole word or term searches.
- Performs a case-insensitive search.
- Optimized for performance compared to 'contains'.
- Matches a whole term or substring anywhere in the text.
Memory trick: Has the word? Case ignored? Fast!
MDCAS DLP Enforcement
Flip cardMicrosoft Defender for Cloud Apps (MDCAS) enforces Data Loss Prevention (DLP) policies across connected cloud applications, preventing sensitive data exfiltration.
- Integrates with Microsoft Purview DLP policies.
- Provides real-time protection for data in transit and at rest.
- Covers apps like SharePoint, Teams, OneDrive, and third-party cloud apps.
Memory trick: For DLP in 'Cloud Apps', you need 'MDCAS' to guard the gates.
Microsoft 365 DLP Policy
Flip cardA Data Loss Prevention (DLP) policy in Microsoft 365 that identifies, monitors, and protects sensitive information across various Microsoft 365 services, including Exchange Online, SharePoint Online, and OneDrive for Business.
- Detects sensitive information types (SITs) like credit card numbers.
- Can be configured to block, notify, or encrypt content.
- Helps comply with regulatory requirements.
Memory trick: DLP stops sensitive data from slipping out.
Defender for Identity: Unusual Travel
Flip cardAn alert generated by Microsoft Defender for Identity when a user account logs in from two geographically distinct locations within an impossible travel time, indicating potential credential compromise.
- Detects impossible travel scenarios.
- Strong indicator of compromised credentials.
- Helps identify suspicious access from unusual locations.
Memory trick: Defender for Identity is like a watchful guard, noticing if a user's 'teleporting' or doing something truly bizarre.
Threat and Vulnerability Management (TVM)
Flip cardA capability within Microsoft Defender for Endpoint that continuously discovers, assesses, prioritizes, and remediates software vulnerabilities and misconfigurations on endpoints.
- Identifies software vulnerabilities.
- Prioritizes remediation based on risk.
- Provides actionable security recommendations.
Memory trick: For 'threats' and 'vulnerabilities', 'TVM' is your proactive management tool.
DLP Policies (MDO)
Flip cardData Loss Prevention (DLP) policies within Microsoft Defender for Office 365, powered by Microsoft Purview, help organizations prevent sensitive information from being accidentally or maliciously shared outside the organization.
- Identifies sensitive information types (SITs).
- Can apply actions like blocking, encrypting, or notifying.
- Integrates with sensitivity labels for persistent protection.
Memory trick: To prevent data leaks, you need a strong DLP policy to seal the email.
IoC: URL/Domain
Flip cardA type of custom indicator of compromise in Microsoft Defender XDR used to define malicious URLs or domains that should be blocked, allowed, or audited on managed devices.
- Blocks access to specified malicious web addresses.
- Effective for disrupting command-and-control (C2) communications.
- Can be set with different actions: Allow, Audit, Block, Alert.
Memory trick: IoCs are your custom blocklist, telling Defender what to stop.
MDE Indicators of Compromise (IoC)
Flip cardIndicators of Compromise (IoCs) are artifacts observed on a network or in an operating system that reliably indicate a computer intrusion.
- Can be files, IPs, URLs, domains, certificates.
- Used for custom detection and prevention rules.
- Allows immediate blocking or alerting on specific threats.
Memory trick: To block a specific bad IP, you need to mark it as an 'IoC', like putting a 'wanted' poster on it.
Advanced Hunting
Flip cardA powerful, flexible, and interactive query-based threat-hunting tool in Microsoft Defender XDR that allows security teams to proactively inspect data from various Defender products (Endpoint, Identity, Office 365, Cloud Apps).
- Uses Kusto Query Language (KQL).
- Enables cross-domain correlation and custom detection rules.
- Provides access to raw event data for deep investigation.
Memory trick: To hunt across domains, you need advanced tools and a sharp eye.
MDE Indicator of Compromise (IoC)
Flip cardAn IoC in Microsoft Defender for Endpoint is an artifact observed on a network or in an operating system that reliably indicates a computer intrusion. MDE can ingest IoCs like URLs, domains, IPs, file hashes, and certificates to detect and block threats.
- Used for rapid detection and blocking of known threats.
- Supports various types: files, IP addresses, URLs/domains, certificates.
- Configured in the Microsoft 365 Defender portal under Settings > Endpoints > Indicators.
Memory trick: Indicators of Compromise are the fastest way to STOP bad links.
Threat Explorer
Flip cardA powerful security tool within Microsoft Defender for Office 365 that allows security teams to investigate and respond to email-borne threats like phishing, malware, and spam.
- Provides real-time visibility into email threats.
- Enables search by sender, recipient, subject, attachment, and URL.
- Facilitates remediation actions such as blocking senders or deleting emails.
Memory trick: To explore email threats, you need a good map and a flashlight.
Safe Links Policy
Flip cardA Microsoft Defender for Office 365 policy that provides time-of-click verification of URLs in email messages and other Office apps to protect users from malicious websites.
- Rewrites URLs in email to Defender for Office 365 scanning links.
- Scans the destination of the link in real-time when clicked.
- Can block access to malicious sites or warn users.
Memory trick: Safe Links keeps your clicks safe, even if the URL tries to play a trick.
MDO Submissions
Flip cardA feature in Microsoft Defender for Office 365 that allows security teams to manually submit suspicious emails, attachments, or URLs to Microsoft for re-analysis, and receive detailed reports on their findings.
- Used for re-analysis of suspicious content.
- Provides detailed detonation reports.
- Helps improve detection capabilities.
Memory trick: When a threat slips past, submit it to understand the 'why' and to train the system.
Advanced Hunting: DeviceProcessEvents
Flip cardAn Advanced Hunting table in Microsoft Defender XDR that contains information about process creation, network connections, and other process-related events on monitored devices.
- Crucial for investigating execution and persistence techniques.
- Includes details like process ID, command line, parent process, and user account.
- Often used in conjunction with other device-related tables.
Memory trick: Processes are events on a device.
Kerberos Event ID 4769
Flip cardWindows Security Event ID 4769 signifies 'A Kerberos service ticket was requested.' It is a crucial event for detecting Kerberos-related attacks like Golden Ticket or Silver Ticket.
- Indicates a successful Kerberos service ticket request.
- Monitored by Microsoft Defender for Identity for suspicious activity.
- Found in the 'IdentityLogonEvents' table in Advanced Hunting.
Memory trick: Identity logon events for Kerberos tickets.
MDO DLP with Encryption
Flip cardMicrosoft Defender for Office 365 (via Microsoft 365 DLP) allows creating policies to detect sensitive information in emails and automatically apply encryption when specific conditions, such as external recipients, are met.
- Identifies sensitive information types (SITs).
- Applies protective actions like encryption.
- Crucial for regulatory compliance and data protection.
Memory trick: DLP is the data's bodyguard, encrypting secrets before they leave the building.
MDCAS Session Policy: Block Download
Flip cardA Microsoft Defender for Cloud Apps Session Policy enables real-time monitoring and control over user activities within sanctioned cloud applications, allowing actions like blocking downloads of sensitive data to unmanaged devices.
- Enforces control during active user sessions.
- Can detect sensitive information in content.
- Supports 'Block download' for data exfiltration prevention.
Memory trick: Session policies are like a real-time customs agent, checking every download during a user's cloud 'trip'.
Cloud Discovery (MDCAS)
Flip cardA feature of Microsoft Defender for Cloud Apps that identifies all cloud applications used in an organization, assesses their risk, and helps manage 'shadow IT'.
- Analyzes traffic logs from network devices.
- Provides a risk score for each discovered app.
- Helps gain visibility into unsanctioned cloud app usage.
Memory trick: To discover hidden clouds, you need a good cloud discovery radar.
Microsoft Defender for Identity
Flip cardA cloud-based security solution that leverages on-premises Active Directory signals to identify, detect, and investigate advanced threats, compromised identities, and malicious insider actions.
- Protects hybrid identity environments.
- Detects credential theft, lateral movement, domain dominance.
- Provides security posture assessments for Active Directory.
Memory trick: Each Defender Protects a Specific Domain.
IdentityLogonEvents Table
Flip cardAn advanced hunting table in Microsoft Defender XDR that contains information about authentication activities and logon events across the organization's identities.
- Tracks successful and failed logon attempts.
- Includes details like account name, device, logon type, and authentication protocol.
- Crucial for investigating identity-based attacks and lateral movement.
Memory trick: IdentityLogonEvents watches who logs on where, a digital ID check.
Advanced Hunting Tables (Cloud App & Identity)
Flip cardSpecific tables in Microsoft Defender XDR's Advanced Hunting schema that store detailed activity logs from Microsoft Defender for Cloud Apps and Microsoft Defender for Identity, respectively.
- CloudAppEvents: Records actions in monitored cloud apps (e.g., file access, downloads, logins).
- IdentityLogonEvents: Records authentication events from Active Directory (on-prem and Azure AD).
Memory trick: Cloud activities and Identity logins tell the story of a compromised user.
Antivirus and Next-Generation Protection
Flip cardThe core component of Microsoft Defender for Endpoint providing real-time protection, behavioral monitoring, and automatic updates for security intelligence.
- Prevents malware and viruses.
- Uses cloud-delivered protection and machine learning.
- Includes automatic security intelligence updates.
Memory trick: Defender's Core Protections Always Keep Devices Safe.
Defender for Identity Sensor Types
Flip cardMicrosoft Defender for Identity uses sensors to collect data from domain controllers and network traffic to detect threats.
- Integrated sensors run directly on domain controllers.
- Standalone sensors run on dedicated servers, monitoring port-mirrored traffic.
- Sensor placement dictates visibility into specific threat vectors.
Memory trick: Integrated sensors live inside the brain (DC), standalone sensors watch from afar.
MDE Streaming API
Flip cardA feature in Microsoft Defender for Endpoint that provides a continuous stream of raw security events and alerts to external systems, such as SIEMs, data lakes, or Azure Event Hubs, for centralized logging and analysis.
- Enables near real-time data export.
- Used for integration with external SIEMs or data storage.
- Provides granular control over which event types are streamed.
Memory trick: Stream your MDE events to your SIEM lake.
Microsoft Defender for Cloud (CSPM)
Flip cardMicrosoft Defender for Cloud provides Cloud Security Posture Management (CSPM) features that continuously assess, monitor, and improve the security posture of cloud resources across Azure, multi-cloud, and hybrid environments.
- Identifies security misconfigurations and provides recommendations.
- Assesses compliance against regulatory standards and industry benchmarks.
- Offers a secure score to visualize security posture improvements.
Memory trick: Defender for Cloud: Your cloud's security guardian.
MDE SIEM Integration
Flip cardMicrosoft Defender for Endpoint integrates with SIEM systems to centralize security data for analysis and correlation.
- Streaming API to Azure Event Hubs is the primary method for real-time data export.
- Exports alerts and raw event data.
- Enables centralized logging and long-term retention.
Memory trick: To send all MDE data, you need a 'Hub' to stream it through, not just a manual copy or email.
KQL: CloudAppEvents (File Downloads)
Flip cardThe Advanced Hunting table in Microsoft Defender XDR that provides detailed logs of activities occurring within cloud applications, including specific events related to files such as downloads, uploads, and access.
- Records activities in cloud apps (e.g., SharePoint, OneDrive).
- Includes file-specific details (name, size, hash).
- Crucial for investigating data exfiltration from cloud services.
Memory trick: For file actions in 'cloud apps', check 'CloudAppEvents'.
Advanced Hunting: Service Creation (Registry)
Flip cardSuspicious service creation is often detected by monitoring registry modifications. The `DeviceRegistryEvents` table in Advanced Hunting captures these changes, allowing an analyst to identify the process responsible for creating a new service.
- Services are defined in the Windows Registry.
- DeviceRegistryEvents captures additions/modifications.
- Helps identify the initiating process of service creation.
Memory trick: To find out who built the 'UpdaterService' (a registry thing), check the 'RegistryEvents' first to see who wrote its blueprints.
Microsoft 365 Defender File Page
Flip cardA dedicated page within the Microsoft 365 Defender portal that provides a comprehensive, centralized view of a specific file, including its global and organizational prevalence, associated alerts, observed activities, and analysis submissions.
- Aggregates data from Defender for Endpoint and other sources.
- Helps analysts quickly assess the impact and nature of a suspicious file.
- Includes details like file hash, name, size, and associated threats.
Memory trick: Files get their own page for deep dives.
Data Loss Prevention (DLP) in MDO
Flip cardPolicies configured within Microsoft Defender for Office 365 (and the Microsoft Purview compliance portal) to identify, monitor, and protect sensitive information in email, SharePoint, and OneDrive.
- Prevents accidental or malicious sharing of sensitive data.
- Uses sensitive info types (SITs) to detect data.
- Can apply actions like block, encrypt, or notify.
Memory trick: MDO Secures Sensitive Email Content.
KQL: Service-initiated PowerShell from FolderPath
Flip cardA KQL query pattern in Microsoft Defender XDR's Advanced Hunting to detect malicious services initiating PowerShell scripts from specific, potentially suspicious, folder paths.
- Uses `DeviceProcessEvents` table.
- Filters by `InitiatingProcessFileName` (e.g., `services.exe`).
- Checks `ProcessCommandLine` for script execution.
- Identifies `FolderPath` for suspicious locations.
Memory trick: To catch a service running a script from a weird place, check the 'process events' for 'services.exe', 'powershell', and the 'folder path'.
Advanced Hunting Custom Detection Rules
Flip cardCustom detection rules in Microsoft Defender XDR's Advanced Hunting allow security analysts to create their own alerts and incidents based on Kusto Query Language (KQL) queries that identify specific behaviors or events across their environment.
- Uses KQL to query raw event data from various Defender sources.
- Enables proactive hunting for novel threats and specific attack techniques.
- Can generate alerts, trigger automated actions, and create incidents.
Memory trick: Advanced Hunting's custom rules are your magnifying glass for sneaky malware.
KQL 'search *' operator
Flip cardThe 'search *' operator in KQL performs a full-text search across all tables and columns within the current scope (e.g., a Log Analytics workspace) for a specified term or pattern.
- Useful for broad, exploratory searches.
- Can be slower than targeted queries.
- Ideal for threat hunting when data source is unknown.
Memory trick: Search Star: Seek Everywhere, See Everything!
Log Analytics Workspace Encryption (CMK)
Flip cardCustomer-managed key (CMK) encryption for Log Analytics workspaces allows organizations to use their own encryption keys from Azure Key Vault to protect data at rest, providing greater control over encryption keys.
- Configured at the Log Analytics workspace level.
- Requires an Azure Key Vault to store the CMK.
- Enhances security and compliance for data at rest.
Memory trick: Workspace: The Key to Your Data's Encryption!
Azure Active Directory Data Connector
Flip cardThe Azure Active Directory data connector in Microsoft Sentinel ingests identity-related logs, including sign-in logs, audit logs, and provisioning logs, providing visibility into user authentication and administrative activities.
- Ingests SignInLogs, AuditLogs, ProvisioningLogs.
- Crucial for identity-based threat detection.
- Covers user authentication, administrative changes, and user provisioning.
Memory trick: AAD Connector: All About AAD Actions!
Microsoft Sentinel Cost Optimization - Ingestion
Flip cardOptimizing Sentinel ingestion costs involves reducing the volume of data sent to Log Analytics. This can be achieved by filtering irrelevant data at the source or using ingestion-time transformations.
- Billed primarily on data ingestion volume.
- Commitment tiers offer discounted rates for predictable usage.
- Filter out unnecessary data *before* ingestion to save most effectively.
Memory trick: Filter First, Then Fund Savings
KQL 'summarize' and 'top' operators
Flip cardThe 'summarize' operator groups rows by specified columns and performs aggregations, while the 'top' operator efficiently returns the first N rows sorted by specified columns.
- 'summarize' is for aggregation (e.g., count(), sum()).
- 'top' is optimized for retrieving the top N records.
- Often used together for 'top N by count' scenarios.
Memory trick: Summarize, then Top: Count and Crown!
KQL 'union' operator
Flip cardThe 'union' operator in KQL combines the rows of two or more tables or tabular expressions into a single result set. It's useful for aggregating similar data from different sources.
- Appends rows, not columns.
- Requires compatible schemas (similar columns).
- Can be used with 'kind=outer' to include all rows even if schema differs slightly.
Memory trick: Union: Unite Similar Logs!
Microsoft Sentinel Multi-Region Deployment
Flip cardFor strict data sovereignty, Microsoft Sentinel deployments often involve multiple Log Analytics workspaces and corresponding Sentinel instances, each located in a specific geographic region, with centralized management typically layered on top.
- Log Analytics workspace location determines data residency.
- Each Sentinel instance is tied to one Log Analytics workspace.
- Centralized management can be achieved via Azure management groups or Azure Lighthouse.
Memory trick: Regional Workspaces: Rule Your Data's Realm!
Microsoft Sentinel Fusion Rules
Flip cardFusion rules are built-in analytics rules in Microsoft Sentinel that use machine learning to automatically detect multi-stage attacks by correlating disparate alerts and behavioral anomalies across various data sources.
- Uses machine learning for correlation.
- Detects multi-stage, sophisticated attacks.
- Correlates low-fidelity alerts into high-fidelity incidents.
Memory trick: To 'Fuse' together many small clues into one big attack, use Fusion rules.
Azure Diagnostic Settings
Flip cardAzure Diagnostic Settings are used to configure an Azure resource to send its platform logs and metrics to one or more destinations, including a Log Analytics workspace (for Sentinel ingestion).
- Configured per Azure resource (VM, NSG, Storage, etc.).
- Sends resource-specific operational logs and metrics.
- Essential for comprehensive Azure service monitoring in Sentinel.
Memory trick: Diagnostics Direct Data to Destination
Log Analytics Gateway
Flip cardA Log Analytics gateway acts as a proxy that forwards data from agents to Azure Monitor when agents cannot directly connect to Azure Monitor due to network restrictions.
- Centralizes log collection from multiple agents.
- Supports Windows and Linux agents.
- Requires outgoing HTTPS (port 443) to Azure Monitor endpoints.
Memory trick: Gateway Guards On-Premises Logs to Cloud
Microsoft Sentinel Scheduled Query Rules
Flip cardScheduled query rules in Microsoft Sentinel run custom Kusto Query Language (KQL) queries at defined intervals over specified historical data to detect threats and create incidents.
- Highly customizable with KQL.
- Supports long lookback periods (up to 14 days).
- Ideal for complex correlation and statistical analysis.
Memory trick: Schedule Queries for Slow Threats
KQL distinct operator
Flip cardThe 'distinct' operator in KQL returns a table with the unique combinations of the provided columns. It's often used with 'summarize' to count unique items.
- Returns unique values in a column or set of columns.
- Useful for counting unique entities (e.g., users, IPs).
- Can be used as a standalone operator or within summarize functions.
Memory trick: Distinctly Count Unique IPs
Microsoft Sentinel Automation Rules & Playbooks
Flip cardAutomation Rules in Sentinel can trigger Playbooks (Logic Apps) to perform complex, multi-step automated actions on incidents, such as enrichment, notification, assignment, and status updates.
- Automation Rules act as triggers for Playbooks.
- Playbooks (Logic Apps) execute the actual workflow.
- Enables advanced, conditional incident response automation.
Memory trick: Rules Run Playbooks for Incident Control
KQL Aggregation and Top N
Flip cardTo find the 'top N' items based on a count or sum in KQL, you typically use the 'summarize' operator to aggregate, 'sort by' to order the results, and 'take' or 'top' to select the desired number of rows.
- summarize: Groups and aggregates data.
- sort by: Orders results based on specified columns.
- take/top: Selects a specified number of rows (top or bottom N).
Memory trick: Summarize, Sort, Then Take Top
Azure Monitor Agent (AMA)
Flip cardThe Azure Monitor Agent (AMA) is a unified agent for collecting monitoring data from guest operating systems of Azure and non-Azure machines and delivering it to Azure Monitor.
- Replaces older agents (Log Analytics agent).
- Supports Windows and Linux.
- Collects logs, metrics, and other monitoring data.
Memory trick: AMA: All Machines, All Logs, All Aboard!
KQL AzureActivity table
Flip cardThe AzureActivity table in Log Analytics (and thus Sentinel) contains events from the Azure Activity Log, which records control plane operations performed on Azure resources across subscriptions.
- Tracks resource creation, update, deletion, and other management operations.
- Provides 'who, what, when, and where' for Azure management events.
- Crucial for auditing and security investigations of Azure resource changes.
Memory trick: Activity Always Audits Azure Actions
Minimizing Attack Surface
Flip cardA security principle focused on reducing the number of potential entry points or vulnerabilities that an attacker could exploit in a system, application, or network.
- Involves removing unnecessary services, ports, and features.
- Reduces the likelihood of successful exploitation.
- A fundamental concept in secure design.
- Example: closing unused network ports.
Memory trick: Closed ports reduce the attack, for security to come back.
Microsoft Defender for Storage
Flip cardMicrosoft Defender for Storage provides agentless security intelligence that detects unusual and potentially harmful attempts to access or exploit Azure storage accounts. It protects Blob storage, Azure Files, and Azure Data Lake Storage from malware, ransomware, and other advanced threats.
- Agentless threat detection for Azure Storage accounts.
- Detects malware, ransomware, and suspicious access patterns.
- Integrates with Defender for Cloud for alerts and recommendations.
Memory trick: For your data in the cloud, Defender for Storage speaks aloud.
Defender for Cloud Regulatory Compliance Dashboard
Flip cardThe regulatory compliance dashboard in Microsoft Defender for Cloud provides a centralized view of compliance status against various regulatory standards and custom policies, enabling continuous assessment and reporting.
- Maps security recommendations to compliance controls.
- Supports built-in and custom compliance standards (Azure Policy initiatives).
- Provides a compliance score for each standard.
- Helps identify and remediate non-compliant resources.
Memory trick: Compliance's core: Custom rules, constant checks, clear reports.
Just-in-Time (JIT) VM Access
Flip cardJust-in-Time (JIT) VM access in Microsoft Defender for Cloud helps reduce the attack surface of virtual machines by locking down inbound traffic to management ports. Access is granted temporarily, on demand, and only to specified source IP addresses or ranges.
- Locks down management ports (e.g., RDP, SSH).
- Access is granted only for a limited time and to approved IPs.
- Significantly reduces exposure to brute-force attacks and other threats.
Memory trick: Only when needed, only for a bit, JIT access makes the port fit.
Azure Policy 'DeployIfNotExists' Effect
Flip cardAn Azure Policy effect that ensures a specific resource or configuration is deployed if it's not detected on a target resource, commonly used for automated remediation and baseline enforcement.
- Used to automatically deploy missing resources or configurations.
- Evaluated after resource creation or update.
- Ideal for deploying agents, extensions, or enabling settings.
- Supports compliance by ensuring required components are present.
Memory trick: If the agent is not there, 'DeployIfNotExists' will show care.
Azure Policy 'DeployIf NotExists'
Flip cardThe 'DeployIf NotExists' effect in Azure Policy is used to automatically deploy a resource (e.g., enable a security setting, deploy an extension) or modify an existing resource if a specified condition is not met on the target resource.
- Used for automatic remediation of non-compliant resources.
- Requires a managed identity for deployment/modification actions.
- Commonly used to enforce security baselines or enable Defender features.
Memory trick: If it's not there, deploy it there, to keep compliance in the air.
Unsupported Operating Systems
Flip cardOperating system versions that have reached their end-of-life (EOL) and no longer receive security updates, bug fixes, or technical support from the vendor, posing significant security risks.
- Vulnerable to unpatched exploits.
- No new security patches are released.
- May not be compliant with regulatory standards.
- Requires migration or decommissioning for effective risk management.
Memory trick: An old OS, no longer supported, must be upgraded or discarded, for new security to be afforded.
Azure Arc for Multi-Cloud Security
Flip cardAzure Arc extends Azure management and security services, including Microsoft Defender for Cloud, to resources running across multi-cloud (AWS, GCP) and on-premises environments, providing a unified control plane.
- Connects servers, Kubernetes clusters, and data services to Azure.
- Enables Defender for Cloud features like vulnerability assessment and threat detection for non-Azure resources.
- Provides a single pane of glass for hybrid and multi-cloud security.
- Requires installing the Azure Connected Machine agent on the non-Azure VMs.
Memory trick: Arc's embrace: Unites all clouds under Azure's grace.
Microsoft Defender for Containers
Flip cardMicrosoft Defender for Containers provides cloud-native threat protection for containerized environments, including vulnerability assessment of container images, runtime protection for Azure Kubernetes Service (AKS) clusters and their nodes, and monitoring for suspicious activities within containers.
- Scans container images for vulnerabilities.
- Provides runtime protection for AKS clusters and nodes.
- Monitors for suspicious activities within containers.
Memory trick: For your containers, big or small, Defender for Containers protects them all.
Defender for Cloud Enhanced Security Features
Flip cardA comprehensive set of security capabilities within Microsoft Defender for Cloud that provides advanced threat protection and security posture management for various Azure, hybrid, and multi-cloud resources.
- Includes automatic onboarding and agent deployment.
- Offers advanced threat detection and vulnerability assessments.
- Provides security recommendations and regulatory compliance.
- Consolidates security management across different resource types.
Memory trick: To secure all in the cloud, enhance it loud!
Defender for Cloud Workflow Automation
Flip cardA feature in Microsoft Defender for Cloud that enables automated responses to security alerts and recommendations by triggering Azure Logic Apps or Azure Functions, streamlining incident response.
- Automates repetitive security tasks.
- Integrates with Azure Logic Apps and Azure Functions.
- Can perform actions like quarantining, sending notifications, or opening tickets.
- Reduces manual effort and response time to security events.
Memory trick: For alerts to auto-act, workflow automation is the pact.
Azure Policy 'Modify' Effect
Flip cardThe 'Modify' effect in Azure Policy is used to add, update, or remove properties or tags on existing Azure resources or resource groups, enabling automatic remediation of non-compliant configurations.
- Requires a managed identity to perform changes.
- Can be used to enforce specific configurations (e.g., encryption settings, tags).
- Applies to existing resources and can be used on new creations.
Memory trick: Policy effects: Audit, Deny, Deploy, Modify – each has a job.