JTCyberTech / Cybersecurity-Home-Labs

5 stars 1 forks source link

Azure: Sentinel SIEM - READ ME #43

Open JTCyberTech opened 11 months ago

JTCyberTech commented 11 months ago

Prerequisites

I successfully implemented a Security Information and Event Management (SIEM) solution within Azure Cloud Sentinel, significantly improving our ability to monitor and analyze security events. Employing advanced techniques and configurations has further enhanced the system's threat detection capabilities. A standout feature of this project is the practical experience it offers in implementing remediation measures to mitigate and resolve identified cybersecurity incidents. This has not only demonstrated my problem-solving skills but also underscored my proficiency in responding effectively to security breaches, thereby strengthening our overall cybersecurity capabilities.

Creating an Azure Account

Here are the steps I will be taking to complete this project:

  1. Create SIEM in Azure Cloud

  2. Configuration of Sentinel Diagnostic Settings

  3. Explore Cloud SIEM: Sentinel

  4. Create Watchlist to Detect Threats

  5. Create Detection Rule for Threats

  6. Create User Account in Azure for SIEM Investigation

  7. Infiltrate User Account to Generate Incidents in SIEM

  8. Explore Created Incidents in SIEM

  9. Investigate Incident in SIEM

  10. Remediate Incident in SIEM