Azure Sentinel Preview (Feb 2019): Microsoft Enters the Cloud SIEM Market
On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...
Insights
Articles in Retrospectives.
On February 28, 2019, Microsoft announced Azure Sentinel in preview — a cloud-native security information and event management (SIEM) service built on Azure...
A good Microsoft Sentinel deployment starts with planning workspaces, data sources and costs before turning anything on. Here is the sequence Microsoft's...
Data connectors determine both what Microsoft Sentinel can detect and what it costs. Use this checklist to prioritize them.
The short version: In 2019, Microsoft released Sentinel, a security monitoring service that runs in the cloud. It made centralized security monitoring...
In November 2018, AWS launched S3 Block Public Access, a set of four settings that override bucket policies and access control lists to prevent public...
Account-level S3 Block Public Access protects every bucket in an account. With AWS Organizations, you can apply it everywhere and prevent anyone from...
Use this checklist to audit S3 public access across your AWS organization.
The short version: In 2018, AWS added a setting that prevents cloud storage from being made public at all. Turned on across an account, it stops the most...
At re:Invent in November 2018, AWS announced previews of two services that reshaped multi-account security: AWS Security Hub and AWS Control Tower.
A multi-account AWS landing zone separates workloads, centralizes security tools and protects logs. Here is how to design one using AWS's own reference...
AWS Security Hub can produce hundreds of failed controls on day one. This checklist helps you triage them without drowning.
The short version: AWS recommends running your cloud as many separate accounts — one per application or environment — instead of one big account. In 2018,...
On November 19, 2018, Azure Active Directory's multi-factor authentication service suffered a major outage. For much of a working day, many users in Europe,...
Emergency access accounts — often called break-glass accounts — let you regain administrative access to Entra ID and Microsoft 365 when normal sign-in...
When your identity provider or MFA service fails, every minute of confusion costs productivity. This runbook outlines what to do.
The short version: In 2018, Microsoft's multi-factor authentication service had a major outage, and many organizations couldn't sign in to their email and...
On November 30, 2018, Marriott International announced that attackers had accessed the guest reservation database of its Starwood brands. The intrusion had...
When you acquire a company, you acquire its cloud environments, identities and possibly its attackers. Here is how to run a cloud security due diligence...
Marriott's attackers stayed inside Starwood's network for about four years. Long-dwell intruders are quiet by design. Hunting for them means looking for...
The short version: When Marriott bought Starwood in 2016, it also bought a hacker who had been inside Starwood's systems since 2014. The breach wasn't...
On September 28, 2018, Facebook announced that attackers had exploited a vulnerability in its "View As" feature to steal access tokens. Facebook initially...
Stolen tokens let attackers bypass passwords and MFA. Conditional Access session controls limit how long tokens stay useful and when users must...
Token theft lets an attacker act as a user without their password or MFA. Detection focuses on tokens being used in ways that don't match the device and...
The short version: In 2018, a Facebook bug let attackers steal the digital "keys" that keep users signed in, giving access to millions of accounts without...