Microsoft Sentinel Security Posts

Discover the latest insights, best practices, and security research related to Microsoft Sentinel cloud-native SIEM.

Search Sentinel Posts

Filter Posts

Posts

Creating a CCP connector: Part 4

by Tim Groothuis
data-connectors microsoft-sentinel sentinel security azure

Hi there! Welcome (back) to my blog series about building a connector using Microsoft’s Sentinel Codeless Connector Platform (CCP). In the previous...

Read Article →

Creating a CCP connector: Part 3

by Tim Groothuis
security sentinel data-connectors microsoft-sentinel azure

Hey there, glad to see you’re still with me on this journey! If this is your starting point, you might want to considered reading the previous part...

Read Article →

Creating a CCP connector: Part 2

by Tim Groothuis
security sentinel azure microsoft-sentinel data-connectors

Hey there, welcome back! In this blog series I’ll show you how you can make your own Sentinel Codeless Connector Platform (CCP) connector. If you h...

Read Article →

Creating a CCP connector: Part 1

by Tim Groothuis
azure microsoft-sentinel sentinel data-connectors security

Hey there! In this blog series I’ll be going to walk you through a step by step guide on how to build your own Codeless Connector Platform (CCP) da...

Read Article →

KQL Sources - 2025 Update

by Bert-Jan Pals
azure entra-id security intune sentinel

What started as a single blog is now becoming a yearly trend. More and more KQL related repositories are created, not only with a focus on security...

Read Article →

Tool Release: pwshmisp

by Truls Dahlsveen
sentinel

In an attempt to make using MISP easier, I have created a PowerShell module to interact with MISP. The release of this module is the first step tow...

Read Article →

Announcing the Netskope CCP connector!

by Tim Groothuis
azure security netskope sentinel microsoft-sentinel

Over the past couple of weeks I’ve been working in close collaboration with the Netskope team to build and design a new Sentinel data connector for...

Read Article →

UAL = Unaligned Activity Logs

by Bert-Jan Pals
azure entra-id defender sentinel cloud

The unified audit log is a centralized repository for M365 user and admin activities. The activities originate from different applications, such as...

Read Article →

Cyber Back to School

by Robbe Van den Daele
defender sentinel

I spoke together with my colleague Thijs Lecomte at Cyber back to School, where we recorded our session on how to architect a SOC on top of Microso...

Read Article →

Experts Live Netherlands

by Robbe Van den Daele
security defender sentinel

I spoke together with my colleague Thijs Lecomte at Experts Live, where we talked about how we architecture a Security Operations Center on top of ...

Read Article →

Microsoft Sentinel User Forum

by Robbe Van den Daele
sentinel

Together with my colleague Louis Mastelinck, we talked on the Microsoft Sentinel user forum about Microsoft Sentinel data ingestion and avoiding al...

Read Article →

Sentinel & SOAR: Part 4 - Error handling

by Tim Groothuis
soar security sentinel microsoft-sentinel azure

IntroductionHello there, welcome back to part 4 of my Sentinel & SOAR series! If you’re new to this series you might want to check out any earl...

Read Article →

MC2MC

by Robbe Van den Daele
sentinel

My first public speaking experience! I spoke together with my colleague Sander Bougrine on MC2MC, where we deep dived into how to integrate 3th par...

Read Article →

Searching and finding data

by Gianni Castaldi
sentinel kusto-knight kusto-query-language kql

Welcome to the fifth blog post in the series becoming a Kusto Knight. While the previous blog post was about time in Kusto, this blog post will be ...

Read Article →