Boddu / Trent / Lamppu | Microsoft Unified XDR and SIEM Solution Handbook | E-Book | www.sack.de
E-Book

E-Book, Englisch, 296 Seiten

Boddu / Trent / Lamppu Microsoft Unified XDR and SIEM Solution Handbook

Modernize and build a unified SOC platform for future-proof security
1. Auflage 2024
ISBN: 978-1-83508-584-4
Verlag: De Gruyter
Format: PDF
Kopierschutz: 1 - PDF Watermark

Modernize and build a unified SOC platform for future-proof security

E-Book, Englisch, 296 Seiten

ISBN: 978-1-83508-584-4
Verlag: De Gruyter
Format: PDF
Kopierschutz: 1 - PDF Watermark



Tired of dealing with fragmented security tools and navigating endless threat escalations? Take charge of your cyber defenses with the power of Microsoft's unified XDR and SIEM solution.
This comprehensive guide offers an actionable roadmap to implementing, managing, and leveraging the full potential of the powerful unified XDR + SIEM solution, starting with an overview of Zero Trust principles and the necessity of XDR + SIEM solutions in modern cybersecurity. From understanding concepts like EDR, MDR, and NDR and the benefits of the unified XDR + SIEM solution for SOC modernization to threat scenarios and response, you'll gain real-world insights and strategies for addressing security vulnerabilities. Additionally, the book will show you how to enhance Secure Score, outline implementation strategies and best practices, and emphasize the value of managed XDR and SIEM solutions. That's not all; you'll also find resources for staying updated in the dynamic cybersecurity landscape.
By the end of this insightful guide, you'll have a comprehensive understanding of XDR, SIEM, and Microsoft's unified solution to elevate your overall security posture and protect your organization more effectively.

Boddu / Trent / Lamppu Microsoft Unified XDR and SIEM Solution Handbook jetzt bestellen!

Weitere Infos & Material


Table of Contents - Introduction to Zero Trust
- Introduction to XDR & SIEM
- Microsoft Unified XDR and SIEM Solution
- Power of Investigation and SOC Experience with Microsoft XDR + SIEM
- Defend attacks with Microsoft XDR + SIEM
- Security Misconfigurations & Vulnerability Management
- Assess and Improve Secure Score
- XDR implementation Strategy, Roadmap and Best Practices
- Managed XDR & SIEM
- Useful Resources & References


Table of Contents


Prefacexv


Case Study – High Tech Rapid Solutions Corporationxxi


Introductionxxi


The current environmentxxi


A cloud environmentxxii


A hybrid cloud architecturexxii


User entitiesxxii


Collaboration with partnersxxii


End user devicesxxii


Server infrastructurexxii


An application landscapexxiii


An IoT/OT environmentxxiii


Security challengesxxiii


Management concernsxxiii


Challenges emphasized by security teamsxxiv


Concerns raised by CISOxxv


A recent incident response casexxvi


Summaryxxvii


Part 1 – Zero Trust, XDR, and SIEM Basics and Unlocking Microsoft’s XDR and SIEM Solution


1


Introduction to Zero Trust3


Zero Trust and its history3


Why do we need Zero Trust?5


Zero Trust in security operations6


Zero Trust principles and architecture7


Zero Trust pillars10


A real-life example11


Case study analysis12


Future of Zero Trust12


Summary12


Further reading13


2


Introduction to XDR and SIEM15


Understanding XDR and SIEM15


What is XDR and how did it start?16


What is SIEM and how did it start?18


How does a SIEM solution work?19


What do these *DR acronyms mean?20


The benefits of having XDR and SIEM solutions in an enterprise22


XDR’s benefits and reasons to adopt it22


Why do we need to consider SIEM?24


How to choose the right XDR and SIEM tool26


Case study analysis28


Summary29


Further reading29


3


Microsoft’s Unified XDR and SIEM Solution31


What is Microsoft’s unified XDR and SIEM solution?32


Microsoft Defender XDR33


Microsoft Defender for Cloud33


Microsoft Sentinel33


Other relevant Microsoft Security solutions34


Microsoft Defender XDR overview (MDE, MDO, MDA, and MDI)35


Microsoft Defender XDR solutions36


MDE37


MDO41


MDA46


MDI52


Microsoft Entra ID Protection (formerly Azure AD Identity Protection)58


Use cases for Entra ID Protection60


Case study analysis60


Extending XDR capabilities to on-premises and hybrid cloud by leveraging MDC62


MDC key features62


Benefits of using unified XDR for on-premises, multi-cloud, or hybrid cloud scenarios67


Case study analysis71


Microsoft Sentinel – SIEM and SOAR74


Sentinel key features75


Microsoft Sentinel versus Microsoft Defender XDR76


Case study analysis77


XDR and beyond – exploring commonly used security solutions78


Microsoft Defender for IoT79


EASM80


MDTI81


Microsoft Copilot for Security82


Case study analysis83


Microsoft’s unified XDR and SIEM solution's benefits over non-MS solutions86


The future – Microsoft’s influence in cybersecurity88


The graphical Windows OS revolution88


Reshaping server technology with Windows NT88


Outlook and the transformation of email communication88


MS Office – standard in productivity software89


Internet Explorer – a chapter in web browsing89


The future – Microsoft’s rising influence in cybersecurity89


Summary89


Further reading90


Part 2 – Microsoft’s Unified Approach to Threat Detection and Response


4


Power of Investigation with Microsoft Unified XDR and SIEM Solution93


Understanding the basics of SOC94


Typical SOC roles95


Avengers of cybersecurity96


Traditional versus modern SOC operations97


SOC journey with Microsoft’s unified security operations platform98


Investigation in Microsoft Sentinel98


Investigation in Microsoft Defender XDR106


Microsoft Copilot for Security122


Integrations with other Microsoft security solutions and third-party tools125


Microsoft Defender XDR platform – Single pane of glass126


Microsoft Sentinel127


Third Party integrations128


Case study analysis130


Summary131


Further reading131


5


Defend Attacks with Microsoft XDR and SIEM133


An attack kill chain in XDR and SIEM134


Identity threat detection and response134


Microsoft Defender XDR’s automatic attack disruption135


An overview of Microsoft Defender XDR’s automatic attack disruption135


Automatic attack disruption key stages136


Deception capability in Microsoft Defender XDR138


Attack scenarios139


An identity-based supply chain attack in the cloud139


Business Email Compromise attack145


Human-Operated Ransomware150


A case study analysis159


Summary160


Further reading161


6


Security Misconfigurations and Vulnerability Management163


Introduction to security misconfigurations and vulnerabilities164


Security misconfigurations164


Vulnerabilities165


Vulnerability management framework165


How can Microsoft’s unified solution help to address this?168


Microsoft Defender Vulnerability Management168


Microsoft Defender for Cloud175


Microsoft Sentinel177


Microsoft Copilot for Security177


Integration with other tools179


ServiceNow integration179


Intune/MDE remediation (native integration capability)179


API integrations and automation179


Case study analysis180


Summary181


Further reading181


7


Understanding Microsoft Secure Score183


What is Microsoft Secure Score?183


Why do we need to monitor Secure Score?184


Azure secure score in MDC184


Identity secure score in Entra ID187


Microsoft Secure Score in Microsoft Defender XDR188


Understanding your score – how are scores calculated?192


How to assess and improve findings196


Addressing findings197


Integrations200


MDC secure score200


Microsoft Secure Score202


Case study analysis202


Summary203


Further reading203


Part 3 – Mastering Microsoft’s Unified XDR and SIEM Solution – Strategies, Roadmap, and the Basics of Managed Solutions


8


Microsoft XDR and SIEM Implementation Strategy, Approach, and Roadmap207


XDR and SIEM assessment and implementation strategy207


Security assessments208


Security strategies209


Implementation approach and roadmap217


Adoption order218


What’s next?224


Case study analysis225


Summary227


Further reading227


9


Managed XDR and SIEM Services229


Managed services overview229


Security services230


How to select a provider232


Pros and cons of using managed services233


Generic MSSP framework in the Microsoft ecosystem235


Azure Lighthouse236


Microsoft Entra ID236


Multi-tenant management in Microsoft Defender XDR237


Content management in an MSSP scenario238


Case study analysis240


Summary241


Further reading241


10


Useful Resources243


Microsoft Unified XDR and SIEM Solution resources243


Microsoft Defender XDR243


Microsoft Sentinel244


Microsoft Defender for Identity244


Microsoft Defender for Office244


Microsoft Defender for Endpoint244


Microsoft Defender for Cloud Apps245


Microsoft Defender for Cloud245


Non-Microsoft XDR and SIEM solutions245


XDR solutions245


SIEM solutions245


Managed XDR and managed...



Boddu Raghu :

Raghu Boddu is a Microsoft Security MVP based out of Texas. He works as Technical Director and leads Security & Threat Practice at Edgile, a Wipro company. A Visionary Leader with more than two decades of IT experience, helped many customers as advisory, specialization in Cyber Security, Legacy Migration & Modernization Strategies, multi-cloud/hybrid implementations, Digital Cloud Transformation Roadmaps, Cloud Native Architectures, etc. Raghu has earned dual masters (Master of Science in Information Services and Master of Science in Information Technology). He is a PMP certified, Agile Scrum certified & Six Sigma Green Belt certified and also holds Azure and AWS Solution Architect certifications.Lamppu Sami :

Sami Lamppu is a Cloud Security Lead at Netox, a Finland-based Cyber Security company. With over 20 years of IT experience, he is a distinguished expert in the field. He is not only a Microsoft Security MVP but also a passionate advocate for cloud security. For the past 8 years, he has been specializing in cloud security, focusing on innovative solutions and strategies. His expertise extends beyond the cloud, encompassing multi-cloud and hybrid implementations, as well as on-premises environments. Sami is the co-author of the "Entra ID Attack & Defense Playbook" (formerly known as the "Azure AD Attack & Defense Playbook"), and also blogs frequently. He holds a Bachelor's degree in business information technology and holds ~50+ Microsoft certifications, dating back to Windows Server 2003 and Windows XP.



Ihre Fragen, Wünsche oder Anmerkungen
Vorname*
Nachname*
Ihre E-Mail-Adresse*
Kundennr.
Ihre Nachricht*
Lediglich mit * gekennzeichnete Felder sind Pflichtfelder.
Wenn Sie die im Kontaktformular eingegebenen Daten durch Klick auf den nachfolgenden Button übersenden, erklären Sie sich damit einverstanden, dass wir Ihr Angaben für die Beantwortung Ihrer Anfrage verwenden. Selbstverständlich werden Ihre Daten vertraulich behandelt und nicht an Dritte weitergegeben. Sie können der Verwendung Ihrer Daten jederzeit widersprechen. Das Datenhandling bei Sack Fachmedien erklären wir Ihnen in unserer Datenschutzerklärung.