Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security
Colorkrew's Nishida received the "Microsoft Top Partner Engineer Award 2025 (Security Category)". Explain the efforts and results of security integration management and operational automation using Microsoft Sentinel. |Colorkrew Security
Are you having too many Microsoft Defender alerts? In this article, we will explain noise reduction techniques to eliminate alert fatigue. We will introduce the key points of severity setting, handling automatic remediation, and operation rule design, and propose effective alert operation and optimization methods. |Colorkrew Security
Microsoft 365 audit and sign-in logs can help you quickly spot signs of internal fraud. In this article, we will explain abnormal behavior patterns in OneDrive, Teams, etc., with specific examples, and introduce effective analysis methods and countermeasures. |Colorkrew Security
Explain the difference between CSIRT and PSIRT in an easy-to-understand manner. We will organize the roles and scope of CSIRT to protect the company and PSIRT to protect products in a comparison table in a comparison table, and introduce points that are easy to misunderstand and points to note when introducing them. |Colorkrew Security
Learn how to use Microsoft Defender for Endpoint timeline logs to gain time-series visibility into the full picture of attacks. We will also introduce key points for using KQL, visualization, and incident response. |Colorkrew Security
Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog
Learn how to create custom alerts for your company in Microsoft Sentinel. We will introduce in detail useful information for practical work, from query design and notification settings using KQL. Colorkrew Security Blog
Streamline security operations with Microsoft Sentinel automation! From log integration to alert response, we will explain the optimal implementation method combined with SOC support. |Colorkrew Security
For those who are worried about reducing costs with Microsoft Sentinel. Here are three specific measures to optimize Log Analytics pricing and how to set it up. |Colorkrew Security
An easy-to-understand explanation of how to integrate AWS CloudTrail and VPC Flow Logs with Microsoft Sentinel using Azure Functions. A hands-on step-by-step guide for those looking to enhance security monitoring for their multi-cloud environments. Colorkrew Security Blog
Learn how to easily integrate CrowdStrike logs with Microsoft Sentinel. This course explains the process of using Azure Functions to acquire data from Falcon Data Replicator via AWS in an easy-to-understand manner even for beginners. Learn how to achieve real-time threat detection and automated incident response to reduce the burden on SOC operations. |Colorkrew Security