詳細検索
Avatar

西田

Logs are meaningless just by collecting them|Operational points to make use of them

Logs are meaningless just by collecting them|Operational points to make use of them

Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security

Microsoft Top Partner Engineer Award 2025|Security Operations Optimization Case Study

Microsoft Top Partner Engineer Award 2025|Security Operations Optimization Case Study

Colorkrew's Nishida received the "Microsoft Top Partner Engineer Award 2025 (Security Category)". Explain the efforts and results of security integration management and operational automation using Microsoft Sentinel. |Colorkrew Security

Have you seen all the security alerts? Microsoft Defender's Noise Reduction

Have you seen all the security alerts? Microsoft Defender's Noise Reduction

Are you having too many Microsoft Defender alerts? In this article, we will explain noise reduction techniques to eliminate alert fatigue. We will introduce the key points of severity setting, handling automatic remediation, and operation rule design, and propose effective alert operation and optimization methods. |Colorkrew Security

You can do this with Microsoft 365 logs! Analysis techniques to detect signs of internal fraud!

You can do this with Microsoft 365 logs! Analysis techniques to detect signs of internal fraud!

Microsoft 365 audit and sign-in logs can help you quickly spot signs of internal fraud. In this article, we will explain abnormal behavior patterns in OneDrive, Teams, etc., with specific examples, and introduce effective analysis methods and countermeasures. |Colorkrew Security

Thorough explanation of the differences between CSIRT and PSIRT|Summary of roles, scope of response, and necessity

Thorough explanation of the differences between CSIRT and PSIRT|Summary of roles, scope of response, and necessity

Explain the difference between CSIRT and PSIRT in an easy-to-understand manner. We will organize the roles and scope of CSIRT to protect the company and PSIRT to protect products in a comparison table in a comparison table, and introduce points that are easy to misunderstand and points to note when introducing them. |Colorkrew Security

How to gain holistic visibility into attacks with Defender for Endpoint timeline logs

How to gain holistic visibility into attacks with Defender for Endpoint timeline logs

Learn how to use Microsoft Defender for Endpoint timeline logs to gain time-series visibility into the full picture of attacks. We will also introduce key points for using KQL, visualization, and incident response. |Colorkrew Security

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel

Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog

Create custom alerts with Microsoft Sentinel! How to design security rules for your company

Create custom alerts with Microsoft Sentinel! How to design security rules for your company

Learn how to create custom alerts for your company in Microsoft Sentinel. We will introduce in detail useful information for practical work, from query design and notification settings using KQL. Colorkrew Security Blog

How Microsoft Sentinel automation can dramatically streamline security operations

How Microsoft Sentinel automation can dramatically streamline security operations

Streamline security operations with Microsoft Sentinel automation! From log integration to alert response, we will explain the optimal implementation method combined with SOC support. |Colorkrew Security

Worried about the cost of Sentinel? 3 points to keep Log Analytics costs down

Worried about the cost of Sentinel? 3 points to keep Log Analytics costs down

For those who are worried about reducing costs with Microsoft Sentinel. Here are three specific measures to optimize Log Analytics pricing and how to set it up. |Colorkrew Security

How to integrate AWS logs with Microsoft Sentinel – Leverage Azure Functions

How to integrate AWS logs with Microsoft Sentinel – Leverage Azure Functions

An easy-to-understand explanation of how to integrate AWS CloudTrail and VPC Flow Logs with Microsoft Sentinel using Azure Functions. A hands-on step-by-step guide for those looking to enhance security monitoring for their multi-cloud environments. Colorkrew Security Blog

How to easily integrate CrowdStrike logs with Microsoft Sentinel – with Azure Functions

How to easily integrate CrowdStrike logs with Microsoft Sentinel – with Azure Functions

Learn how to easily integrate CrowdStrike logs with Microsoft Sentinel. This course explains the process of using Azure Functions to acquire data from Falcon Data Replicator via AWS in an easy-to-understand manner even for beginners. Learn how to achieve real-time threat detection and automated incident response to reduce the burden on SOC operations. |Colorkrew Security