Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security
Explains the purpose, scenario design, system building, and specific methods of ransomware attack exercises led by CSIRT. Practical Security Training to Enhance Detection and Response|Colorkrew Security
It explains the basics of DLP (Data Loss Prevention), implementation and operation points, and how to use Microsoft Purview. Systematic understanding of information leakage countermeasures due to internal fraud and mistransmission|Colorkrew Security
Explaining how Defender for Identity detects lateral deployment and privilege escalation attacks targeting Active Directory, how it differs from EDR and SIEM, and how it can be used in SOC operations|Colorkrew Security
Now that supply chain attacks are rapidly increasing, companies must review their "connections". Easy-to-understand explanation of practical measures such as zero trust implementation, log integration, and monitoring system|Colorkrew Security
Distributed log management doesn't give you a complete picture of an attack. Log integration realizes correlation analysis, early detection, and man-hour reduction, and strengthens defenses with "lines" rather than "points". Explain the key points of integrated management that are essential in the cloud era. |Colorkrew Security
Explain the differences between Microsoft Entra ID sign-in logs and audit logs and how to use them. We have summarized the key points of log management that are essential for unauthorized access detection and audit response. |Colorkrew Security
Learn how to deploy Microsoft Sentinel for free or cheaply. Focus on Entra ID logs to reduce costs and start security operations small. Colorkrew Security Blog
Microsoft Entra's recommendation function provides visibility into your company's security risks and strengthens countermeasures. It also explains how to improve MFA and permission settings. |Colorkrew Security
Learn about Entra ID's Conditional Access feature. Learn how to control access to cloud services and improve security levels. It also covers proper policy design and enhanced monitoring by leveraging Azure Monitor and Microsoft Sentinel. Streamline your enterprise's security operations and achieve stronger defenses with comprehensive support from Colorkrew Security. |Colorkrew Security
Learn more about how to leverage Microsoft Defender for Cloud Apps to manage shadow IT risk in your enterprise. Introduce specific configuration and operation tips to strengthen the security of cloud environments and prevent information leaks and security vulnerabilities. This is a must-see practical guide for IT professionals. Colorkrew Security Blog
Microsoft 365 audit logs are essential for security measures and compliance. In this article, we will explain in detail the types of audit logs, how to obtain them, and the importance of retention period. Learn how to manage properly and strengthen your company's information security! | Colorkrew Security Blog