詳細検索
Avatar

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

How to choose a SIEM that won't fail|How to compare the purpose × operation design

How to choose a SIEM that won't fail|How to compare the purpose × operation design

Explains the purpose, scenario design, system building, and specific methods of ransomware attack exercises led by CSIRT. Practical Security Training to Enhance Detection and Response|Colorkrew Security

What is DLP? Basics and introduction points to prevent internal information leakage

What is DLP? Basics and introduction points to prevent internal information leakage

It explains the basics of DLP (Data Loss Prevention), implementation and operation points, and how to use Microsoft Purview. Systematic understanding of information leakage countermeasures due to internal fraud and mistransmission|Colorkrew Security

Active Directory Defense Essentials|Defender for Identity Explained

Active Directory Defense Essentials|Defender for Identity Explained

Explaining how Defender for Identity detects lateral deployment and privilege escalation attacks targeting Active Directory, how it differs from EDR and SIEM, and how it can be used in SOC operations|Colorkrew Security

Why is it essential to take measures against "supply chain attacks" now? Practical measures that companies should take

Why is it essential to take measures against "supply chain attacks" now? Practical measures that companies should take

Now that supply chain attacks are rapidly increasing, companies must review their "connections". Easy-to-understand explanation of practical measures such as zero trust implementation, log integration, and monitoring system|Colorkrew Security

Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]

Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]

Distributed log management doesn't give you a complete picture of an attack. Log integration realizes correlation analysis, early detection, and man-hour reduction, and strengthens defenses with "lines" rather than "points". Explain the key points of integrated management that are essential in the cloud era. |Colorkrew Security

In-depth Explanation of Entra ID Sign-in Logs and Audit Logs|Unauthorized Access Detection and Audit Response

In-depth Explanation of Entra ID Sign-in Logs and Audit Logs|Unauthorized Access Detection and Audit Response

Explain the differences between Microsoft Entra ID sign-in logs and audit logs and how to use them. We have summarized the key points of log management that are essential for unauthorized access detection and audit response. |Colorkrew Security

Try Microsoft Sentinel for free! Cheap Small Start Technique with Entra ID Integration

Try Microsoft Sentinel for free! Cheap Small Start Technique with Entra ID Integration

Learn how to deploy Microsoft Sentinel for free or cheaply. Focus on Entra ID logs to reduce costs and start security operations small. Colorkrew Security Blog

Visualize security risks with Microsoft Entra's recommendation function! Ideal for MFA and privilege review

Visualize security risks with Microsoft Entra's recommendation function! Ideal for MFA and privilege review

Microsoft Entra's recommendation function provides visibility into your company's security risks and strengthens countermeasures. It also explains how to improve MFA and permission settings. |Colorkrew Security

Entra ID's main features! A Thorough Look at Conditional Access: The Key to Enhanced Security

Entra ID's main features! A Thorough Look at Conditional Access: The Key to Enhanced Security

Learn about Entra ID's Conditional Access feature. Learn how to control access to cloud services and improve security levels. It also covers proper policy design and enhanced monitoring by leveraging Azure Monitor and Microsoft Sentinel. Streamline your enterprise's security operations and achieve stronger defenses with comprehensive support from Colorkrew Security. |Colorkrew Security

How to use Microsoft Defender for Cloud Apps to enhance cloud security

How to use Microsoft Defender for Cloud Apps to enhance cloud security

Learn more about how to leverage Microsoft Defender for Cloud Apps to manage shadow IT risk in your enterprise. Introduce specific configuration and operation tips to strengthen the security of cloud environments and prevent information leaks and security vulnerabilities. This is a must-see practical guide for IT professionals. Colorkrew Security Blog

[Thorough explanation] What are the types, acquisitions, and storage of Microsoft 365 audit logs?

[Thorough explanation] What are the types, acquisitions, and storage of Microsoft 365 audit logs?

Microsoft 365 audit logs are essential for security measures and compliance. In this article, we will explain in detail the types of audit logs, how to obtain them, and the importance of retention period. Learn how to manage properly and strengthen your company's information security! | Colorkrew Security Blog