
Now that attackers are leveraging AI, automation is essential for defenders. How will the use of AI change security operations, such as anomaly detection, alert prioritization, and automatic response through SOAR? We will explain realistic defense strategies in which humans and AI work together. |Colorkrew Security

To prevent lateral movement after intrusion, it is essential to have a multi-layered defense of privilege management, network isolation, and behavior detection. Based on the concept of Assume Breach, we will explain practical measures that can be used in common with Azure, AWS, and GCP. |Colorkrew Security

Systematically explains ransomware attack methods, damage risks, and multi-layered defense practices. Introducing a realistic defense model that includes EDR, SIEM, and backup strategies|Colorkrew Security

Logs can be analyzed, but they cannot determine whether they are a threat - a "decision-making barrier" that many companies face. Explanation of how to mature SOC through judgment criteria, risk assessment, and knowledge|Colorkrew Security

Alert fatigue in SOC operations is caused by false positives and labor shortages. In this article, we'll explore specific ways to reduce the burden, such as improving alert accuracy, automating prioritization, and implementing SOAR. Colorkrew Security Blog

Learn about the key features of Microsoft Defender for Office 365. Learn more about how to protect against phishing and malware, the difference between P1 and P2 plans, and how to deploy them. Colorkrew Security Blog