
A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security

Are you having too many Microsoft Defender alerts? In this article, we will explain noise reduction techniques to eliminate alert fatigue. We will introduce the key points of severity setting, handling automatic remediation, and operation rule design, and propose effective alert operation and optimization methods. |Colorkrew Security

How will you respond to the new management measures in ISMS 2022? Specific examples of security monitoring, web filtering, and secure coding are explained. |Colorkrew Security

Learn more about how to leverage Microsoft Defender for Cloud Apps to manage shadow IT risk in your enterprise. Introduce specific configuration and operation tips to strengthen the security of cloud environments and prevent information leaks and security vulnerabilities. This is a must-see practical guide for IT professionals. Colorkrew Security Blog