詳細検索

Microsoft Sentinel


How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?
Security
February 23, 2026
2分で読めます

How to Use Microsoft Sentinel|What is Automation Design to Avoid Missing Critical Incidents?

Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security

3 KQL templates that can be used with Microsoft Sentinel! Tips for speeding up incident investigations
Security
February 22, 2026
3分で読めます

3 KQL templates that can be used with Microsoft Sentinel! Tips for speeding up incident investigations

A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security

Don't let Microsoft Sentinel end up being "just noisy." 3 tips to keep your operations from becoming a formality
Security
February 16, 2026
3分で読めます

Don't let Microsoft Sentinel end up being "just noisy." 3 tips to keep your operations from becoming a formality

Have you adopted Microsoft Sentinel but are tired of dealing with a high volume of alerts? A security engineer explains the key points of prioritizing rules, tuning to suit the environment, and notification design to avoid becoming a "noisy SIEM". Here are some practical improvement approaches that don't make operations a reality. |Colorkrew Security

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points
Security
January 22, 2026
4分で読めます

Log Selection Guide to Avoid Failure in SIEM Implementation|Priorities and Practical Points

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

New design for log operations optimization with Microsoft Sentinel × Data Lake
Security
October 15, 2025
3分で読めます

New design for log operations optimization with Microsoft Sentinel × Data Lake

Microsoft Sentinel and Azure Data Lake Storage work together to optimize costs and provide analytics foundation flexibility. Explaining the latest design that separates real-time detection from long-term storage|Colorkrew Security

Logs are meaningless just by collecting them|Operational points to make use of them
Security
September 29, 2025
3分で読めます

Logs are meaningless just by collecting them|Operational points to make use of them

Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security

Microsoft Top Partner Engineer Award 2025|Security Operations Optimization Case Study
Security
September 28, 2025
2分で読めます

Microsoft Top Partner Engineer Award 2025|Security Operations Optimization Case Study

Colorkrew's Nishida received the "Microsoft Top Partner Engineer Award 2025 (Security Category)". Explain the efforts and results of security integration management and operational automation using Microsoft Sentinel. |Colorkrew Security

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel
Security
August 4, 2025
2分で読めます

[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel

Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog

Create custom alerts with Microsoft Sentinel! How to design security rules for your company
Security
August 1, 2025
2分で読めます

Create custom alerts with Microsoft Sentinel! How to design security rules for your company

Learn how to create custom alerts for your company in Microsoft Sentinel. We will introduce in detail useful information for practical work, from query design and notification settings using KQL. Colorkrew Security Blog

Try Microsoft Sentinel for free! Cheap Small Start Technique with Entra ID Integration
Security
July 30, 2025
4分で読めます

Try Microsoft Sentinel for free! Cheap Small Start Technique with Entra ID Integration

Learn how to deploy Microsoft Sentinel for free or cheaply. Focus on Entra ID logs to reduce costs and start security operations small. Colorkrew Security Blog

How Microsoft Sentinel automation can dramatically streamline security operations
Security
May 17, 2025
5分で読めます

How Microsoft Sentinel automation can dramatically streamline security operations

Streamline security operations with Microsoft Sentinel automation! From log integration to alert response, we will explain the optimal implementation method combined with SOC support. |Colorkrew Security

Protect your enterprise with Microsoft Sentinel! Next-generation security starts with log integration and SOC
Security
May 11, 2025
5分で読めます

Protect your enterprise with Microsoft Sentinel! Next-generation security starts with log integration and SOC

Enhance security with Microsoft Sentinel! Learn how log integration and SOC can detect threats in real time and reduce operational load. |Colorkrew Security