
Experts will explain the setting conditions and "three principles" to ensure that serious incidents are not overlooked regarding automatic closing of alerts, which is an issue in SOC operations. The secrets of safe automation design, such as the importance of Severity limited and logging and weekly reviews to prevent accidents, are now available. Dramatically improve your own operations. |Colorkrew Security

A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security

Have you adopted Microsoft Sentinel but are tired of dealing with a high volume of alerts? A security engineer explains the key points of prioritizing rules, tuning to suit the environment, and notification design to avoid becoming a "noisy SIEM". Here are some practical improvement approaches that don't make operations a reality. |Colorkrew Security

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

Microsoft Sentinel and Azure Data Lake Storage work together to optimize costs and provide analytics foundation flexibility. Explaining the latest design that separates real-time detection from long-term storage|Colorkrew Security

Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security

Colorkrew's Nishida received the "Microsoft Top Partner Engineer Award 2025 (Security Category)". Explain the efforts and results of security integration management and operational automation using Microsoft Sentinel. |Colorkrew Security
![[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel](https://ckmediastgstr.blob.core.windows.net/uploads/post_43_00_d182f4947e.png)
Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog

Learn how to create custom alerts for your company in Microsoft Sentinel. We will introduce in detail useful information for practical work, from query design and notification settings using KQL. Colorkrew Security Blog

Learn how to deploy Microsoft Sentinel for free or cheaply. Focus on Entra ID logs to reduce costs and start security operations small. Colorkrew Security Blog

Streamline security operations with Microsoft Sentinel automation! From log integration to alert response, we will explain the optimal implementation method combined with SOC support. |Colorkrew Security

Enhance security with Microsoft Sentinel! Learn how log integration and SOC can detect threats in real time and reduce operational load. |Colorkrew Security