
Now that attackers are leveraging AI, automation is essential for defenders. How will the use of AI change security operations, such as anomaly detection, alert prioritization, and automatic response through SOAR? We will explain realistic defense strategies in which humans and AI work together. |Colorkrew Security

To prevent lateral movement after intrusion, it is essential to have a multi-layered defense of privilege management, network isolation, and behavior detection. Based on the concept of Assume Breach, we will explain practical measures that can be used in common with Azure, AWS, and GCP. |Colorkrew Security

Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security

OSINT Explains Admin Page Identification and SQL Injection Attack Flow, WAF Evasion Methods, Detection Methods, and Defense-in-Depth Practices|Colorkrew Security

Practical Explanation of Log Selection Concepts Important in SIEM Implementation from the Perspective of Priority and Cost of Authentication, EDR, Network, and Cloud Logs|Colorkrew Security

Systematically explains ransomware attack methods, damage risks, and multi-layered defense practices. Introducing a realistic defense model that includes EDR, SIEM, and backup strategies|Colorkrew Security
![Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]](https://ckmediastgstr.blob.core.windows.net/uploads/post_65_00_8c78290c74.jpg)
Distributed log management doesn't give you a complete picture of an attack. Log integration realizes correlation analysis, early detection, and man-hour reduction, and strengthens defenses with "lines" rather than "points". Explain the key points of integrated management that are essential in the cloud era. |Colorkrew Security

Logs are meaningless just by collecting them. We will explain in an easy-to-understand manner the key points of "usable log operation" using Microsoft Sentinel and Defender, as well as examples of failures and improvement measures. |Colorkrew Security
![[With KQL commentary] How to create custom alerts to detect logon failures in Microsoft Sentinel](https://ckmediastgstr.blob.core.windows.net/uploads/post_43_00_d182f4947e.png)
Detect brute force attacks early with Microsoft Sentinel! Learn how to create custom alerts and integrate Logic Apps to avoid missing a lot of logon failures. Colorkrew Security Blog

Are you wondering whether to operate your own SOC or outsource it? In this article, we will explain in detail the importance of outsourcing through examples of SOC operation failures. It shows how companies with talent shortages, cost management, and the risk of false positives can solve their challenges by outsourcing. If you're looking for tips to streamline your security operations and reduce risk, check out this one. |Colorkrew Security

Alert fatigue in SOC operations is caused by false positives and labor shortages. In this article, we'll explore specific ways to reduce the burden, such as improving alert accuracy, automating prioritization, and implementing SOAR. Colorkrew Security Blog

Explain how to integrate Azure logs with Microsoft Sentinel for beginners. It also explains the key points of supporting efficient log management and security enhancement, utilizing KQL, and monitoring operations. Colorkrew Security Blog