
Explain the causes of SOC fatigue due to too many alerts and five practical points for operational design to prevent the risk of missing incidents and personalization. Learn how to build a sustainable SOC with automation, prioritization design, and knowledge standardization. |Colorkrew Security

Explains the pitfall of security operation, "I take logs but don't notice the attack". From the perspective of an infrastructure engineer, we will introduce five steps to transform logs from mere storage objects into "defensive weapons" using correlation analysis and automatic detection. |Colorkrew Security

A collection of KQL templates for combat that dramatically streamline investigations in Microsoft Sentinel and Defender. Active engineers publish queries that instantly identify suspicious behavior from three starting points: sign-in, terminal, and email. What are the tips for speeding up initial response by 10 times and standardizing security operations? |Colorkrew Security

Have you adopted Microsoft Sentinel but are tired of dealing with a high volume of alerts? A security engineer explains the key points of prioritizing rules, tuning to suit the environment, and notification design to avoid becoming a "noisy SIEM". Here are some practical improvement approaches that don't make operations a reality. |Colorkrew Security

SOC engineers explain what MITRE is and how CVEs and MITRE ATT&CK are used in security operations in an easy-to-understand manner. Basic knowledge for beginners to help you understand the overall picture of attacks and strengthen defenses|Colorkrew Security

Explains the types and risks of supply chain attacks and the defense measures that should be implemented throughout the organization from an expert's perspective. From Account Evaluation to Monitoring|Colorkrew Security
![Why security personnel should invest in "integrated log management" [Improve operational efficiency and detection]](https://ckmediastgstr.blob.core.windows.net/uploads/post_65_00_8c78290c74.jpg)
Distributed log management doesn't give you a complete picture of an attack. Log integration realizes correlation analysis, early detection, and man-hour reduction, and strengthens defenses with "lines" rather than "points". Explain the key points of integrated management that are essential in the cloud era. |Colorkrew Security

With the ever-increasing number of vulnerabilities, it's impossible to keep up with everything. In this article, we will explain how to efficiently manage vulnerabilities with limited resources by utilizing EPSS (Exploit Prediction Scoring System), which predicts the likelihood of exploitation. We also introduce the differences from CVSS and tips for using it together. |Colorkrew Security

Should all dependent library vulnerabilities be addressed? Learn how GitHub Dependabot and risk-based management can help you focus on critical vulnerabilities. |Colorkrew Security

Utilize Azure WAF's Bot Protection feature to protect your website from malicious bots and explain specific setup steps and practical measures. This is a must-see for businesses considering implementing or reviewing a WAF. |Colorkrew Security

Learn about Entra ID's Conditional Access feature. Learn how to control access to cloud services and improve security levels. It also covers proper policy design and enhanced monitoring by leveraging Azure Monitor and Microsoft Sentinel. Streamline your enterprise's security operations and achieve stronger defenses with comprehensive support from Colorkrew Security. |Colorkrew Security