Microsoft Sentinel Integration - Go Tanium Tech Talks #47

Опубликовано: 18 Октябрь 2024
на канале: Tanium
1,932
22

Increase the efficiency of security operations by combining Tanium's real-time visibility and control with the Microsoft Sentinel cloud-native SIEM solution.

Cybersecurity teams have many tools in their arsenal today, and half the battle is spent switching context between those tools. Imagine if you could use a single console to triage alerts, request more live endpoint data, remediate, and more. And then at scale imagine automating alert responses with Tanium actions like LiveResponse data collection, quarantine, and more.

This scenario is now reality with the combination of two world-class platforms: Tanium and Microsoft Sentinel. Tanium has integrated with native Microsoft capabilities for years. Now that integration extends to the cloud with Microsoft's Sentinel SIEM and SOAR platform:

-Tanium signal alerts feed into Sentinel
-Workbooks for Sentinel show additional context from Tanium Threat Response, Comply, Discover, and more
-Sentinel actions and playbooks can call Tanium actions like retrieving compliance data, quarantining an endpoint, checking Microsoft client health, and more
-Automation of alert triage at scale by calling Tanium actions with automation rules

Watch the power of this integration in action on today's Go Tanium Tech Talk.

Community article: Integrate with Microsoft Azure Log Analytics and Sentinel Using Tanium Connect
https://community.tanium.com/s/articl...

CHAPTERS
00:00 Intro
00:24 Converge
01:06 Intro
01:55 Meet Sam
03:17 Sentinel integration
05:04 SIEM & SOAR
05:57 DEMO Data Connector
07:11 DEMO Workbooks
08:45 Efficiency
09:50 DEMO Incidents & Alerts
12:45 DEMO Playbooks & Actions
16:11 DEMO Automation Rules
18:45 Automation over Threat Response
19:27 How do I get this?
20:32 Cloud vs on prem?
21:20 Feedback
22:30 Documentation
23:08 Final remarks
23:48 Summary

#informationsecurity #informationtechnology #siem #soar #secops #infosec #cybersecurity #dfir #soc