cd .. (Geri Dön)
siem-kutuphanesi/detection-use-cases/detection-use-cases-cloud-azure.md

Azure

Azure'da Sentinel'in algılama kuralları.

Orta SeviyeT1078.004T1098T1580T1530T1078Azure Activity LogAzure AD Sign-in LogsMicrosoft SentinelDefender for Cloud

Azure'da Sentinel'in algılama kuralları.

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureActivity →

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureActivity

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureAppServices →

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureAppServices

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureDevOpsAuditing →

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureDevOpsAuditing

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureDiagnostics →

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureDiagnostics

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureFirewall →

https://github.com/Azure/Azure-Sentinel/tree/master/Detections/AzureFirewall

"Azure Active Directory Arka Kapıları Nasıl Tespit Edilir"

https://www.inversecos.com/2021/11/how-to-detect-azure-active-directory.html →

https://www.inversecos.com/2021/11/how-to-detect-azure-active-directory.html

Breakglass hesaplarının kullanımını tespit etmek çok iyi bir uygulamadır

https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access →

https://learn.microsoft.com/en-us/entra/identity/role-based-access-control/security-emergency-access

INTERACTIVE_TOOLS.sh
Siber Güvenlik Test & Analiz Araçları
$./soc-maturity-test.sh

Kurumunuzun güvenlik operasyon merkezi (SOC) olgunluk seviyesini, tehdit algılama ve müdahale (MTTD/MTTR) sürelerini hızlıca ölçün.

[ TESTİ BAŞLAT ]
$./mitre-attack-coverage.sh

SIEM kullanım senaryolarımızın MITRE ATT&CK matrisi üzerindeki kapsamını ve ısı haritasını (taktik/teknik eşleşmelerini) interaktif görün.

[ MATRİSİ İNCELE ]
SIGMA_RULES.yml

İlgili Sigma Algılama Kuralları

Bu senaryoyla ilişkili 1 adet Sigma kuralı bulundu. Kuralları genişleterek YAML formatında görebilir, kopyalayabilir veya SIEM formatına dönüştürebilirsiniz.

🛡️ INTEGRATION.md

ACKLOG SIEM İle Tam Entegrasyon

Bu dokümantasyonda listelenen log kaynakları, kurallar, korelasyon mantıkları ve tespit senaryoları ACKLOG SIEM ürün ailesi tarafından yerleşik olarak desteklenmektedir. ACKLOG, teknolojisi ve otomasyon modülleri ile tespit süreçlerinizi saniyeler içinde devreye almanızı sağlar.