Skip to content

Latest commit

 

History

History
24 lines (13 loc) · 1.36 KB

Introduction.md

File metadata and controls

24 lines (13 loc) · 1.36 KB

What is a SIEM?

Microsoft Sentinel is a Security information and event management (SIEM). A SIEM system combines outputs from multiple sources and uses alarm filtering techniques to distinguish malicious activity from false alarms.

A lot of security solutions exist which cater to specific needs of an organiation. A SIEM sits at the centre itegrating and collecting data from all these solutions.

Security Solutions

The Microsoft Security Stack for Security Operations Center

MCRA

Where does Defender for Cloud fit into this

Defender for Cloud was originally designed to be a Cloud Workload Posture Protection(CWPP) service which can help protect all infrastructure in Azure and other major clouds.

Defender for Cloud also includes Azure Defender which is the EDR/XDR solution for Cloud and selected on-prem workloads. More details can be found here.

What is Microsoft Sentinel?

MIcrosoft Sentinel is Microsoft's cloud native SIEM (Security Information and Event Management) + SOAR(Security Ochestration and Response) and has the capability to monitor and remediate several workloads in Azure, Other Clouds as well as On-Premises.

More Details