Alert Pack: Azure
Purpose
This alert pack brings our Security Operations related content to our non-Security Operations customers and helps jump-start threat coverage. Inside this pack we have a multitude of detections that alert when an attacker is trying to attack Microsoft Azure environments.
Â
What is Azure?
Azure is a market leader in public clouds and is used by many companies across the globe. Devo recognizes the importance of securing your cloud infrastructure and has decided to become a market leader in out-of-the-box detections for Microsoft Azure. These detections protect all aspects of Azure ranging from Active Directory to DevOps. We want to ensure that our customers are accurately covered and can rest assured that these detections will alert them for most attacks they face.
Prerequisites
To use this alert pack, you must have the following data sources available on your domain:
cloud.azure
learn morecloud.azure.ad.audit
learn morecloud.azure.activity.events
learn morecloud.azure.ad.signin
learn morecloud.azure.eh.events
learn more
Open alert pack
Once you have installed the alert pack, you can use the Open button at the top right of the card in Exchange to access the Alert configuration, where you can apply filters to find it and later manage it as required. You can also access this area via the Navigation pane (Administration → Alert Configuration → Available alerts).
Use alert pack
The alerts in the alert pack are deactivated by default when the alert pack is installed. Access the Alert configuration area to activate those you need and assign sending policies to receive them through the desired channels.