Dec 4, 2020
Azure Sentinel, our cloud-native SIEM - XDR capabilities
The XDR capabilities of Microsoft Defender delivered through Azure Defender and Microsoft 365 Defender provides rich insights and prioritized alerts, but to gain visibility across your entire environment and include data from other security solutions such as firewalls and existing security tools, we connect Microsoft Defender to Azure Sentinel, our cloud-native SIEM.
Azure Sentinel is deeply integrated with Microsoft Defender so you can integrate your XDR data in only a few clicks and combine it with all your security data from across your entire enterprise.
Today, we are announcing new features within Azure Sentinel:
- The new entity behavior analytics view makes it easier to diagnose compromised accounts or malicious insiders.
- Simplify management of threat intelligence by including the ability to search, add, and track threat indictors, perform threat intelligence lookups, and create watchlists. To learn more about these in detail, check out the Azure Sentinel blog.
Read more
Microsoft delivers unified SIEM and XDR to modernize security operations - Microsoft Security