{"id":24255,"date":"2024-04-15T08:33:12","date_gmt":"2024-04-15T16:33:12","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2024\/04\/15\/news-17985\/"},"modified":"2024-04-15T08:33:12","modified_gmt":"2024-04-15T16:33:12","slug":"news-17985","status":"publish","type":"post","link":"https:\/\/www.palada.net\/index.php\/2024\/04\/15\/news-17985\/","title":{"rendered":"Get end-to-end protection with Microsoft&#8217;s unified security operations platform, now in public preview"},"content":{"rendered":"<p><strong>Credit to Author: Rob Lefferts| Date: Wed, 03 Apr 2024 16:00:00 +0000<\/strong><\/p>\n<p>Today, I am excited to announce the public preview of our unified security operations platform. When we announced a limited preview in November 2023, it was one of the first security operations center platforms that brought together the full capabilities of an industry-leading cloud-native security information and event management (SIEM), comprehensive extended detection and response (XDR), and generative AI built specifically for cybersecurity. This powerful <a href=\"https:\/\/www.microsoft.com\/security\/business\/solutions\/siem-xdr-threat-protection\">combination of capabilities<\/a> delivers a truly unified analyst experience in the security operations center (SOC).<\/p>\n<p>And last month at Microsoft Secure, we added unified exposure management capabilities that provide continuous, proactive end-to-end visibility of assets and cyberattack paths. Together, these fully integrated, comprehensive capabilities give security leaders and SOC teams what they need to manage cyberthreats across their organization\u2014from prevention to detection and response.<\/p>\n<p>After gaining insights from the initial customer feedback, we are excited to expand the platform\u2019s availability to public preview. Customers with a single Microsoft Sentinel workspace and at least one Defender XDR workload deployed can start enjoying the benefits of a unified experience, in a production environment, now. Onboarding a Microsoft Sentinel workspace only takes a few minutes, and customers can continue to use their Microsoft Sentinel in Azure. Need another reason to <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/security\/defender\/microsoft-sentinel-onboard?view=o365-worldwide\" target=\"_blank\" rel=\"noreferrer noopener\">get started today<\/a>? Microsoft Sentinel customers using Microsoft Copilot for Security can now leverage the embedded experience in the <a href=\"https:\/\/security.microsoft.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Defender portal<\/a>, helping them to level up their security practice further. <\/p>\n<div class=\"wp-block-msxcm-cta-block\" data-moray data-bi-an=\"CTA Block\">\n<div class=\"card d-block mx-ng mx-md-0\">\n<div class=\"row no-gutters material-color-brand-dark\">\n<div class=\"d-flex col-md\">\n<div class=\"card-body align-self-center p-4 p-md-5\">\n<h2>Unified security operations platform<\/h2>\n<div class=\"mb-3\">\n<p>The new platform brings together the capabilities of XDR and SIEM. Learn how to onboard your Microsoft Sentinel workspace to the Microsoft Defender portal.<\/p>\n<\/p><\/div>\n<div class=\"link-group\"> \t\t\t\t\t\t\t<a href=\"https:\/\/aka.ms\/onboard-microsoft-sentinel\" class=\"btn btn-primary bg-body text-body\" target=\"_blank\"> \t\t\t\t\t\t\t\t<span>Get started today<\/span> \t\t\t\t\t\t\t\t<span class=\"glyph-append glyph-append-chevron-right glyph-append-xsmall\"><\/span> \t\t\t\t\t\t\t<\/a> \t\t\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<div class=\"col-md-4\"> \t\t\t\t\t<img loading=\"lazy\" decoding=\"async\" width=\"609\" height=\"600\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/SEC20_Security_041-1_600.jpg\" class=\"card-img img-object-cover\" alt=\"Side view of a man, with monitors in the background, and a graphic design overlay\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/SEC20_Security_041-1_600.jpg 609w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/SEC20_Security_041-1_600-300x296.jpg 300w\" sizes=\"auto, (max-width: 609px) 100vw, 609px\" \/>\t\t\t\t<\/div>\n<\/p><\/div>\n<\/p><\/div>\n<\/p><\/div>\n<h2 class=\"wp-block-heading\" id=\"knock-down-security-silos-and-drive-better-security-outcomes\">Knock down security silos and drive better security outcomes<\/h2>\n<p>SOCs are buried under mountains of alerts, security signals, and initiatives. Analysts are spending too much time sifting through low-level alerts, jumping between portals, and navigating complex workflows to understand what happened, how to resolve it, and how to prevent it from happening again. This leaves little time for analysts to focus on high-value tasks\u2014like remediating multistage incidents fully or even decreasing the likelihood of future attacks by reducing the attack surface. With an ever-growing gap in supply and demand of talent\u2014in fact, there are only enough cybersecurity professionals to meet 82% of the United States demand\u2014something must change.<sup>1<\/sup>&nbsp;<\/p>\n<p>At the heart of this challenge is siloed data\u2014SOCs have too much security data stored in too many places and most SOC teams lack the tools to effectively bring it all together, normalize it, apply advanced analytics, enrich with threat intelligence, and act on the insights across the entire digital estate. This is why we built the security operations platform\u2014by bringing together the full capabilities of SIEM, XDR, exposure management, generative AI, and threat intelligence together, security teams will be empowered with unified, comprehensive features that work across use cases, not security tool siloes.<\/p>\n<p>The new analyst experience is built to create a more intuitive workflow for the SOC, with unified views of incidents, exposure, threat intelligence, assets, and security reporting. This is a true single pane of glass for security across your entire digital estate. Beyond delivering a single experience, unifying these features all on one platform delivers more robust capabilities across the entire cyberattack lifecycle.<\/p>\n<p>\u201cSecurity teams need a single pane of glass to manage today\u2019s IT environments. Long gone are the days when teams could operate in silos and protect their environments. With today\u2019s announcement Microsoft is moving another step forward in helping businesses protect their systems, customers and reputations,\u201d said Chris Kissel, IDC Research Vice President, Security and Trust. &#8220;Microsoft combining the full capabilities of an industry-leading cloud-native SIEM and XDR with the first generative AI built specifically for cybersecurity is a game changer for the industry.&#8221;&nbsp;&nbsp;<\/p>\n<p>Capabilities across <a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-sentinel\">Microsoft Sentinel<\/a> and <a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-defender-xdr\">Microsoft Defender XDR<\/a> products are now extending, making both Microsoft Sentinel and Defender XDR more valuable. XDR customers can now enjoy more flexibility in their reporting, their ability to deploy automations, and greater insight across data sources. With the new ability to run custom security orchestration, automation, and response (SOAR) playbooks on an incident provided by Microsoft Sentinel, Defender XDR customers can reduce repetitive processes and further optimize the SOC. They can also now hunt across their XDR and SIEM data in one place. Further, XDR detection and incident creation will now open to data from SIEM. SIEM customers can now get more out of the box value, improving their ability to focus on the tasks at hand and gain more proactive protection against threats, freeing them to spend more time on novel threats and the unique needs of their environment.<\/p>\n<h2 class=\"wp-block-heading\" id=\"prevent-breaches-with-end-to-end-visibility-of-your-attack-surface\">Prevent breaches with end-to-end visibility of your attack surface<\/h2>\n<p>During the past 10 years, the enterprise attack surfaces have expanded exponentially with the adoption of cloud services, bring-your-own device, increasingly complex supply chains, Internet of Things (IoT), and more. Approximately 98% of attacks can be prevented with basic cybersecurity hygiene, highlighting the importance of hardening all systems.<sup>2<\/sup> Security silos make it more difficult and time-consuming to uncover, prioritize, and eliminate exposures.<\/p>\n<p>Fortunately, the <a href=\"https:\/\/www.microsoft.com\/security\/business\/siem-and-xdr\/microsoft-security-exposure-management\">Microsoft Security Exposure Management<\/a> solution, built right into the new unified platform experience, consolidates silos into a contextual and risk-based view. Within the unified platform, security teams gain comprehensive visibility across a myriad of exposures, including software vulnerabilities, control misconfigurations, overprivileged access, and evolving threats leading to sensitive data exposure. Organizations can leverage a single source of truth with unified exposure insights to proactively manage their asset risk across the entire digital estate. In addition, attack path modeling helps security professionals of all skill levels predict the potential steps adversaries may take to infiltrate your critical assets and reach your sensitive data.<\/p>\n<h2 class=\"wp-block-heading\" id=\"shut-down-in-progress-attacks-with-automatic-attack-disruption\">Shut down in-progress attacks&nbsp;with automatic attack disruption<\/h2>\n<p>In today\u2019s threat landscape, where multistage attacks are the new normal, automation is no longer optional, but a necessity. We\u2019ve seen entire ransomware campaigns that only needed two hours to complete, with attackers moving laterally in as little as five minutes after initial compromise\u2014the median time for attackers to access sensitive data is only 72 minutes.<sup>3<\/sup> This capability is essential to counter the rapid, persistent attack methods like an <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2023\/10\/11\/automatic-disruption-of-human-operated-attacks-through-containment-of-compromised-user-accounts\/\" target=\"_blank\" rel=\"noreferrer noopener\">AKIRA ransomware attack<\/a>. Even the best security teams need to take breaks and with mere seconds separating thousands versus millions of dollars spent on an attack, the speed of response becomes critical.<\/p>\n<p>This platform harnesses the power of XDR and AI to disrupt advanced attacks like ransomware, business email compromise, and adversary-in-the-middle attacks at machine speed with automatic attack disruption, a game-changing technology for the SOC that remains exclusive to Microsoft Security. Attack disruption is a powerful, out-of-the-box capability that automatically stops the progression and limits the impact of the most sophisticated attacks in near real-time. By stopping the attack progression, precious time is given back to the SOC to triage and resolve the incident.<\/p>\n<p>Attack disruption works by taking a wide breadth of signals across endpoints and IoT, hybrid identities, email and collaboration tools, software as a service (SaaS) apps, data, and cloud workloads and applying AI-driven, researcher-backed analytics to detect and disrupt in-progress attacks with 99% confidence.<sup>3<\/sup> With more than 78 trillion signals fueling our AI and machine learning models, we can rapidly detect and disrupt prominent attacks like ransomware in <strong>only three minutes, <\/strong>saving thousands of devices from encryption and recovery costs. Using our unique ability to recognize the intention of the attacker, meaning accurately predict their next move, Microsoft Defender XDR takes an automated response such as disabling a user account or isolating a device from connecting to any other resource in the network.&nbsp;<\/p>\n<p>Built on the attack disruption technology in our Defender XDR solution, our unified platform now extends this dynamic protection to new solutions through Microsoft Sentinel\u2014starting with SAP. When an SAP account attack is detected, our platform will <strong>automatically respond to cut off access in SAP.<\/strong> This means unprecedented protection for a platform that houses incredibly sensitive data, making it a prime target for attackers.<\/p>\n<h2 class=\"wp-block-heading\" id=\"investigate-and-respond-faster\">Investigate and respond faster<\/h2>\n<p>Multiple dashboards and siloed hunting experiences can really slow down the meantime to acknowledge and respond. The effectiveness of the SOC is measured by these critical metrics. Microsoft delivers a single incident queue, equipped with robust out-of-the-box rules, that saves time, reduces alert noise, and improves alert correlation, ultimately delivering a full view of an attack. During our private preview, <strong>customers saw up to an 80% reduction in incidents<\/strong>, with improved correlation of alerts to incidents across Microsoft Sentinel data sources, accelerating triage and response.<sup>4<\/sup> Further, unified hunting helps customers to reduce investigation time by eliminating the need to know where data is stored or to run multiple queries on different tables.<\/p>\n<p>We\u2019re not stopping at automatic attack disruption and unified incident queues\u2014we\u2019re on a mission to uplevel analysts of all experience levels.&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/business\/ai-machine-learning\/microsoft-copilot-security\">Microsoft Copilot for Security<\/a> helps security analysts accelerate their triage with comprehensive incident summaries that map to the MITRE framework, reverse-engineer malware, translate complex code to native language insights, and even complete multistage attack remediation actions with a single click.<\/p>\n<p>Copilot for Security is embedded in the analyst experience, providing analysts with an intuitive, intelligent assistant than can guide response and even create incident reports automatically\u2014saving analysts significant time. Early adopters are seeing their analysts move an average of&nbsp;22% faster&nbsp;and accelerate time to resolution.<sup>5<\/sup> Copilot for Security is more than a chatbot\u2014it\u2019s a true intelligent assistant built right into their workflow, helping them use their tools better, level up their skills, and get recommendations relevant to their work at hand.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-1024x560.webp\" alt=\"View of the unified SOC platform incident page, which includes Microsoft Sentinel and Defender XDR data and embedded Copilot for Security. This incident benefited from automatic attack disruption.\" class=\"wp-image-133861 webp-format\" srcset=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-1024x560.webp 1024w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-300x164.webp 300w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-768x420.webp 768w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-1536x840.webp 1536w, https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-2048x1120.webp 2048w\" data-orig-src=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/wp-content\/uploads\/2024\/03\/Picture1-4-1024x560.webp\"><\/figure>\n<p>If you\u2019d like to join the public preview, <a href=\"https:\/\/aka.ms\/onboard-microsoft-sentinel\" target=\"_blank\" rel=\"noreferrer noopener\">view the prerequisites<\/a> and how to connect your Microsoft Sentinel workplace.<\/p>\n<h2 class=\"wp-block-heading\" id=\"learn-more\">Learn more<\/h2>\n<p>Learn more about <a href=\"https:\/\/www.microsoft.com\/security\/business\/solutions\/siem-xdr-threat-protection\">Microsoft SIEM and XDR solutions<\/a>. <\/p>\n<p>To learn more about Microsoft Security solutions, visit our&nbsp;<a href=\"https:\/\/www.microsoft.com\/en-us\/security\/business\" target=\"_blank\" rel=\"noreferrer noopener\">website.<\/a>&nbsp;Bookmark the&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/\" target=\"_blank\" rel=\"noreferrer noopener\">Security blog<\/a>&nbsp;to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (<a href=\"https:\/\/www.linkedin.com\/showcase\/microsoft-security\/\">Microsoft Security<\/a>) and X (<a href=\"https:\/\/twitter.com\/@MSFTSecurity\" target=\"_blank\" rel=\"noreferrer noopener\">@MSFTSecurity<\/a>)&nbsp;for the latest news and updates on cybersecurity.<\/p>\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n<p><sup>1<\/sup><a href=\"https:\/\/www.cyberseek.org\/heatmap.html\" target=\"_blank\" rel=\"noreferrer noopener\">Cybersecurity Supply and Demand Heat Map<\/a>, CyberSeek. 2024.<\/p>\n<p><sup>2<\/sup><a href=\"https:\/\/www.microsoft.com\/security\/security-insider\/microsoft-digital-defense-report-2023\">Microsoft Digital Defense Report<\/a>, Microsoft. 2023.<\/p>\n<p><sup>3<\/sup><a href=\"https:\/\/query.prod.cms.rt.microsoft.com\/cms\/api\/am\/binary\/RE5bUvv?culture=en-us&amp;country=us\" target=\"_blank\" rel=\"noreferrer noopener\">Microsoft Digital Defense Report<\/a>, Microsoft. 2022.<\/p>\n<p><sup>4<\/sup>Microsoft Internal Research.<\/p>\n<p><sup>5<\/sup>Microsoft Copilot for Security randomized controlled trial (RCT) with experienced security analysts conducted by Microsoft Office of the Chief Economist, January 2024.&nbsp;<\/p>\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/04\/03\/get-end-to-end-protection-with-microsofts-unified-security-operations-platform-now-in-public-preview\/\">Get end-to-end protection with Microsoft&#8217;s unified security operations platform, now in public preview<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/04\/03\/get-end-to-end-protection-with-microsofts-unified-security-operations-platform-now-in-public-preview\/\" target=\"bwo\" >https:\/\/blogs.technet.microsoft.com\/mmpc\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Rob Lefferts| Date: Wed, 03 Apr 2024 16:00:00 +0000<\/strong><\/p>\n<p>Microsoft\u2019s unified security operations platform is now in public preview. Read on for details of how a comprehensive approach to cybersecurity can benefit your security operations center. <\/p>\n<p>The post <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/04\/03\/get-end-to-end-protection-with-microsofts-unified-security-operations-platform-now-in-public-preview\/\">Get end-to-end protection with Microsoft&#8217;s unified security operations platform, now in public preview<\/a> appeared first on <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\">Microsoft Security Blog<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10759,10378],"tags":[],"class_list":["post-24255","post","type-post","status-publish","format-standard","hentry","category-microsoft","category-security"],"_links":{"self":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24255","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=24255"}],"version-history":[{"count":0,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/24255\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=24255"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=24255"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=24255"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}