Cookie Consent by Free Privacy Policy Generator ๐Ÿ“Œ Gundog - Guided Hunting In Microsoft 365 Defender

๐Ÿ  Team IT Security News

TSecurity.de ist eine Online-Plattform, die sich auf die Bereitstellung von Informationen,alle 15 Minuten neuste Nachrichten, Bildungsressourcen und Dienstleistungen rund um das Thema IT-Sicherheit spezialisiert hat.
Ob es sich um aktuelle Nachrichten, Fachartikel, Blogbeitrรคge, Webinare, Tutorials, oder Tipps & Tricks handelt, TSecurity.de bietet seinen Nutzern einen umfassenden รœberblick รผber die wichtigsten Aspekte der IT-Sicherheit in einer sich stรคndig verรคndernden digitalen Welt.

16.12.2023 - TIP: Wer den Cookie Consent Banner akzeptiert, kann z.B. von Englisch nach Deutsch รผbersetzen, erst Englisch auswรคhlen dann wieder Deutsch!

Google Android Playstore Download Button fรผr Team IT Security



๐Ÿ“š Gundog - Guided Hunting In Microsoft 365 Defender


๐Ÿ’ก Newskategorie: IT Security Nachrichten
๐Ÿ”— Quelle: feedproxy.google.com



Gundog provides you with guided hunting in Microsoft 365 Defender. Especially (if not only) for Email and Endpoint Alerts at the moment.


Functionality

You provide an AlertID (you might received via Email notification) and gundog will then hunt for as much as possible associated data. It does not give you the flexibility of advanced hunting like you have in the portal, but it will give you a quick, first overview of the alert, all associated entities and some enrichment.

All the hunting it does is based on the alert timestamp โ€“ so we only care about events shortly before, or after the alert.

It also provides you with PowerShell objects for each entity it hunted for โ€“ like $Network for everything it found related to this alert in the Microsoft 365 Defender DeviceNetworkEvents table.

gundog also comes up with some other features that make your life easier:

  • per default, only the most relevant data is displayed (this is the way)
  • it gives you context wherever possible: last AAD Sign-Ins & userโ€™s AAD address
  • network connections can be automatically filtered to display more relevant connections only (get rid of connections to Office 365 e.g.)
  • network connections are enriched with geo location (country & city)
  • in the variables section you can easily adjust most parameters like advanced hunting timeframe of every query
  • In addition it searches for IOCs at other services like abuse.ch, urlscan.io or ip-api.com. I ask you to apply for their paid services if you use them commercially.

After first evaluations with gundog, you can continue in the portal to dig deeper into the rabbit hole.

Feel free to extend gundog and send me pull requests! For the best psychodelic experience, use Windows Terminal Dracula theme with gundog.


Quick usage
mandatory parameters:

- TenantID
- ClientID
- ClientSecret

Optional parameters:

- forgetIncidents

(Background: the first thing gundog is doing is to query all incidents and alerts from the incident API from the last 30 days. These are
saved to a global variable. If you restart gundog, it will not query all incidents again, unless you set forgetIncidents to true.)

Requirements

Register an new App in AAD and give it the following permission: (How to register an app)

Threat Protection - AdvancedHunting.ReadAll - Incident.Read.All Windows Defender ATP - AdvancedQuery.Read.All - Alert.Read.All - File.Read.All - Ip.Read.All - Url.Read.All - User.Read.All - Vulnerability.Read.All ">
Microsoft Graph

- Directory.Read.All
- IdentityRiskEvent.Read.All
- IdentityRiskyUser.Read.All
- SecurityEvents.Read.All
- User.Read

Microsoft Threat Protection

- AdvancedHunting.ReadAll
- Incident.Read.All

Windows Defender ATP

- AdvancedQuery.Read.All
- Alert.Read.All
- File.Read.All
- Ip.Read.All
- Url.Read.All
- User.Read.All
- Vulnerability.Read.All

For more information visit: https://emptydc.com/2021/02/25/gundog/



...



๐Ÿ“Œ Hunting for the True Meaning of Threat Hunting at RSAC 2019


๐Ÿ“ˆ 24.19 Punkte

๐Ÿ“Œ Threat Hunting: Eight Tactics to Accelerating Threat Hunting


๐Ÿ“ˆ 24.19 Punkte

๐Ÿ“Œ Risk Hunting statt Threat Hunting: So sorgen Sie fรผr mehr Cybersicherheit


๐Ÿ“ˆ 24.19 Punkte

๐Ÿ“Œ Microsoft Defender ATP Gets Advanced Hunting Capabilities, More


๐Ÿ“ˆ 23.52 Punkte

๐Ÿ“Œ Microsoft Defender Experts for Hunting now generally available


๐Ÿ“ˆ 23.52 Punkte

๐Ÿ“Œ โ€œMicrosoft Defender Experts for Huntingโ€ verรถffentlicht


๐Ÿ“ˆ 23.52 Punkte

๐Ÿ“Œ Microsoft Ships Antivirus For macOS as Windows Defender Becomes Microsoft Defender


๐Ÿ“ˆ 22.85 Punkte

๐Ÿ“Œ Ignite 2022: Microsoft Defender fรผr DevOps & Microsoft Defender CSPM


๐Ÿ“ˆ 22.85 Punkte

๐Ÿ“Œ Windows Defender ATP is dead. Long live Microsoft Defender ATP


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Microsoft Defender ATP: Der Windows Defender verteidigt auch Macs


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Windows Defender ATP kommt auf den Mac โ€“ย und wird "Microsoft Defender"


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Windows Defender Gets a New Name: Microsoft Defender


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Windows Defender wird wohl zum Microsoft Defender umbenannt


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Microsoft bestรคtigt: Der Defender legitime URLs oder Dateien als schรคdlich gemeldet (Defender Issue DZ534539)


๐Ÿ“ˆ 20.92 Punkte

๐Ÿ“Œ Microsoft launches Defender for Individuals for Microsoft 365 Personal and Family subscribers


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Kalenderwoche 25/2022 fรผr IT-Expert*innen: Power Apps, Microsoft Defender, Microsoft 365 und mehr


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Amazon Deal: Microsoft 365 Family (inkl. Microsoft Defender) โ€“ 22 Prozent Preisnachlass


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Amazon Deal: Microsoft 365 Single (inkl. Microsoft Defender) โ€“ 19 Prozent Preisnachlass


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Amazon Deal: Microsoft 365 Single (inkl. Microsoft Defender) โ€“ besonders preiswertes Angebot


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Amazon Deal: Microsoft 365 Single (inkl. Microsoft Defender) โ€“ jetzt 15 Prozent sparen


๐Ÿ“ˆ 20.83 Punkte

๐Ÿ“Œ Defender Exclusion Tool (ehemals Defender Injector) 1.2 Deutsch


๐Ÿ“ˆ 18.99 Punkte

๐Ÿ“Œ X-Post r/Funny Windows Defender is best Defender.


๐Ÿ“ˆ 18.99 Punkte

๐Ÿ“Œ Defender-Pretender: When Windows Defender Updates Become a Security Risk


๐Ÿ“ˆ 18.99 Punkte

๐Ÿ“Œ Defeat-Defender - Powerful Batch Script To Dismantle Complete Windows Defender Protection And Even Bypass Tamper Protection


๐Ÿ“ˆ 18.99 Punkte

๐Ÿ“Œ Code42 Incydr, Microsoft 365 Defender, & Qualys Multi-Vector EDR - ESW #200


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft Defender for Office 365 to allow testing without setup


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft to add 'nation-state activity alerts' to Defender for Office 365


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft 365 Defender Threat Analytics enters public preview


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft To Add 'Nation-State Activity Alerts' To Defender for Office 365


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Kalenderwoche 23/2021 fรผr IT-Experten im Rรผckblick: Azure Virtual Desktop, Azure Defender, Microsoft 365 und mehr


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Mehr Sicherheit mit Microsoft 365 Defender


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ If someone tries ransacking your Windows network, it's a bit easier now to grok in Microsoft 365 Defender


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft installiert Defender 365 ungefragt auf Windows PCs


๐Ÿ“ˆ 18.9 Punkte

๐Ÿ“Œ Microsoft 365: Windows-Defender-App installiert sich automatisch


๐Ÿ“ˆ 18.9 Punkte











matomo