Understanding Microsoft Sentinel and Microsoft Defender
Microsoft Sentinel and Microsoft Defender are cloud services in Microsoft Azure. Sentinel is a cloud-based SIEM service that acts as an extension on top of Azure Log Analytics, a centralized log collection service in Azure. Sentinel provides real-time analytics and incident handling and supports different third-party services for threat intelligence and data collection. Sentinel also provides automation capabilities, where it has built-in integrations with Logic Apps to trigger playbooks for remediation. Using Logic Apps also means that we can easily integrate with other products in the ecosystem. The service also has APIs that can be used to ingest data. For instance, the following blog post shows how we can ingest data from a third-party cloud provider into Microsoft Sentinel: https://msandbu.org/streaming-of-audit-logs-from-oracle-cloud-to-microsoft-sentinel/.
Microsoft Defender for Cloud consists of multiple threat detection...