Microsoft Sentinel

E730139

Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution on Azure that helps organizations detect, investigate, and respond to threats at scale.

All labels observed (4)

Label Occurrences
Microsoft Sentinel canonical 8
Log Analytics 1
Microsoft Sentinel content hub 1

How this entity was disambiguated

Statements (57)

Predicate Object
instanceOf SIEM platform
SOAR platform
cloud-native security information and event management solution
security orchestration automation and response solution
category cybersecurity product
incident response platform
security monitoring tool
threat detection platform
dataIngestionModel pay-per-GB ingested
deploymentModel cloud-native
developedBy Microsoft
hostPlatform Azure
integratesWith Azure Active Directory
Microsoft 365
Microsoft 365 Defender
Microsoft Defender for Cloud
Microsoft Defender for Endpoint
cloud platforms
endpoint protection platforms
firewalls
identity providers
third-party security solutions
licensingModel consumption-based pricing
partOf Microsoft Azure
linked to: Azure
provides alerting and notification
case management for incidents
centralized security event analysis
centralized security event collection
dashboards and workbooks for security monitoring
runsOn Microsoft Azure
linked to: Azure
securityDomain incident management
security operations
threat detection and response
supportsCapability alert correlation
automated incident response
hunting queries
integration with threat intelligence feeds
log analytics
playbook automation
security analytics
security information and event management
security orchestration automation and response
threat detection
threat investigation
threat response
user and entity behavior analytics
supportsEnvironment hybrid cloud environments
multi-cloud environments
on-premises data sources via connectors
targetUser incident responders
security analysts
security operations center teams
threat hunters
usesTechnology Azure Logic Apps
Azure Monitor Logs
linked to: Azure Monitor

Kusto Query Language
machine learning-based analytics

How these facts were elicited

Referenced by (11)

Full triples — surface form annotated when it differs from this entity's canonical label.

Azure Monitor hasComponent Log Analytics
linked to: Microsoft Sentinel
Microsoft Security portfolio includesProduct Microsoft Sentinel
Microsoft Security portfolio includesProduct Microsoft Sentinel content hub
linked to: Microsoft Sentinel
Microsoft Security portfolio includesProduct Microsoft Sentinel playbooks
linked to: Microsoft Sentinel
Microsoft Defender for Cloud integratesWith Microsoft Sentinel
Kusto Query Language usedIn Microsoft Sentinel
Log Analytics workspace canBeLinkedTo Microsoft Sentinel
Microsoft Defender integratesWith Microsoft Sentinel