Microsoft Sentinel

E730139

Microsoft Sentinel is a cloud-native security information and event management (SIEM) and security orchestration, automation, and response (SOAR) solution on Azure that helps organizations detect, investigate, and respond to threats at scale.

All labels observed (4)

Label Occurrences
Microsoft Sentinel canonical 8
Log Analytics 1
Microsoft Sentinel content hub 1

How this entity was disambiguated

Statements (57)

Predicate Object
instanceOf SIEM platform ⓘ
SOAR platform ⓘ
cloud-native security information and event management solution ⓘ
security orchestration automation and response solution ⓘ
category cybersecurity product ⓘ
incident response platform ⓘ
security monitoring tool ⓘ
threat detection platform ⓘ
dataIngestionModel pay-per-GB ingested ⓘ
deploymentModel cloud-native ⓘ
developedBy Microsoft ⓘ
hostPlatform Azure ⓘ
integratesWith Azure Active Directory ⓘ
Microsoft 365 ⓘ
Microsoft 365 Defender ⓘ
Microsoft Defender for Cloud ⓘ
Microsoft Defender for Endpoint ⓘ
cloud platforms ⓘ
endpoint protection platforms ⓘ
firewalls ⓘ
identity providers ⓘ
third-party security solutions ⓘ
licensingModel consumption-based pricing ⓘ
partOf Microsoft Azure ⓘ
linked to: Azure
provides alerting and notification ⓘ
case management for incidents ⓘ
centralized security event analysis ⓘ
centralized security event collection ⓘ
dashboards and workbooks for security monitoring ⓘ
runsOn Microsoft Azure ⓘ
linked to: Azure
securityDomain incident management ⓘ
security operations ⓘ
threat detection and response ⓘ
supportsCapability alert correlation ⓘ
automated incident response ⓘ
hunting queries ⓘ
integration with threat intelligence feeds ⓘ
log analytics ⓘ
playbook automation ⓘ
security analytics ⓘ
security information and event management ⓘ
security orchestration automation and response ⓘ
threat detection ⓘ
threat investigation ⓘ
threat response ⓘ
user and entity behavior analytics ⓘ
supportsEnvironment hybrid cloud environments ⓘ
multi-cloud environments ⓘ
on-premises data sources via connectors ⓘ
targetUser incident responders ⓘ
security analysts ⓘ
security operations center teams ⓘ
threat hunters ⓘ
usesTechnology Azure Logic Apps ⓘ
Azure Monitor Logs ⓘ
linked to: Azure Monitor

Kusto Query Language ⓘ
machine learning-based analytics ⓘ

How these facts were elicited

Referenced by (11)

Full triples — surface form annotated when it differs from this entity's canonical label.

Azure Monitor → hasComponent → Log Analytics ⓘ
linked to: Microsoft Sentinel
Microsoft Security portfolio → includesProduct → Microsoft Sentinel ⓘ
Microsoft Security portfolio → includesProduct → Microsoft Sentinel content hub ⓘ
linked to: Microsoft Sentinel
Microsoft Security portfolio → includesProduct → Microsoft Sentinel playbooks ⓘ
linked to: Microsoft Sentinel
Microsoft Defender for Cloud → integratesWith → Microsoft Sentinel ⓘ
Kusto Query Language → usedIn → Microsoft Sentinel ⓘ
Log Analytics workspace → canBeLinkedTo → Microsoft Sentinel ⓘ
Microsoft Defender → integratesWith → Microsoft Sentinel ⓘ