Random Thoughts of an IT Security Professional
  • Home
  • About
  • Hire Me for Consulting Work
  • Resume
  • Blog Recommenations

Filtering Events on the Microsoft AMA Syslog Agent for Microsoft Sentinel

4 months ago 1 min read
When you’re collecting syslog events from VMware hosts, Cisco switches and routers, it’s easy to find yourself drowning in noise—hundreds of messages you’ll never use, each one eating into
Read Now Read Later
By: TBJ Consulting

Getting My Bachlors in Cybersecurity

6 months ago 3 min read
Executive Summary For years, two primary barriers prevented me from obtaining a bachelor's degree: time and cost. After graduating from DeVry Institute of Technology in 1996, I discovered that few credits
Read Now Read Later
By: TBJ Consulting

Best Practices for Migrating Microsoft Sentinel to a New Subscription

7 months ago 4 min read
Executive Summary Organizations utilizing Microsoft Sentinel for an extended period may have initially configured it without adhering to contemporary best practices. When I first implemented Microsoft Sentinel—then known as Azure Sentinel—limited
Read Now Read Later
By: TBJ Consulting

Microsoft Sentinel Log Retention

8 months ago 1 min read
Executive Summary Recently I needed to move Microsoft Sentinel and the underlying log analytics workspace to a new subscription. That will be detailed in another blog post. Part of that move is setting
Read Now Read Later
By: TBJ Consulting

Tracking Group Policy Changes with Microsoft Sentinel KQL

10 months ago 2 min read
Executive Summary For many organizations, maintaining control over Group Policy (GPO) changes is critical, especially in environments where change control processes are inconsistently followed. Tracking GPO changes can help you monitor unexpected modifications
Read Now Read Later
By: TBJ Consulting
Newer Posts
Page 2 of 13
Older Posts
Powered by Ghost
Random Thoughts of an IT Security Professional