{"id":218757,"date":"2019-06-04T00:16:00","date_gmt":"2019-06-03T22:16:00","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=218757"},"modified":"2024-07-21T08:43:25","modified_gmt":"2024-07-21T06:43:25","slug":"sysinternals-sysmon-in-azure-sentinel-verwenden","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2019\/06\/04\/sysinternals-sysmon-in-azure-sentinel-verwenden\/","title":{"rendered":"Sysinternals Sysmon in Azure Sentinel verwenden"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2019\/07\/Azure.jpg\" width=\"86\" align=\"left\" height=\"50\"\/>Azure Sentinel ist eine SIEM-L\u00f6sung von Microsoft, um Bedrohungen zu erkennen und zu stoppen, bevor sie Schaden anrichten. Olaf Hartong testete die Verwendung der Sysinternals Tools Sysmon in Azure Sentinel. <\/p>\n<p><!--more--><\/p>\n<p>Das K\u00fcrzel <a href=\"https:\/\/de.wikipedia.org\/wiki\/Security_Information_and_Event_Management\" target=\"_blank\" rel=\"noopener noreferrer\">SIEM<\/a> steht f\u00fcr Security Information and Event Management f\u00fcr die Echtzeitanalyse von Sicherheitsalarmen ausgel\u00f6st von Anwendungen und Netzwerkkomponenten. Eine Einf\u00fchrung in Azure Sentinel finden Sie auf dieser Microsoft-Website und <a href=\"https:\/\/azure.microsoft.com\/de-de\/services\/azure-sentinel\/\" target=\"_blank\" rel=\"noopener noreferrer\">hier<\/a>. Laut Microsoft ist Azure Sentinel der Blick aus der Vogelperspektive auf das gesamte Unternehmen. Sicherheitsgeek Olaf Hartong hat ein wenig mit diesem neuen Werkzeug experimentiert und auch mal den Sysmon aus den Sysinternals Tools eingebunden. Innerhalb des nachfolgenden Tweets k\u00fcndigte er seinen Blogbeitrag \u00fcber die Verwendung von Sysmon in Azure Sentinel an &#8211; vielleicht ist es hilfreich f\u00fcr jemanden von Euch. <\/p>\n<blockquote class=\"twitter-tweet\" data-lang=\"de\">\n<p lang=\"en\" dir=\"ltr\">I've just published a small blogpost \"Using Sysmon in Azure Sentinel\" <a href=\"https:\/\/t.co\/GFpI1d01vF\">https:\/\/t.co\/GFpI1d01vF<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/DFIR?src=hash&amp;ref_src=twsrc%5Etfw\">#DFIR<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/Sysmon?src=hash&amp;ref_src=twsrc%5Etfw\">#Sysmon<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/AzureSentinel?src=hash&amp;ref_src=twsrc%5Etfw\">#AzureSentinel<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/BlueTeam?src=hash&amp;ref_src=twsrc%5Etfw\">#BlueTeam<\/a> <a href=\"https:\/\/twitter.com\/hashtag\/ThreatHunting?src=hash&amp;ref_src=twsrc%5Etfw\">#ThreatHunting<\/a><\/p>\n<p>\u2014 Olaf Hartong (@olafhartong) <a href=\"https:\/\/twitter.com\/olafhartong\/status\/1135278065695809537?ref_src=twsrc%5Etfw\">2. Juni 2019<\/a><\/p><\/blockquote>\n<p><span id=\"preserve7e9e8da9de8d4c0c89f74fa5f1eba2cb\" class=\"wlWriterPreserve\"><script charset=\"utf-8\" src=\"https:\/\/platform.twitter.com\/widgets.js\" async><\/script><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Azure Sentinel ist eine SIEM-L\u00f6sung von Microsoft, um Bedrohungen zu erkennen und zu stoppen, bevor sie Schaden anrichten. Olaf Hartong testete die Verwendung der Sysinternals Tools Sysmon in Azure Sentinel.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426],"tags":[4375,4328],"class_list":["post-218757","post","type-post","status-publish","format-standard","hentry","category-sicherheit","tag-azure","tag-sicherheit"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/218757","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=218757"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/218757\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=218757"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=218757"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=218757"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}