Blueprint - Mark Morowczynski & Thomas Detzner: Microsoft Incident Response Playbooks | 22
We all need solid, well though-out playbooks to help standardize our respons to common threat scenarios. In this episode we speak with Thomas Detzner and Mark Morowczynski about the brand new set of Microsoft incident response playbooks that were just released. This is a brand new effort to meticulously document prerequisites, investigation steps, and remediation process for common scenarios most commonly seen by the Microsoft incident response teams, and you definitely won't want to miss it.
Resources mentioned in this episode:
- Playbooks discussed in this episode - https://aka.ms/irplaybooks
- Azure Event Hub - https://docs.microsoft.com/en-us/azure/active-directory/reports-monitoring/tutorial-azure-monitor-stream-logs-to-event-hub#access-data-from-your-event-hub
- Security Baselines - https://techcommunity.microsoft.com/t5/microsoft-security-baselines/security-baseline-final-for-windows-10-v1909-and-windows-server/ba-p/1023093
- Security Auditing and Monitoring Reference - https://www.microsoft.com/en-us/download/details.aspx?id=52630