Kloudynet - Microsoft Modern XDRSOC Offering 2022
Kloudynet - Microsoft Modern XDRSOC Offering 2022
Kloudynet - Microsoft Modern XDRSOC Offering 2022
User Win 10 Win Server 2016 Win Server 2019 Win 2008/2012 R2 MacOS Linux Servers iOS Android
Microsoft 365 Defender : Unified Defense Suite connecting via Endpoint Detection & Response (EDR) Public Preview
Threat & Vulnerability Management (TVM)
VPN Defender Anti-Virus
Real-time Protection
Cloud Delivered Protection
Network Protection
Safe Links Threat Explorer Compromised credential phase alerts Custom Indicators for Ips & URLs/Domains
Custom Indicators for Certificates
Anti Malware Real-Time Combined incidents queue: Full attack scope, impacted assets and actions in a single Incident Exfiltration phase alerts Manually install ATP Sensors
Standalone Server Group policy
Protection Detections on the domain controllers managed
Auto assignment of
security trainings Users Automatic response to threats: Automatically stop progression of Threats • Identity Security Posture Assessment
ATP for SP,ODFB • Detect suspicious activities on the network
AIR
& Teams • User investigation priority score Domain Controller Win 10 & Windows Server
Cross-Product Threat Hunting: Across Alerts, Apps & Identities, Email & Devices
Manually export group policy objects
EDR
Secure Score: Track and improve your overall Security Posture using Microsoft Secure Score
Defender for Cloud Apps Defender for Endpoint Integration
Connect Power
Reports Onboarding configuration
Apps Automate
Data and remediation
Unfamiliar Sign-in Properties Malware linked IP address Device
Export/
Concur Inventory Onboarding configuration Local Script
SIEM and remediation JAMF Pro
Box Local Script
Slack Github Docusign Log
Cloud
SIEM Leaked Credentials Password spray
Dropbox Workday Collector
Discovery
Connector Power Intune macOS
Salesforce Report Reporting Managed
Okta Automate
Servicenow Tableau Jira HighQ
Workvira Office 365 Egnyte Local Script
G-Suite Ansible
Cornerstone On demand Workplace by Facebook Integration with Defender Win 10, Android, IOS, & Puppet
Integration with Microsoft Defender for Cloud Apps for posture management
for Endpoint (EDR) macOS
CASB as proxy for 3rd Party Apps IT Administrator
Linux Server
Microsoft Defender for Cloud (Previously Azure Security Center) Isolate Device ios/Android
Local Script
Restrict App Execution
Cloud Security Posture Management Cloud Workload Protection Platform SQL Auto
Email Security Alert Workflow Run Antivirus Scan
Vulnerability Provision
Notification Map Automation
Secure Score & Assessment VMs Azure Network Layer
Recommendations Servers Collect Investigation Package
Defender AV and ATP for
Windows and Linux VMs Storage Azure Resource Manager
Continuous Live Response Session
CIS 1.1.0, PCI DSS, ISO Network
IOT Security
ASC GitHhub Threat Log Analytics
27001, SOC TSP…. EPP & EDR Map Community Detection Export
App Service Azure Cosmos DB Windows/Linux VM Arc
Secure Score Automated Investigation
Security Baseline enabled (AWS,GCP or On-
Custom Security Baseline Adaptive Application Control SQL Prem)
File Integrity Monitoring Container Azure Web URL Filtering Azure WAF
Advanced
Image Resource Cloud
Advanced VM Defense IOT Insights Threat Event Hub
Scanning Graph Connectors
Asset Inventory (Azure, AWS, GCP, On-Prem) Protection Azure DDoS Protection
(Qualys) Explorer Device Actions
Advance Threat Protection for Kubernetes
Azure IaaS, PaaS services Export to Azure MariaDB (Resource Level)
Container Registries
Vulnerability scan for VMs Download PowerBI Secure Score Event Hub/Log Analytics Workspace
Regulatory & Vulnerability Vulnerability Rest API Alerts Azure MySQL/Postgre SQL
& Containers with native Just In Time VM Access Reports Reports API
Compliance Assessment Assessment Threat Protection: Key Vault Storage Account (Resource Level)
Qualys integration Adaptive Network Hardening Azure Windows/Linux VM
Shadow IT Discovery IaaS/Paas
Azure Defender Supports ASC Advanced Threat Protection
for Azure Services