SOC Daily Report : 03/27(Thu)

2025. 3. 28. 23:42·Security/Azure SOC

Case 1. (High)
 
Correlate Unfamiliar sign-in properties and atypical travel alerts

This alert indicates that unfamiliar sign-in properties and atypical travel patterns are correlated, suggesting potential security risks: Possible Legitimate User Activity The user logged in from a new device, browser, or network The user is using a VPN The user is traveling for work or personal reasons

 

Case 2. (Medium)
 
Successful logon from IP and failure from a different IP

 

This alarm is triggered when a successful login occurs from one IP address, followed by a failed login attempt from a different IP address. This may indicate: Legitimate User Activity: The user switches networks (e.g., VPN, mobile, home, office Wi-Fi) Dynamic IP changes due to ISP settings

 

Case 3. (Medium)
 
(Preview) TI map Domain entity to DnsEvent

This alert indicates that a domain identified by Threat Intelligence (TI) has matched a DNS event (DnsEvent) within the organization’s network. In other words, a DNS request from within the network has been flagged as related to a potentially malicious or suspicious domain. Possible causes include: Legitimate Cases A user or system accessing a legitimate but newly registered domain False positives (FP) due to misclassification of a safe domain
저작자표시 비영리 변경금지 (새창열림)

'Security > Azure SOC' 카테고리의 다른 글

SOC Daily Report : 03/25(Tue)  (0) 2025.03.27
'Security/Azure SOC' 카테고리의 다른 글
  • SOC Daily Report : 03/25(Tue)
ccie68155
ccie68155
USA Network Engineer
  • ccie68155
    DJ (시시한아이)
    ccie68155
    • 분류 전체보기 (97)
      • Network (0)
        • Switch (0)
        • Router (0)
        • OSPF (0)
        • BGP (0)
        • MPLS (0)
        • EIGRP (0)
        • N9K in NX-OS (0)
        • N9K in ACI (0)
        • SD-WAN (0)
        • DNA Center (0)
        • ISE (0)
        • IPSec (0)
        • Load Balancer (0)
        • Wireless (0)
        • IS-IS (0)
        • GRE Tunnel (0)
        • LISP (0)
        • Multicast (0)
        • IPv6 (0)
        • SAN (0)
        • UCS (0)
        • QoS (0)
        • Network Design (0)
      • Program (0)
        • Python (0)
        • Node.js (0)
      • Windows Server (0)
        • Active Directory (0)
      • IT Etc (3)
        • VMware (3)
        • Linux (0)
      • Security (2)
        • Azure SOC (2)
      • Cisco Certification (31)
        • CCNA (0)
        • CCNP ENCOR (3)
        • CCIE EI (8)
        • CCIE Sec (4)
        • CCIE DC (3)
        • CCIE EW (0)
      • Fortinet Certification (28)
        • NSE4 (23)
        • NSE5 (0)
        • NSE6 (0)
        • NSE7 (0)
        • NSE8 (0)
      • Palo Alto Certification (0)
        • PCNSE (0)
      • Juniper Certification (0)
        • JNCIE (0)
      • Education (5)
        • WGU B.S Cyber security (5)
      • LAB (9)
        • NAS (0)
        • Windows Server (0)
        • home LAB (9)
        • Cisco IOS (0)
        • Lab practice programs (0)
      • 미국 네트워크 엔지니어 이야기 (9)
        • 영어 (8)
  • 링크

  • hELLO· Designed By정상우.v4.10.3
ccie68155
SOC Daily Report : 03/27(Thu)
상단으로

티스토리툴바