Tagged CrowdStrike

2026

  1. Project2 min readEntra ID audit logs to CrowdStrike SIEM, one stream per countryEntra ID → Event Hubs → Stream Analytics → CrowdStrike NG-SIEM, with Azure Automation keeping the user-to-country lookup fresh. Beyond filtering: each country becomes a measurable unit, with its own events, volumes and security metrics.

2025

  1. Project2 min readTurning SOC findings into a remediation process the Workplace team could runThe security operations centre detects and analyses; the Workplace team has the hands on the devices. Without an agreed process between the two, every alert was a conversation. With one, it became a playbook, and playbooks can be automated.