4 Comments

Thank you for writing this up, Andrea!

Expand full comment

Great post Andrea. Now I need to go link it to Sentinel tables & rules!

Expand full comment

I get this question with every new SIEM conversation. Thanks for writing this up Andrea!

Expand full comment

Depends on organization and setup but I believe all critical network/security devices and servers should be addressed.

Expand full comment