logo

Behind the scenes: Building Azure integrations for ASC alerts

ID: 10b069f5-21cc-5e39-a887-945fee080e4a

STIX ID: report--10b069f5-21cc-5e39-a887-945fee080e4a

Feed Name: Expel Blog

Date Published: 2021-02-09

Date Updated: 2026-04-27

Author: Matthew Kracht

...
...

Expel outlines their process and lessons learned building an Azure Security Center integration: they evaluated Microsoft Graph Security API, Azure Log Analytics, and Azure Management API, ultimately choosing Management API for data parity; added context and automated decision support to improve SOC triage; deduplicated and tuned noisy/preview alerts; implemented visibility and onboarding workflows; and developed a log aggregation approach that reduced Azure Storage log volume (and costs) significantly while preserving detection context. The post is an engineering and operational guide, not an incident report.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.