Behind the scenes: Building Azure integrations for ASC alerts
ID: 10b069f5-21cc-5e39-a887-945fee080e4a
STIX ID: report--10b069f5-21cc-5e39-a887-945fee080e4a
Feed Name: Expel Blog
Expel outlines their process and lessons learned building an Azure Security Center integration: they evaluated Microsoft Graph Security API, Azure Log Analytics, and Azure Management API, ultimately choosing Management API for data parity; added context and automated decision support to improve SOC triage; deduplicated and tuned noisy/preview alerts; implemented visibility and onboarding workflows; and developed a log aggregation approach that reduced Azure Storage log volume (and costs) significantly while preserving detection context. The post is an engineering and operational guide, not an incident report.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
