Microsoft graph security alerts
이 페이지는 아직 영어로 제공되지 않습니다. 번역 작업 중입니다.
현재 번역 프로젝트에 대한 질문이나 피드백이 있으신 경우
언제든지 연락주시기 바랍니다.Goal
Detect when a Microsoft security product sends an alert to the Microsoft Graph security API.
Strategy
Microsoft Graph is the gateway to data and intelligence in Microsoft 365. It provides a unified programmability model that you can use to access the data in Microsoft 365, Windows, and Enterprise Mobility + Security. This detection identifies when an alert from a Microsoft security product is raised and queried through the Microsoft Graph security API.
Triage and response
- Investigate the alert to determine if it is malicious or benign.
- If the alert is deemed malicious, follow any recommended actions provided by Microsoft on the alert and also any internal incident response processes.
- If the alert is benign, consider including the user, host, or IP address in a suppression list. See Best practices for creating detection rules with Datadog Cloud SIEM for more information.