{"id":7518,"date":"2021-10-28T12:26:06","date_gmt":"2021-10-28T19:26:06","guid":{"rendered":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/?p=7518"},"modified":"2023-06-25T14:06:44","modified_gmt":"2023-06-25T21:06:44","slug":"how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events","status":"publish","type":"post","link":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/","title":{"rendered":"How Microsoft narrows the threat funnel on over 600 billion monthly security events"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-7479 size-medium\" style=\"margin-top: 0px;\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-perspectives-300x106.png\" alt=\"Microsoft Digital Perspectives\" width=\"300\" height=\"106\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-perspectives-300x106.png 300w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/ms-digital-perspectives.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>At Microsoft, we typically see around 600 billion security events each month.<\/p>\n<p>Security events are innocuous actions that happen all the time, ranging from adding a user to a Microsoft SharePoint site, to creating a file, to deleting a folder, to opening an email. On their own, events are typically not notable, but in conjunction with other events, they can signal a threat, so we\u2019ve always got to be on the lookout.<\/p>\n<p>Across a large enterprise like ours, we use <a href=\"https:\/\/azure.microsoft.com\/en-us\/services\/azure-sentinel\/\" target=\"_blank\" rel=\"noopener\">Microsoft Azure Sentinel<\/a> to see 20 billion security events each day, and that\u2019s a lot of data to collect and manage. Azure Sentinel is our cloud-native security information and events manager.<\/p>\n<p>Instead of sending our Security Operations Center (SOC) analysts on a wild hunt after every event in the SIEM, we use our own tools and solutions to funnel that big 12-digit number down to a more reasonable number. This focuses our efforts on the events that matter and how they were created\u2014this narrows us in on the ones that pose a real threat. The reason this is important is we can\u2019t\u2014and shouldn\u2019t\u2014respond to every event. Like anyone who has a security team, we want our security professionals spending their time on true threats to our company.<\/p>\n<figure id=\"attachment_7532\" aria-describedby=\"caption-attachment-7532\" style=\"width: 350px\" class=\"wp-caption alignright\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-7532\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-001-v2.png\" alt=\"Diagram of four consecutively smaller rings forming a funnel, decreasing with the number of security events.\" width=\"350\" height=\"429\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-001-v2.png 500w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-001-v2-245x300.png 245w\" sizes=\"auto, (max-width: 350px) 100vw, 350px\" \/><figcaption id=\"caption-attachment-7532\" class=\"wp-caption-text\">Combining solutions like machine learning and automation along with human expertise allows Microsoft to focus on the security events that require attention.<\/figcaption><\/figure>\n<p>But how can we be certain that the right events are being flagged for investigation?<\/p>\n<h2>It all starts with Zero Trust<\/h2>\n<p>Zero Trust means verifying everything you can, including identity and device health. It means giving your users enough access to stay productive, but not enough to create unnecessary risk. Segment networks, encrypt your data from end to end, take advantage of telemetry, and assume there will be a breach.<\/p>\n<p>More specifically, Zero Trust architecture reduces risk across all environments by establishing strong identity verification, validating device compliance prior to granting access, and ensuring least privilege access to only explicitly authorized resources. <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noopener\">These are the core principles of Microsoft\u2019s Zero Trust architecture.<\/a><\/p>\n<p>Adhering to it is the first step in protecting Microsoft and serves as a framework that encapsulates all our security controls. It\u2019s also how we empower self-service and let users access the resources they need to stay productive from anywhere.<\/p>\n<p>Zero Trust keeps a lot of threats outside of our ecosystem\u2014around 98 percent of attacks are subverted by these basic principles. Most data breaches, roughly 70 percent, come from phishing. In adhering to the values of Zero Trust, we assume that any device or user can be breached, which means carefully scrutinizing security events across our organization for concerning patterns.<\/p>\n<h2>Going from <strong>several billion to several thousand<\/strong><\/h2>\n<p>You can find threats through use cases, scenarios that describe how unusual security events might be high risk.<\/p>\n<p>When you collect a lot of events data, you either create your own use cases or let the products do it for you. We rely heavily on the latter.<\/p>\n<p>Each of our extended detection and response tools (XDR) include a team dedicated to knowing and identifying if something is out of the ordinary. Inside Microsoft 365 Defender lives Threat Analytics, which <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender\/threat-analytics?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">consolidates findings\u2014like active threats and critical vulnerabilities\u2014from product groups and security researchers<\/a>. Then it tells us <a href=\"https:\/\/cm-edgetun.pages.dev\/security\/blog\/2020\/12\/28\/using-microsoft-365-defender-to-coordinate-protection-against-solorigate\/\" target=\"_blank\" rel=\"noopener\">what the finding means, what the associated activity is, what the problem is, and which entities\u2014a device, a mailbox, an inbox, or something else\u2014are involved<\/a>.<\/p>\n<p>The Threat Analytics feature, along with the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/behavioral-blocking-containment?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">rich research-driven behavioral alerts<\/a> in Microsoft Defender for Endpoint, have a large impact in reducing the number of events we see. By utilizing our security tools that leverage machine learning, threat intelligence, data science, and more, we are able to filter an estimated 600 billion monthly events down to around 10,000 alerts. Whittling those 12 digits down to 4 gets us closer to real threats.<\/p>\n<p>But we still have to determine which items require\u00a0<span data-ogsb=\"yellow\">further investigation from our SOC<\/span>, and we only want to give our analysts cases that lead to an actionable response.<\/p>\n<h2>Cutting that in half, and then some<\/h2>\n<p>An estimated 10,000 alerts are still a lot to handle. We utilize automation to help us understand what\u2019s going on and to reduce the number of cases we dig into.<\/p>\n<p>Microsoft Defender for Office 365\u2019s Automated Investigation and Response (AIR) helps our SOC prioritize security events that pose the greatest risk while reducing manual steps in the process. In part, it does this by triaging low-threat cases that have already been identified by our system.<\/p>\n<p>AIR works because it generates an investigation whenever a user flags an email as a phishing attempt. It doesn\u2019t matter if it\u2019s actually malicious or not, because our tools, like Microsoft Defender for Office 365, tell us if we need to investigate further. <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-defender-for-office\/automatically-triage-phish-submissions-in-microsoft-defender-for\/ba-p\/2733752\" target=\"_blank\" rel=\"noopener\">The tool also takes action<\/a>, like combining emails for deletion, blocking URLs, or providing additional steps to our SOC so that we can protect the company.<\/p>\n<p>And because AIR has taken care of the lower risk items, our SOC can worry about higher risk phishing.<\/p>\n<p>We also use Microsoft Defender for Endpoint Automated Investigation and Response (MDE AIR), which <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/automated-investigations?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">finds and fixes low-level malware<\/a> instances, stuff we regularly see. MDE AIR can clean up a device, remove any scheduled tasks, delete the service, erase the file, and simply tell us that the problem has been remediated. We can make choices about whether to even look at it, which reduces a lot of noise for our SOC.<\/p>\n<p>These are some of the ways we go from 10,000 monthly alerts down to a manageable 3,500 cases for investigation.<\/p>\n<p>But there are other ways to reduce the number of security alerts an organization must respond to.<\/p>\n<p>Sometimes several events are related and can be correlated into an incident. <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender\/incidents-overview?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Microsoft 365 Defender uses threat intelligence to find these relationships<\/a>. Knowing the association between events, a SOC can be more efficient in its efforts, reducing the number of events along with duplicated efforts performed by multiple analysts.<\/p>\n<p>Machine learning and data science can show how impactful data can be. As event data grows, divergent datasets can be merged together to assist threat hunters. There is a function in Microsoft Azure Sentinel called Fusion that can <a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-sentinel\/what-s-new-fusion-detection-for-ransomware\/ba-p\/2621373\" target=\"_blank\" rel=\"noopener\">spot ransomware in the background<\/a>. The solution can also automatically <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/fusion\" target=\"_blank\" rel=\"noopener\">detect multistage attacks<\/a> and recognize patterns in data that would otherwise be too complex to see.<\/p>\n<h2>Making it easy for the SOC<\/h2>\n<p>This is how we get from 3,500 cases to the actual security threats that need our attention. But it\u2019s not only about the volume of events\u2014it\u2019s also about how we spend our time.<\/p>\n<p>We want to be able to dig through the data, but when our analysts need to act, we want all that data to be curated and ready to go. Some of this is done through additional layers of automation, like bots that use the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/management-apis?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Microsoft Defender APIs<\/a> to pull important data for an analyst. Developers within the SOC team <a href=\"https:\/\/dev.botframework.com\/\" target=\"_blank\" rel=\"noopener\">utilized the Microsoft Bot Framework<\/a> to make it easier for our analysts to get the data they need quickly and efficiently by connecting directly to these robust APIs. Here\u2019s an example:<\/p>\n<figure id=\"attachment_7525\" aria-describedby=\"caption-attachment-7525\" style=\"width: 500px\" class=\"wp-caption alignleft\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-7525 size-full\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-002.png\" alt=\"Sherlock Bot screenshot displaying security event information such as timestamps, frequency, affected systems, risk, exposure level.\" width=\"500\" height=\"445\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-002.png 500w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_image-002-300x267.png 300w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\" \/><figcaption id=\"caption-attachment-7525\" class=\"wp-caption-text\">Sherlock Bot is one of the many automation tools created and used by SOC analysts to quickly investigate a security event.<\/figcaption><\/figure>\n<p>This saves time for the analyst having to go back and forth between screens to get data\u00a0<span data-ogsb=\"yellow\">or choose remediation actions<\/span>, all the while helping the analyst determine if the alert is a true positive that needs cleanup or a benign or false positive to add to the list for exclusion.<\/p>\n<p>A SOC can also leverage <a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-respond-threats-playbook\" target=\"_blank\" rel=\"noopener\">playbooks with automation rules<\/a> to further improve analysts\u2019 efficiency by assigning tasks to the right team, giving further resolution to incidents, and clearing out known false positives. Automation makes things easier, more efficient, and more accurate. It empowers our SOC to make strategic decisions instead of focusing on manual steps.<\/p>\n<p>The winnowing we do dramatically reduces the number of events that we need to respond to. For every 3,500 security events we investigate each month, only about 500 require remediation from Microsoft. This system allows us to quickly identify and respond to those real threats.<\/p>\n<h2>Why quality, not quantity, matters<\/h2>\n<p>We collect a lot of events each month, but we don\u2019t have time to investigate everything. And not everything is worthy of our SOC\u2019s time. Most of our threats are dealt with by Zero Trust and good security hygiene, but we\u2019re still going to be cautious and perform due diligence.<\/p>\n<p>The solutions and practices we have in place help funnel these security events into a manageable number by eliminating innocuous events, resolving low-risk items, and remediating common problems on behalf of our SOC analysts. When the distilled batch of cases arrive for investigation, our SOC can leverage automation and other tools to work efficiently, quickly responding to items that really matter.<\/p>\n<p>That\u2019s how we get from 600 billion monthly events, a 12-digit number, down to 500 remediations, or 3 digits\u2019 worth of action items.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"74\" class=\"alignnone size-medium wp-image-7448\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png\" alt=\"Key Takeaways\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways-300x74.png 300w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/key-takeaways.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>Here are three things you can do to get started at your company:<\/p>\n<ul class=\"c-list\">\n<li>Use a <a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/insidetrack\/implementing-a-zero-trust-security-model-at-microsoft\/\">Zero Trust security model<\/a> to ensure you have a healthy and protected environment that reinforces strong identity verification, device health enforcement and management, and least privilege access.<\/li>\n<li>Ensure that your SOC team is using enterprise security tools that leverage research and machine learning to produce actionable alerts. This includes making sure to use tools that provide alert reduction in the form of correlated pending actions for the SOC, or features such as Fusion or incident correlation.<\/li>\n<li>Utilize the APIs provided by your security tools to build automation that ensures analysts can be efficient and get to true positives as quickly as possible.<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"81\" class=\"alignnone size-medium wp-image-7482\" src=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png\" alt=\"Related links\" srcset=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links-300x81.png 300w, https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/related_links.png 500w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<ul class=\"c-list\">\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/behavioral-blocking-containment?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">How Microsoft Defender for Endpoint uses behavioral blocking and containment.<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/automated-investigations?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Learn about automated investigations in Microsoft Defender for Endpoint.<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/tutorial-respond-threats-playbook\" target=\"_blank\" rel=\"noopener\">Tutorial: Use playbooks with automation rules in Azure Sentinel.<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender-endpoint\/management-apis?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Discover how to manage and use APIs in Microsoft Defender for Endpoint.<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/defender\/incidents-overview?view=o365-worldwide\" target=\"_blank\" rel=\"noopener\">Gain insights into incident response with Microsoft 365 Defender.<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/microsoft-defender-for-office\/automatically-triage-phish-submissions-in-microsoft-defender-for\/ba-p\/2733752\" target=\"_blank\" rel=\"noopener\">Find out how to automatically triage phish submissions in Microsoft Defender for Office 365.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/security\/business\/zero-trust\" target=\"_blank\" rel=\"noopener\">Embrace proactive security with Zero Trust.<\/a><\/li>\n<li><a href=\"https:\/\/techcommunity.microsoft.com\/t5\/azure-sentinel\/what-s-new-fusion-detection-for-ransomware\/ba-p\/2621373\" target=\"_blank\" rel=\"noopener\">Learn what&#8217;s new with Fusion Detection for Ransomware.<\/a><\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/azure\/sentinel\/fusion\" target=\"_blank\" rel=\"noopener\">Understand how advanced multistage attack detection works in Azure Sentinel.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/security\/blog\/2020\/12\/28\/using-microsoft-365-defender-to-coordinate-protection-against-solorigate\/\" target=\"_blank\" rel=\"noopener\">Discover how Microsoft 365 Defender protects against Solorigate.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/insidetrack\/implementing-a-zero-trust-security-model-at-microsoft\/\">Learn about how Microsoft Digital is implementing a Zero Trust security model at Microsoft.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/insidetrack\/securing-the-enterprise-and-responding-to-cybersecurity-attacks-with-microsoft-azure-sentinel\">Learn how Microsoft is securing the enterprise and responding to cybersecurity attacks with Microsoft Azure Sentinel.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/insidetrack\/moving-to-next-generation-siem-with-azure-sentinel\">Find out how Microsoft is moving to a next-generation SIEM with Azure Sentinel.<\/a><\/li>\n<li><a href=\"https:\/\/cm-edgetun.pages.dev\/en-us\/insidetrack\/best-practices-for-implementing-zero-trust-at-microsoft\">Get insights into Microsoft&#8217;s practices for implementing Zero Trust.<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>At Microsoft, we typically see around 600 billion security events each month. Security events are innocuous actions that happen all the time, ranging from adding a user to a Microsoft SharePoint site, to creating a file, to deleting a folder, to opening an email. On their own, events are typically not notable, but in conjunction [&hellip;]<\/p>\n","protected":false},"author":114,"featured_media":7521,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_hide_featured_on_single":false,"_show_featured_caption_on_single":true,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[419],"coauthors":[617],"class_list":["post-7518","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-zero-trust","program-microsoft-digital-perspectives","m-blog-post"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog<\/title>\n<meta name=\"description\" content=\"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog\" \/>\n<meta property=\"og:description\" content=\"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/\" \/>\n<meta property=\"og:site_name\" content=\"Inside Track Blog\" \/>\n<meta property=\"article:published_time\" content=\"2021-10-28T19:26:06+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2023-06-25T21:06:44+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"2300\" \/>\n\t<meta property=\"og:image:height\" content=\"1294\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Kristin Burke\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Kristin Burke\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/\"},\"author\":{\"name\":\"Kristin Burke\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/3816aaa65b9056339221184a1828b822\"},\"headline\":\"How Microsoft narrows the threat funnel on over 600 billion monthly security events\",\"datePublished\":\"2021-10-28T19:26:06+00:00\",\"dateModified\":\"2023-06-25T21:06:44+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/\"},\"wordCount\":1794,\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2021\\\/10\\\/10328_wordpress-hero.jpg\",\"keywords\":[\"Zero Trust\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/\",\"name\":\"How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2021\\\/10\\\/10328_wordpress-hero.jpg\",\"datePublished\":\"2021-10-28T19:26:06+00:00\",\"dateModified\":\"2023-06-25T21:06:44+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/3816aaa65b9056339221184a1828b822\"},\"description\":\"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#primaryimage\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2021\\\/10\\\/10328_wordpress-hero.jpg\",\"contentUrl\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/uploads\\\/prod\\\/2021\\\/10\\\/10328_wordpress-hero.jpg\",\"width\":2300,\"height\":1294,\"caption\":\"Kristin Burke is a principal service engineer on Microsoft\u2019s Digital Security and Resilience Security Incident Response team. (Photo by Aleenah Ansari | Inside Track)\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How Microsoft narrows the threat funnel on over 600 billion monthly security events\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/\",\"name\":\"Inside Track Blog\",\"description\":\"How Microsoft does IT\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/#\\\/schema\\\/person\\\/3816aaa65b9056339221184a1828b822\",\"name\":\"Kristin Burke\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=ged3e302f6de0ee4a8a1fcc8c84090e81\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=g\",\"caption\":\"Kristin Burke\"},\"url\":\"https:\\\/\\\/cm-edgetun.pages.dev\\\/insidetrack\\\/blog\\\/author\\\/krburke\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog","description":"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/","og_locale":"en_US","og_type":"article","og_title":"How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog","og_description":"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.","og_url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/","og_site_name":"Inside Track Blog","article_published_time":"2021-10-28T19:26:06+00:00","article_modified_time":"2023-06-25T21:06:44+00:00","og_image":[{"width":2300,"height":1294,"url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","type":"image\/jpeg"}],"author":"Kristin Burke","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Kristin Burke","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#article","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/"},"author":{"name":"Kristin Burke","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/3816aaa65b9056339221184a1828b822"},"headline":"How Microsoft narrows the threat funnel on over 600 billion monthly security events","datePublished":"2021-10-28T19:26:06+00:00","dateModified":"2023-06-25T21:06:44+00:00","mainEntityOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/"},"wordCount":1794,"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","keywords":["Zero Trust"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/","name":"How Microsoft narrows the threat funnel on over 600 billion monthly security events - Inside Track Blog","isPartOf":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#primaryimage"},"image":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#primaryimage"},"thumbnailUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","datePublished":"2021-10-28T19:26:06+00:00","dateModified":"2023-06-25T21:06:44+00:00","author":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/3816aaa65b9056339221184a1828b822"},"description":"Microsoft sees billions of security events every day, but a carefully orchestrated response allows them to separate innocuous alerts from harmful threats.","breadcrumb":{"@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#primaryimage","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","contentUrl":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","width":2300,"height":1294,"caption":"Kristin Burke is a principal service engineer on Microsoft\u2019s Digital Security and Resilience Security Incident Response team. (Photo by Aleenah Ansari | Inside Track)"},{"@type":"BreadcrumbList","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/how-microsoft-narrows-the-threat-funnel-on-over-600-billion-monthly-security-events\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/"},{"@type":"ListItem","position":2,"name":"How Microsoft narrows the threat funnel on over 600 billion monthly security events"}]},{"@type":"WebSite","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#website","url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/","name":"Inside Track Blog","description":"How Microsoft does IT","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/#\/schema\/person\/3816aaa65b9056339221184a1828b822","name":"Kristin Burke","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=ged3e302f6de0ee4a8a1fcc8c84090e81","url":"https:\/\/secure.gravatar.com\/avatar\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/7bca4c3eb74e6747404f489e3f8c52ec0b01aab55a43e02eb4e1148e152829de?s=96&d=mm&r=g","caption":"Kristin Burke"},"url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/author\/krburke\/"}]}},"jetpack_featured_media_url":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/uploads\/prod\/2021\/10\/10328_wordpress-hero.jpg","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p9hcZA-1Xg","_links":{"self":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7518","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/users\/114"}],"replies":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/comments?post=7518"}],"version-history":[{"count":19,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7518\/revisions"}],"predecessor-version":[{"id":11619,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/posts\/7518\/revisions\/11619"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media\/7521"}],"wp:attachment":[{"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/media?parent=7518"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/categories?post=7518"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/tags?post=7518"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/cm-edgetun.pages.dev\/insidetrack\/blog\/wp-json\/wp\/v2\/coauthors?post=7518"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}