Microsoft-Defender-for-Cloud/Simulations
Lara Goldstein e1bcb27011
Update README.md
2023-04-24 09:59:06 -07:00
..
Azure Security Center Hunting Playbook_V2.pdf Adding ASCHuntingPlaybook_V2 PDF 2020-06-25 15:05:33 -05:00
Azure Security Center Linux Detections_v2.pdf Adding ASCLinuxDetections_v2 PDF 2020-06-25 15:07:30 -05:00
Azure Security Center Security Alerts Playbook_v2.pdf Adding ASCSecurityAlertsPlaybook_v2 2020-06-25 15:06:36 -05:00
Microsoft Defender for Cloud Hunting Playbook_V3.pdf Add files via upload 2022-04-12 15:11:21 -05:00
Microsoft Defender for Cloud Security Alerts Playbook_v3.pdf Add files via upload 2022-04-07 10:05:32 -05:00
Microsoft Defender for cloud Linux Detections V3.pdf Add files via upload 2022-04-07 10:14:29 -05:00
README.md Update README.md 2023-04-24 09:59:06 -07:00

README.md

Microsoft Defender for Cloud Simulation Playbook

There are many ways to simulate an alert in Microsoft Defender for Cloud and if you just want a simple validation to get an alert, use the procedures described in this article. For a more scenario-based approach, you have the resources below that you can use to validate different threat detections capabilities available in Microsoft Defender for Cloud.

Alert Simulation for Defender for Servers (Azure and Non-Azure VMs - Windows)

If you are testing the integration with MDE, use this article to validate the alert integration. Make sure that the server that you are testing this procedure is already onboarded and using MDATP.

Alert Simulation for Defender for Servers (Azure and Non-Azure VMs - Linux)

Alert Simulation for Defender for Containers

Alert Simulation for Defender for Storage

  • This article go over the steps to simulate an upload of a test malware (EICAR) to an Azure Storage account that has Defender for Storage enabled.

  • Defender Storage

Alert Simulation for Defender for Key Vault

Alert Simulation for Defender for Resource Manager

Alert Simulation for Defender for DNS

Alert Simulation for Defender for App Service

Alert Simulation for Defender for SQL on Machines

Alert Simulation for Defender for APIs

Threat Hunting in Microsoft Defender for Cloud and Log Analytics Workspace

  • This simulation playbook go over a threat hunting scenario using Microsoft Defender for Cloud and searching for evidences of attack in Log Analtyics workspace.

  • Download this PDF and follow the steps to configure a lab environment, simulate alerts in Windows and query data using KQL in Log Analytics workspace.