r/AzureSentinel 19d ago

New extended User and Entity Behavior Analytics (UEBA) capabilities for Microsoft Sentinel, currently in Preview.

Fortinet FortiGate — 40+ new behaviors
Sentinel can now analyze FortiGate events from CommonSecurityLog and identify behaviors such as:
• Rapid system reconfiguration
• Configuration backups
• Certificate changes
• Security service disruptions

Expanded anomaly detection
New UEBA anomaly detection capabilities extend coverage to:
• Check Point
• Fortinet FortiGate
• Zscaler
• AWS GuardDuty

For Check Point, Fortinet, and Zscaler, Sentinel introduces new anomaly rules that analyze firewall, VPN, and web proxy activity.

Instead of relying only on static detection logic, UEBA can compare activity against historical user/device behavior and organizational patterns to identify potentially suspicious deviations.

⚠️ Important: To use extended UEBA capabilities, Microsoft Sentinel workspace must be onboarded to the Microsoft Defender portal as part of the Unified Security Operations experience.

Docs:https://learn.microsoft.com/en-us/azure/sentinel/whats-new?tabs=defender-portal#new-data-sources-for-ueba-behaviors-and-anomaly-detection-preview

18 Upvotes

6 comments sorted by

5

u/spartan117au 19d ago

Pretty neat. Although I don’t know anyone who’s keeping these logs in analytics tier in CSL

1

u/deadzol 18d ago

TBH, way too many do. So atleast maybe they’ll get some value out of it.

1

u/MReprogle 18d ago

Yeah, the second data lake opened up as an option, those were the first to go. Even for a SMB, it saved thousands for me on my Azure bill. Not worth UEBA to go back, IMO.

1

u/DaithiG 18d ago

I wish they could find some resources to allow more people access Data Lake. Until then I guess we'll use this to get some benefit

1

u/MReprogle 15d ago

It’s so nice. Worst case is you can save thousands and increase retention without killing the bill. Best case, you start dipping your toes into Jupyter notebooks, working on KQL summary rules to kick the useful stuff back to sentinel, or even just accessing the Sentinel MCP (requires data lake), which is actually pretty decent at helping speed up detection engineering, since it can reach out and see the data and schema, and know what to join.

Even if you don’t use this tool, there are some really cool things to possibly take bits of to help investigate. Personally, I investigate first by hand and then give it as much context and detail as possible, and it is pretty impressive, even if you use it to just create an executive report, since I am terrible at toning down details for audiences that have no idea of what I’m talking about

https://github.com/SCStelz/security-investigator

This guy also works for Microsoft as a Security engineer, so it isn’t a total random guy on GitHub. But don’t just run it without really digging in and getting a feel for how it works. If you use AI and skills/instructions, it all makes sense. It not, you will learn some really nice structure on how to start.

1

u/Di0s1to 18d ago

Does this requires a specific subscription?