Videos
We have an audit running at the moment, and the technician is telling me that Sentinel is necessary for Defender XDR.
My opinion is, that XDR is a SIEMless system, hence no need for a SIEM but similar performance. But Sentinel is a SIEM, so that would defeat the idea of XDR.
Does anyone know if Sentinel is actually necessary for the XDR Detections or if it is just to have "better" automation?
Can anyone explain why the Office Activity table does show up in Microsoft Defender advanced hunting yet you can see it in Sentinel. I'm circling back to this after a couple of years out of the game and could have sworn you used to get that table in Defender.... I'm getting old so maybe it's that....
Looking at bringing in one of these as a premium AV. We would need to license MDE stand alone since we aren't getting it included in any major environment. At $5.25 it seems pretty good.
S1 control or complete are significantly more, but are they actually better?
I'm aware that cloudstrike is an option as well but I haven't looked closely at those differences.
We are also running threatlocker and looking to bring in huntress, which I know is closer connected to MDE
All these products have so much overlap and marketing checklists that it's hard to spot the holes in coverage.
You'll get S1 through Solarwinds for around $2. Connectwise are similar.
I think its all subjective. Security is build in layers. A lot also has to do with logging, if it's not logged it doesn't exist. I recently seen a item from Jon Hammond which was really surprising and am now doubting all EDR.
Read this and see how most EDR's don't catch everything: https://www.mdpi.com/2624-800X/1/3/21