A reactive monitoring service provided from Insta’s Security Operations Center
Monitors the operating environment using Microsoft Defender XDR products. The alerts are sent via Microsoft Sentinel to Insta’s Security Operations Center for analysis. The Security Operations Center analyzes the events and takes the necessary countermeasures (isolation of the unit, etc.) according to its authorizations.
Key areas of the service include:
Fine-tuning the alert ruleset
Sending information security observations (alerts) to the Security Operations Center
Countermeasures
The service can be expanded with Defender XDR Pro, which introduces an expert who regularly tracks the operating environment’s settings and recommends improvements