#azurenetworksecurity

2024-02-14

๐€๐ง๐ง๐จ๐ฎ๐ง๐œ๐ข๐ง๐  ๐ง๐ž๐ฐ ๐Ÿ๐ž๐š๐ญ๐ฎ๐ซ๐ž๐ฌ ๐š๐ง๐ ๐ข๐ฆ๐ฉ๐ซ๐จ๐ฏ๐ž๐ฆ๐ž๐ง๐ญ๐ฌ ๐ข๐ง ๐€๐ณ๐ฎ๐ซ๐ž ๐…๐ข๐ซ๐ž๐ฐ๐š๐ฅ๐ฅ

โžกFlow Trace logs are now generally available.

โžกAutoscaling based on the number of connections is now generally available.

โžกParallel IP Group update support is now in public preview.

techcommunity.microsoft.com/t5

#azure #firewall #azurefirewall #cloudfirewall #cloudsecurity #network #networksecurity #monitoring #soc #monitoring #azurenetworksecurity #cloudnative

2023-08-30

๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐—ฆ๐—ฒ๐—ฐ๐˜‚๐—ฟ๐—ถ๐˜๐˜† ๐—ก๐—ฒ๐˜„๐˜€: ๐—”๐˜‡๐˜‚๐—ฟ๐—ฒ ๐——๐——๐—ผ๐—ฆ ๐—ฆ๐—ฒ๐—ป๐˜๐—ถ๐—ป๐—ฒ๐—น ๐—ฆ๐—ผ๐—น๐˜‚๐˜๐—ถ๐—ผ๐—ป ๐—ฎ๐—ป๐—ฑ ๐—ช๐—”๐—™ ๐—ฃ๐—น๐—ฎ๐˜†๐—ฏ๐—ผ๐—ผ๐—ธ ๐—œ๐—ป๐˜๐—ฒ๐—ด๐—ฟ๐—ฎ๐˜๐—ถ๐—ผ๐—ป

Learn how to how to integrate the Azure DDoS Sentinel Solution with the Azure WAF Playbook to enable a powerful automated detection and response system.

With this integration, the Azure DDoS Sentinel Solution and the WAF Playbook work together to prevent attacks with the steps described below:

1๏ธโƒฃDuring the first stage of a multi-vector attack campaign, initiated by a malicious actor, the DDoS attack floods the customerโ€™s application, creating chaos and serving as a diversion for the subsequent attack.

2๏ธโƒฃUpon identifying the DDoS attack, Azure DDoS protection mitigates the attack and generates logs that are transmitted to Microsoft Sentinel.

3๏ธโƒฃMicrosoft Sentinel extracts the source IP addresses of the attackers from the logs and triggers the WAF Playbook.

4๏ธโƒฃThe WAF Playbook adds the attack IP addresses to a custom WAF rule with a block action. Azure WAF becomes ready to mitigate the forthcoming stages of the adversary's attack cycle.

5๏ธโƒฃHaving employed the DDoS attack as a smokescreen, the adversary now attempts to breach the application to take the sensitive data.

6๏ธโƒฃAzure WAF acts by blocking access from the source IP addresses of the attacker, thereby preventing them from reaching the data.

techcommunity.microsoft.com/t5

#azure #azuresecurity #azurenetworksecurity #ddos #azureddos #waf #azurewaf #sentinel #microsoftsentinel #microsoft #soc #automation #soar #siem #playbook #cybersecurity #microsoft #microsoftsecurity #cloudsecurity

2023-05-20

Protect Office365 and Windows365 with Azure Firewall

"Traffic from the organizationโ€™s network to the required Office 365 endpoints should be managed and secured, which could be a time-consuming ongoing task. With the recent announcement of Azure Firewall integration with Office 365, you can now easily manage this traffic and leverage the firewallโ€™s security features to secure it"

techcommunity.microsoft.com/t5

#azure #office365 #security #network #windows #azurefirewall #microsoftsecurity #microsoft #firewall #network #networksecurity #firewallpolicy #fqdn #cloudsecurity #cloudnetworking #soc #azurenetworksecurity

2023-05-16

Policy Analytics for Azure Firewall to help IT teams manage the rules in the Azure Firewall policy over time is now general availabe.

This feature provides critical insights and surfaces recommendations for optimizing Azure Firewall policies to strengthen security posture.

Key capabilities available in the Azure portal include:

- Policy insight panel: Aggregates policy insights and highlights policy recommendations.

- Firewall flow logs: Displays all traffic flowingโ€ฏthrough the Azure Firewall alongside hit rate and network and application rule match.

- Rule analytics: Displays traffic flows mapped to destination network address translation (DNAT), network, and application rules.

- Single-rule analysis: It analyzes traffic flows matching the selected rule and recommends optimizations based on those observed traffic flows.

azure.microsoft.com/en-us/blog

#azure #azurefirewall #firewall #cloud #cloudnetworking #azurenetwork #azurenetworksecurity #flow #flowlogs #policyanalytics #microsoft #soc #secops #securityplatform

2023-04-04

Azure Firewall enhancements

It offers new logging and metric enhancements designed to increase visibility and provide more insights into traffic processed by the firewall:

o Latency Probe metric: monitor the latency of the firewall.

o Flow Trace Log: ability to monitor and track every packet through the firewall is paramount for identifying packet drops or asymmetric routes.

o Fat Flows Log: industry-known as Fat Flows.

azure.microsoft.com/en-us/blog

#azure #azurefirewall #firewall #ngfw #cloud #cloudnative #network #networksecurity #microsoft #soc #monitoring #latency #flow #idps #ids #threatintelligence #url #urlfiltering #cloudnetworking #microsoftsecurity #azurenetworksecurity

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst