본문으로 건너뛰기

Microsoft Azure Sentinel

Overview

Microsoft Sentinel (formerly Azure Sentinel) is a cloud-native SIEM and SOAR solution built on Azure Log Analytics. KYRA MDR ingests Sentinel incidents, alerts, and analytics rule matches via the Azure REST API and Microsoft Graph Security API for unified cross-platform visibility.

Prerequisites

  • KYRA MDR account (MDR tier or above)
  • KYRA Collector installed with outbound HTTPS access to Azure
  • Azure subscription with Microsoft Sentinel enabled on a Log Analytics workspace
  • Azure AD app registration with Microsoft Sentinel Reader role
  • Application (client) ID, tenant ID, and client secret

Configuration

Step 1: Register an Azure AD Application

  1. Navigate to Azure Portal > App Registrations > New Registration
  2. Name: KYRA-MDR-Sentinel, Supported account types: Single tenant
  3. After creation, go to Certificates & secrets > New client secret
  4. Record the Application (client) ID, Directory (tenant) ID, and Client secret value

Grant API permissions:

  1. Go to API permissions > Add a permission > Microsoft Graph
  2. Add: SecurityEvents.Read.All, SecurityIncident.Read.All
  3. Click Grant admin consent

Step 2: Assign Sentinel Reader Role

Terminal window
# Get workspace resource ID
WORKSPACE_ID=$(az monitor log-analytics workspace show \
--resource-group <RG_NAME> \
--workspace-name <WORKSPACE_NAME> \
--query id -o tsv)
# Assign role
az role assignment create \
--assignee <APP_ID> \
--role "Microsoft Sentinel Reader" \
--scope "$WORKSPACE_ID"

Step 3: Enable Diagnostic Settings

Terminal window
az monitor diagnostic-settings create \
--name "kyra-mdr-export" \
--resource "$WORKSPACE_ID" \
--event-hub "kyra-sentinel-events" \
--event-hub-rule "/subscriptions/<SUB>/resourceGroups/<RG>/providers/Microsoft.EventHub/namespaces/<NS>/authorizationRules/RootManageSharedAccessKey" \
--logs '[{"category":"SentinelAudit","enabled":true},{"category":"SentinelHealth","enabled":true}]'

Step 4: Configure KYRA Collector

/etc/kyra-collector/sources.d/azure-sentinel.yaml
source:
type: azure-sentinel
tenant_id: "<TENANT_ID>"
client_id: "<APP_ID>"
client_secret: "<CLIENT_SECRET>"
subscription_id: "<SUBSCRIPTION_ID>"
resource_group: "<RG_NAME>"
workspace_name: "<WORKSPACE_NAME>"
poll_interval: 60 # seconds
collect:
- incidents
- alerts
- hunting_queries
Terminal window
kyra-collector reload
kyra-collector status

Step 5: Verify API Connectivity

Terminal window
# Get access token
TOKEN=$(az account get-access-token \
--resource https://management.azure.com \
--query accessToken -o tsv)
# List recent incidents
curl -s -H "Authorization: Bearer $TOKEN" \
"https://management.azure.com/subscriptions/<SUB>/resourceGroups/<RG>/providers/Microsoft.OperationalInsights/workspaces/<WS>/providers/Microsoft.SecurityInsights/incidents?api-version=2024-03-01" \
| jq '.value[:3] | .[].properties | {title, severity, status}'

Step 6: KQL Queries via Log Analytics

Terminal window
az monitor log-analytics query \
--workspace "$WORKSPACE_ID" \
--analytics-query "SecurityAlert | where TimeGenerated > ago(1h) | project TimeGenerated, AlertName, AlertSeverity | take 20" \
--output table

Example KQL queries used by KYRA MDR:

// Brute force detection
SigninLogs
| where ResultType != "0"
| summarize FailureCount=count() by UserPrincipalName, IPAddress, bin(TimeGenerated, 5m)
| where FailureCount > 10
// Incident summary by severity
SecurityIncident
| where TimeGenerated > ago(24h)
| summarize count() by Severity, Status

Step 7: Data Connectors to Enable

ConnectorData Tables
Azure Active DirectorySigninLogs, AuditLogs
Microsoft 365 DefenderAlertEvidence, DeviceEvents
Azure ActivityAzureActivity
Azure Key VaultAzureDiagnostics
Microsoft Defender for CloudSecurityAlert

Collected Log Types

Log TypeDescriptionSecurity Use
IncidentsCorrelated security incidents with severity, status, ownerCase management, SOC triage
AlertsIndividual detection rule matchesThreat detection
Hunting ResultsCustom KQL hunting query resultsProactive threat hunting
Sentinel AuditConfiguration changes to rules and connectorsChange tracking
Sentinel HealthData connector health and ingestion statusMonitoring reliability
WatchlistsWatchlist match eventsCustom indicator matching

Troubleshooting

  • 401 Unauthorized: Client secret may have expired. Regenerate via Azure Portal or az ad app credential reset --id <APP_ID>.
  • 403 Forbidden: Verify the service principal has Microsoft Sentinel Reader role. Check with az role assignment list --assignee <APP_ID>.
  • No incidents returned: Verify Sentinel has active analytics rules at Azure Portal > Sentinel > Analytics.
  • Stale data: Default poll interval is 60s. For near real-time, reduce to 30s but monitor API rate limits (200 requests/5 min per tenant).
  • KQL query timeout: Add TimeGenerated > ago(1h) filters to scope large table queries.

Contact kyra@seekerslab.com for integration support.