Customer:
A leading EDR solution provider.
A leading EDR solution provider.
EDR Integration – Custom Integration
Built a Custom Connector Enabled seamless data exchange between the EDR platform and Microsoft Sentinel.
Event Normalization Mapped EDR alerts to Microsoft’s Common Event Format (CEF) for unified analytics.
Automated Playbooks Used Azure Logic Apps to isolate endpoints, trigger scans, and send SOC notifications automatically..
Automated Alert Ingestion Streamed EDR alerts and telemetry into Sentinel via Azure Monitor and REST APIs.
Incident Enrichment Added device, user, and process-level details, along with MITRE ATT&CK mapping.
Compliance Dashboards Created Sentinel visualizations to monitor incident response metrics and audit logs.