Microsoft [Photo: Shutterstock]

Microsoft has unveiled an Integrated Security Operations Center (ISOC) in its integrated security solution Microsoft Defender, SiliconANGLE reported on Tuesday.

The move is part of a push to restructure security operations products around AI agents. It centers on offering in Defender security information and event management (SIEM) functions that had been in Microsoft Sentinel.

Rob Lefferts (롭 레퍼츠), corporate vice president for Threat Protection at Microsoft, said, "Work that an entire team used to do is now being done by a single operator and an agent framework." He said, "If protection and operations run separately and analysts have to move between multiple tools to piece together incident circumstances themselves, the defenders fall behind."

Case management and workbook features brought over from Sentinel can be used immediately in the Defender portal without separate configuration. The same applies to a function that creates automated playbooks through everyday-language instructions. User and entity behavior analytics (UEBA), and integration with Azure and external data, require additional setup. Microsoft said there are more than 500 connectors for external data, and fees may be charged when collecting data.

Microsoft also highlighted an "integrated protection loop" that directly connects telemetry data, exposure data and threat intelligence to Defender control functions. Lefferts cited Defender's "attack disruption" function, which blocks hacking while it is underway, as a representative example.

Agent functions are another point Microsoft has emphasized. In ISOC, agents can view the same information as human analysts and take the same actions. With key security tasks connected to agents from the outset, agents can investigate and respond to incidents without separate setup.

ISOC is based on Project Perception, which Microsoft unveiled along with its first in-house security model, MAI-Cyber-1-Flash, in July. Project Perception agents still require human approval to execute critical actions. Humans also set priorities. Lefferts called it "strategy is for humans."

A public preview of ISOC is available immediately to customers of the Microsoft Defender suite and Microsoft 365 E5 and E7 licenses.

Keyword

#Microsoft Defender #Integrated Security Operations Center #Microsoft Sentinel #SIEM #Project Perception
Copyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.