Gareth Emslie: Harnessing Dynatrace Application Security with Microsoft Sentinel for Advanced Threat
About this talk
In this talk, Gareth Emsley presents on leveraging Microsoft Sentinel for advanced threat hunting in application security using Dynatrace. He discusses the challenges faced by security professionals, such as an increase in data breaches and the complexities of multicloud environments. The speaker highlights the importance of integrating signals from Dynatrace with Microsoft Sentinel to improve security posture. He explains how data can flow between the two platforms through connectors, enabling better visibility and threat detection. Additionally, he touches on monitoring vulnerabilities, analyzing attacks, and the benefits of using Kusto Query Language for deep data analysis. Emsley emphasizes the need for effective telemetry to aid in identifying threats and enhancing overall security capabilities.
Full transcript
ladies and Gentlemen please welcome our next speaker Gareth an presenting the topic harnessing din trce application security with Microsoft Sentinel for advanced bread hunting so yeah it's a pleasure to be here with you all today um in sunny villainous if that's how you pronounce it um so my name is Gare emsley um I'm a Happ scaler strategist with DIN trce and um yeah I'm also interested in
security uh today I'm I'm going to be talking to you a little bit about how how we can combine signals from both DIN trce and other um vendors which are connected to your Microsoft Sentinel uh workspaces so this is my standard disclaimer I don't claim to be an expert in any of the things we will talk about today uh I'm just really interested in in uh technology
security and and development basically software development so in 2017 The Economist um published an article the title was the world's most valuable resource is no longer oil could you Hazard a guess to what the actual resource is yeah yes you would be right so data is today is oil all right and attackers know it um you know that it hasn't gone unnoticed by the attackers um according
to the identity theft Resource Center in 2021 there were around 1,860 breaches right which were reported 2022 we had 1,800 so there was a bit of a dip but in 2023 we saw it almost double right this included around 350 millon records uh customer records right so data which was stolen and it was a 78% increase over the previous year these are some scary uh numbers right
and we really as Security Professionals and it professionals we we really have to protect against these kinds of U situations of course you'll be happy to know things haven't changed much over the years right um social engineering and the human element is the weakest link right so of these uh reported um um data thefts social engineering played a part in 18% of them 10% was R ransomware
and both mware and zero day uh attacked vectors were exploited also uh a lot more right than previous years so they grew 74 4% of all the breaches included in the report had a human right so this paints a a really Bleak picture really at the end of the day uh Defenders a Defenders are also challenged right by uh their environments the complexity of the environments they
are now multicloud environments they have various data States living in data centers all over the world right which have to be protected there is a little bit of confusion sometimes about who protects what and who's responsible for what right in the stack when you talk uh Cloud workloads also volume of um just data points has exploded right alerts the number of alerts you have to deal with
has exploded uh reduced man power so a lot of uh layoffs over the last couple years the cost right of of monitoring these workloads buying the tools that you need um you know to fill all the gaps is also exploding another area where there are challenges is you know how do you correlate different uh events across these different platforms right this can be really challenging for teams
so today I'm talking about Microsoft Sentinel so you know we'll focus a little bit about a little bit on um the ecosystem that they have um they look to drive all Telemetry into Microsoft Sentinel from their various properties as well as you know third party uh vendors like AWS you can connect to Sentinel as well they have their own threat intelligence uh stack as well as their
own Defender you know Suite of of uh tools for protecting you know customer workloads and it's all based on Azure active directory of course or inra ID sorry how many of you actually uh use Azure in your environments okay how many of you use sentinel okay a few okay good so there's a rich ecosystem right of both both third party and first party um Integrations in uh
so one of the one of the challenges is a partner right with Sentinel you have to um um work out how do we get our data our customer data into the Sentinal workspace or into the login Antics workspace right so there are two ways we can do this um one was codeless connector which at the time is a is a recommended uh practice you know you you
give the definition of the the connector to Microsoft they run it for you right on behalf of the customer who's installed the connector and the other is deploying some resources to um to the customers Azure subscription right through a custom connector so there two methods um there there are other extensibility points available to you um if you're building uh such Integrations but these are the most important
right we're looking for signals to do our thread hunting as I mentioned um you can get third party connectors right and third party Solutions uh for Sentinel so there's a a Content Hub where you can self-service install um the various uh solutions that you might be looking for right like uh from both Microsoft and other vendors so it's key as we'll be talking a little bit about
threat hunting it's key that you have the right Telemetry the light right insights right or data um available to you when you're actually uh looking for threats so just looking at first party properties right within Microsoft of course uh we're getting excellent uh signals if you've deployed uh things like input protection uh for collecting you know malware uh fishing attempts Etc dat exfiltration insights um you also
uh get insights around Cloud apps which are which are being protected by the service as well as um some built-in capabilities where you know you can do Behavior analytics to detect various Anonymous uh Behavior right within your environment so there's a lot available to you right if you buy into the suite uh of products right the the 365 Defender Suite of products also on the entra side
of things so on the identity side if you're using entra you have various tools at your disposal right to understand you know uh if anybody's using Anonymous IPS or anonymization Services um you know if they've logged in in China and the next day they logged in somewhere a certain distant away you know you can you can report on all these uh events right uh within your identity
uh stack um it's also possible to use buil-in reports to look at you know risky users risky sign-ins and then also detection of risky events which which happens for you so another key aspect I think in in having you know security stack is the threaten intelligence piece um so Microsoft obviously um they have threatened intelligence built into their uh where you were able to drive various um
insights into or indicators into intelligence um a lot of that comes from you know traditional security vendors and we're able to drive also um things like taxi feeds so data from Taxi feeds into Sentinel as well right where we could actually use those um for our analytics so you probably know about the MIT Tech framework um Sentinel basically bases um a lot of um the functionality is
based on on this framework uh where you can categorize and order you know queries uh by tactics to understand kind of how well you are covered right um from a uh security standpoint so when we come to threat hunting so um the primary tool or one of the primary tools um is essentially custo so kql it's a query language which um really originates from log analytics you're
able to you know query super fast um all the data in your uh which you've ingested into your workspace um really complex queries you can query across tables um and you can understand or explore the data that you've collected you know over a certain uh period on the other hand um you know Microsoft tried to make it easy for you um they have a lot of built-in
queries available to you they also have more powerful capabilities like notebooks Jupiter notebooks um where you can actually um do much more complex um hunting and and quering of your data another key aspect um is that SEL includes both saw capabilities and and also automation right so um based on on your queries you can trigger alerts you can trigger incidents um and you can also uh execute
remediation tasks right even in external systems like din Trace so as I mentioned you can Define these complex rules um and you can also manage then you know the the the raised incidents you can manage those centrally using Sentinel s capabilities okay okay let's see if this works okay so you can see my screen so some of you may be familiar uh with the Azure portal already
and some of you have even deployed Sentinel right but at the end of the day uh Sentinel um is really capability which is added to uh Logix workspace so when you come into the portal you can just search for you Sentinel um click create new workspace you know you would create a resource Group um and um the name whatever okay once the Logics workspace is created um
you can then select it and you know to add the uh Microsoft capabilities so in the meantime I have already created uh another workspace okay so once it's deployed basically um this is where you would land there's an overview uh screen you know which gives you really an overview of your incidents your alerts um all the the kind of insights that you may need right as an
operations team um so something um that will be very useful obviously is um knowing that you can install I mentioned earlier content Hub so this is where you can actually it's like a marketplace where you can actually install various um various Solutions right um if I spell it correctly and so there's a large um list of both uh first party and third party uh Solutions available to
you right to integrate with your various um security tools and okay um there's also uh something called the uh uh Sentinel training lab which I would recommend um that if you if you're trying it out you can just add it to the um to your Sentinel workspace and you'll work through basically a handbook uh which teaches you you know how to use okay so a little bit
about uh Diner trays um as really we we're we're looking here or I'm trying to show value of of combining the two uh Solutions so that you get more insights into your into your environments um so Dino is really an observability platform originally um which a few years ago added uh security appc capabilities right um so you know on the observability side really users can can find
out whether they uh users are um having a good experience with with their applications you know whether they have an outage whether there may be an outage in the future Etc right and then on the security side it's all about you know do we have vulnerable uh applications within the environment you know so do they have vulnerable dependencies um are there attacks ongoing in the environment and
then insights into what those uh different events um you know about those different events and of course the platform is is ex you know complex I'm not going to go into all the details but supports many Technologies so I can show you a little about so on the din Trace so if we look at Din Trace so I don't know how many of you have actually used
din Trace before okay oh great okay so uh we're going to ignore all these other Craft um but really focus on application security so you know this is a module an add-on module which you can have um activated in your tenant um it really does all the things I just described you know so it highlights uh both third party um and code level vulnerabilities in your environment
um and it gives you a way to manage those essentially um understand uh you know which are the you know which Technologies or run times are are are the worst effect Ed and over time uh helps you to improve you know really your uh your stature within your environment um so you can drill into all sorts of information based on uh you know the process which is
running on a specific host in a specific data center it tells you a little bit about the vulnerabilities um the scoring Etc um so if we drill in that's the overview um so if we drill in here we'll see um you know the in this demo environment there's 4 you know 52 vulnerabilities detected um you get what we consider to be so um our AI our Davis
AI basically calculates a score based on the severity of the vulnerability based on U various other uh Telemetry That We Gather like you know do we have access to public internet from that machine do we have access to data and alter and basically comes up with a uh criticality score um and uh you know from din TR itself you can you can actually see um all the
details about you know um the vulnerability uh deep links to get more information you know you can mute the issue if it's um false positive you can see all the related entities right which affected okay let's uh just move on so the same with code level so these are you know within your code so we look at third party code level and then finally attacks so um
so attacks can be useful I mean where your permited defenses haven't caught something for example um so we look at you know various types of uh attacks like SQL injection command injection uh you know those types of things and then uh you know uh raise that to our operations teams uh where they're able to then uh trigger remediation you get obviously a little bit of insights as
well into the type of the attack for example here we can see a SQL uh injection attack um we have the SQL statement as well uh which will give you more information right so so basically we've seen the value or the benefits of the two platforms um you know how can we combine signals from both platforms really to improve your uh security stature right so on the
D TR side we have things like audit logs um which uh can be sent to um to Sentinel we have security problems we have attacks so security problems being vulnerabilities detected in third party and and your own code um we also have things like infra and APM monitoring uh insights right so high CPU High memory things that may indicate I don't know uh Bitcoin minor for um
then so those are all kind of outbound insights to uh potentially to Sentinel right on the Sentinel side we have very powerful analytics uh engine we have you know Advanced hunting alerts we have Jupiter notebooks we have a lot of capabilities right built into Sentinel which we can leverage to push information back into Dino Trace as well right for operations teams to uh be prepared okay so
I mentioned we saw this earlier um so Davis identifies these security problems within your uh environment so we partner with various vendors in industry and we with uh like sneak for example as well as leveraging our own um our own uh rules engines and AI you know to to understand whether an issue is uh apparent in our environment so what we did is we obviously built a
connector so you can bring this data into Sentinel I'll show you a little bit later how that works and how you can use that in your thread hunting I mentioned we also have attacks so we do the same here um we can also bring all our attack data from din Trace into sental right where you can query uh it across with other uh vendor vendor data right
that you have a new environment as I mentioned there are other areas as well like audit logs and um typical APM infrastructure um insights right so both of those uh data points you can also uh bring into Sentinel right and use in your uh queries we also include a number of uh rule templates right so these I'll show these to in a little bit um so these
are out of the box when you install in Sentinel um and they will trigger things like alerts um on certain conditions based on in based on Telemetry and insights which are ingested into Sentinel from Diner trays and um they will basically help you to manage um the number of alerts that you um need to weed through one thing is important of course so depending so we've made
when we built the um the templates we took into the account you know severity um you know whether it should be an incident whether it should be just an alert you know something which is um useful potentially right later when you when you're threat so from both D trace and sentel you have automation capabilities so um this is extremely helpful for uh triggering automatic remediation for example
so in din Trace you can you can create workflows So based on automation engine um also um you can trigger these based on events on schedules um and and various triggers and also you can build your own custom activities for your workflows and the same right so if any of you have used uh Sentinel uh you'll know that you know playbooks based on logic apps under the
the hood all right so we have the playbooks uh capability um in Sentinel so here we can trigger automation when a new incident is created for example so you can enrich an incident with data from an external system um you could do the same or trigger some logic uh when an alert is triggered as well um which can be really useful right to cut down manual steps
which you have to execute in uh your operation Center another area which is um is a possibility is actually pushing various insights back into Dino Trace using playbooks so here we can see uh additional insights which were gathered from uh Defender um showing up in Dino Trace right in in the same um view as the attack you know when the attack was occurring we can see ah
there was some login attempts for example okay so as I mentioned you know when you have your Sentinel workspace created okay anyway I'll just walk you through it um so from the content you can install the din Trace solution right so currently it's it's installed into this uh workspace um but you would just click install that would bring along with it um various artifacts if the internet
is working so various content so we have you know we include connectors uh we include the analytics rules as well as Playbook templates right so these are available to you once you install um the solution and then you're able to configure them you know uh within connector for example you can go to D TR text for and go and open the connector page you provide your dinet
Trace tenant URL an key and you're away right your data starts to flow into okay the same later where you uh once you have data in your workspace you can go to sorry analytics and in Analytics you will have the rule templates available to all the rule templates which are available in the solution um which will basically help you you know raise alerts and incidents uh within
Sentinel based on the insights which you're pulling in through the connectors and the same on the automation right so uh one thing which is quite quite cool is that you can use playbooks um so we have Playbook templates um which can be used for example to add additional insights right or or enrich an incident which is um being tracked by Sentinal with additional data from an external
okay so essentially what we're doing is we're allowing um our customers really to converge data from the development side with the security side right into a single uh workspace um so here we can see um the original diagram that we saw before you know we have the traditional security vendor signals uh being ingested into threat intelligence you know we have things like IPS domains you know file
hashes Etc we add Dino Trace right um through the connectors so we have a connector which is bringing data from din Trace so attacks security vulnerabilities um observability issues bringing those into Sentinel and then we're again enriching dinet Trace um tiet uh problems with insights from Sentinel so it's a essentially it's a circular a flow of data between the two platforms right and this gives you really
um kind of unparalleled insights into what's going on in your environment uh one of the yes okay something I wanted to show you let me just quickly flip over before we close um okay so something I haven't shown you is the data so once you have actually connected the data connectors to your din Trace tenant you can come into can you see yeah so you can come
into your your logs right um and you will see a number of different tables which have been added to your log analytics workspace so things like ATT Tex so for example attex so you will see here essentially all the data points which are collected from Dino Trace um and are available to you for querying right within custa and also available to you uh for creating new alerts
for example in the hunting uh area um we can do things like where is it for instance okay well this is just a basic one but we can create a new uh Central alert rule here based on the you can select your mod U tactics and techniques uh you can do internity mapping so you can map to you know an account or an IP address um you
can also add custom details you can customize the alert uh you can run the query you know on a specific schedule uh looking back at certain amount of data and based on the results you can create incidents right so this is once you've actually established what um your query that you're using and you Cano also automate responses right so you can actually even remediate things automatically okay
so this is all available um from the screen if I go back to um so I mentioned also in the slides um capabilities right so um out of the box there are a ton of um hunting queries available to you right and these tie back they all tie back to the MIT attack framework right where you can see exactly what your coverage is across environment right you
can also simulate you know if you enabled all your analytic rule templates what would that look like for you right so we can do that and we'll see that a different um techniques you know will mitigated um another important point I would say um okay wait let me show you the automation so one thing we do is we see in that last diagram that I showed you
on in the slide um we use a Playbook um basically to add our own threat indicators um to threat intelligence so one of the things that we add is the IP address of the detected attack here um very simply uh edit so this is a Playbook which comes um as part of the solution which basically um adds the attacker IP right as I mentioned as a threat
indicator um and you can use those in further you know queries going forward right so uh I think this is all I have right now do you have any questions yes um the top one was does din Trace Oro perform remediation sorry I does Dino Trace remediation it yeah you can so if we detecting attack you could uh kill a process basically uh yeah Okay cool so
um also you have workflows so automation engine uh you can actually run your own you can create your own workflows to execute your own logic right which would I don't know turn off machines add uh IPS to firewalls uh you know those kinds yep no not that I'm aware of not it's more about highlighting you know the fact that there are vulnerabilities um the interesting thing here
is I um I didn't have it in time for the uh presentation but basically you can actually So based on um vulnerability information you can actually push the details of those resources which are vulnerable into Sentinel and then use that for further threat hunting as well right so host names you know servers and Cloud okay our next question is somewhat interestingly from Steve Jobs uh can you
write your own detection rules in Sentinel and if so in what language is it plain text or something like yaml not yaml no uh so it's custo basically um is what you would write the query in and then you know if you publish it through um I don't know if everybody's seen it but you know Microsoft has a repo on GitHub um where basically help you can
add new Solutions your own Solutions um this is where you would find Dino traces for example the source code and many other vendors are here right and you would see basically how um those are put together so um in here it's kind of yaml but but the query that's executed is is custom okay and then we have a question of can Sentinel cover a company using AWS
Macos open ldap and minimal Microsoft endpoints without ad in aure Cloud what's a you need a consultant for that one yeah I would think so um so its positioned as you know multic Cloud I you know I cannot be certain that it covers all the scenarios that you that you're wishing to cover right but um it's certainly worth investigating and then the last question would be should
cyber threat intelligence teams create hunting plans or should threat Hunters create them themselves i as I will put that one to the side because I'm not uh I don't have any strong opinions I think from my perspective um I would say both you know should be empowered to do so um I don't see why not um you know everything has to be triaged at the end of
the day and we need to understand exactly you know what effect a particular threat has on environment but um I don't have any strong opinions okay