Microsoft Sentinel Capabilities Demo with Abhishek Agrawal
This presentation demonstrates the capabilities of Microsoft Sentinel’s evolution into a unified security platform, showcasing how a single console empowers security practitioners to manage and investigate threats across their entire digital estate. The core principle is that since “attackers think in graphs” and move across domains, defenders need a consolidated, cross-domain view. This is delivered through the Microsoft Defender console, which brings together tools for identity, endpoints, email, and cloud infrastructure. A key feature is the proactive exposure management capability, powered by the Sentinel Graph. It visualizes attack paths from internet-exposed assets to critical data, allowing teams to prioritize patching the most crucial vulnerabilities first, moving beyond simple vulnerability scanning to understanding true organizational risk.
For post-breach scenarios, the platform offers a unified incident queue that reduces alert fatigue by correlating alerts from both Microsoft and third-party sources into a single “Uber story.” When an incident occurs, the Sentinel Graph is used to stitch together the alerts into a coherent narrative and calculate the potential blast radius, showing analysts where an attacker could pivot next and helping them prioritize response actions. This graph-based approach also transforms threat hunting. While analysts can still run traditional Kusto Query Language (KQL) queries on recent data in the analytics tier, they can now also perform “posture hunting” directly on the graph to proactively find overprivileged access or risky configurations before they can be exploited.
These advanced capabilities are powered by the Sentinel Data Lake, which decouples storage and compute to allow for the cost-effective, long-term retention of high-volume data like syslogs and cloud trails. This data is stored in an open Delta Parquet format, enabling multiple forms of analysis on a single copy of the data. Analysts can run KQL queries for retro-hunts spanning years or perform deep, big-data analysis using Spark and Python directly within VS Code. This is further enhanced by AI, where the Sentinel MCP server and GitHub Copilot allow analysts to perform “vibe hunting.” They can use natural language to ask questions, discover relevant data tables in the lake, and even have the AI generate entire Python analysis notebooks, dramatically upskilling the entire SOC and making sophisticated data science accessible to every team member.
Presented by Abhishek Agrawal, Partner Director of Product Management. Recorded live at Tech Field Day Exclusive with Microsoft Security on October 9, 2025. Watch the entire presentation at https://techfieldday.com/event/mssec25/ or visit https://www.microsoft.com/en-us/security for more information.
Transcript
All right. Uh uh. Alright.
So what I'll do is basically, uh, through demos show what Gideon and Scott just talked through, right? So, uh, what you're looking at here is the unified console. I think if you recall the first slide that Gideon showed you, uh, he showed you how in the defender console, this is a defender console.
We have brought together everything that a SOC practitioner needs, right? If we all remember days of civil chairs, where we used to have multiple portals that a security analyst, whether you were trying to understand an email incident or looking at a malware event, or trying to figure out what was happening in your identity space, or trying to connect that to, you know, what might be happening in your cloud infrastructure. What we have done is basically brought all those different consoles into one place.
So this is the one place, if you're in the Microsoft ecosystem, this is a one place top shop for you if you're a security practitioner to take care of, whether you're looking at, you know, identities, your endpoints, you know, events that might be generated inside your, uh, email environment, and then being able to connect that to your SaaS applications, your cloud infrastructure, you know, everything from configuring policies, uh, security policies for these different workloads, or being then be able to do security investigation and response. So it's truly across domain, uh, offering. And the reason we are doing that is because, you know, as Gideon Ventures, and you know, attackers think in graphs, if they're not really attacking just your endpoint or just your email or just your cloud infrastructure, they are gonna attack any part of your infrastructure, of your digital estate and pivot into it, or from one, from one node to another node till they can get to your crown jewels and, you know, either ransom view or extort you or steal the information that thereafter.
So with that in mind, you're really invested in what is our XDR offering, brought all these different domains together. So now you can do cross domain both protection on the pre breach side, and then do investigation respond hunts across all these domains. The first thing I wanna show you in this is, you know, our exposure management capability, and this is the first place where graph starts to show up.
So, one of the questions that, uh, I believe Romeo you were asking was, you know, uh, why is this? Like, once you understand the connections between all the assets in the, in the environment, graphs can help us quickly prioritize, you know, what is the first vulnerability I need to patch? So this is exposed through our exposure manager module inside defender.
And so over here, what I'm gonna look at is there's an, there's an, um, internet exposed, uh, uh, container, but that has an attack path that takes to, um, a storage account that is storing critical, uh, data that I'm using for AI training, right? So because I have this underlying graph, so this graph is powered, uh, by the central graph that Gideon showed you. So that graph becomes a fundamental data structure in the platform that is now powering different security outcomes.
In this case, I am doing essentially a posture assessment, and I've figured out there's an internet exposed container that can lead to a possible breach. So if I, so, uh, so the action here, uh, it would be, it kind of clearly describes what the tax story is, and then gives me a recommendation of, you know, what I need to do, which is basically, you know, I, you know, put this behind a firewall, you know, put this behind a bastion access so you're not having directly exposed containers to the internet. Alright?
So that was the case where it's, you know, pre breach, hopefully, you know, the, as as customers we focus on, you know, good hygiene, we reduce, uh, overprivileged, uh, exposed nodes. We patch our servers on time, we reduce access so that our environments are locked down. Uh, but we know that, you know, sometimes there'll be vulnerabilities, there'll be zero days, and, and, you know, things will get in.
And that's where, as a SOC analyst, you need to be able to quickly look at what's happening in environment, be able to quickly prioritize them and be able to do investigation and responsibilities. So what you're looking at here is the unified incident queue. Um, and this can, this will show you incidents both from Microsoft specific, uh, detection services, but also from third party capabilities that, you know, I think, uh, somebody was talking about Okta, et cetera.
Like, you could have detections on data that was brought into Sentinel, say from Okta or AWS or, you know, CrowdStrike, and then those incidents will show up here. Uh, one thing that, um, Scott referenced was, Hey, we can actually, we're not only looking at, you know, one incident at a time. Uh, we can correlate alerts from different parts of your, uh, environment and stitch that into an incident.
Like, so what does it mean is, you know, one of the challenges SOC teams have had for a long time is, you know, alert noise or alert fatigue. And the reason for that was, you know, we would fire alerts, uh, or different systems would fire alerts at a point level, and you could not connect them together to get to an end-to-end story. So what incidents, uh, capability and defender and Central do is we look at even and alerts that are happening maybe at different points in time across different systems, and be able to correlate them into one Uber story.
So as a SOC analyst, you know exactly what's going on, so you can prioritize your investigation and response. So if I was double clicking to one of these incidents, this is what it would look like. So there are three alerts that are fired in this case in the Azure environment.
And again, using the part of the graph, I've stitched them into a story so I can know exactly what's happening, you know, which IP address was used to log into which user account, and then subsequently what, what other things happened. And the other thing that we have now done is basically add this notion of a blast radio. So I can quickly see, you know, if this person was to get compromised, where would the attacker go next?
So if this, uh, this will render in a second, and that then helps me prioritize, this is the blast release capability that, uh, uh, uh, that Gian talked about. So I can now see that, you know, if this user was to get compromised is an attack pod that goes into, uh, this virtual machine in Azure. And if this is critical, then I can now use that information to prioritize the response steps that I wanna take.
Uh, quick question, Abha, how do you determine, like I am, I am, I'm sure users who have 52 have access to more than one machine and one container, right? Yeah. How do you calculate what the blast rate is for this event is right in the context of here, you just show me two.
Yeah, Right. So this, yeah, actually, so in this demo, this is a demo environment. Obviously, you know, this demo, uh, this person only had two, but imagine they had more, right?
So behind the sea, what's happening on, at the technical level is, you know, uh, as assets are changing the environment, you know, we are computing the relationships between this user and any other asset. So for example, we are looking at the permission set that they might have on entra. So, so will the incident view show me two or will the incident, the, the two assets I have access to, or will the, the blast radius view show me 5,000?
So, so excellent question. So we will show you, I mean, there's two parts. So the system can calculate 5,000.
We will take a subset of that and show you in the graph and, but we'll let you expand, right? So this is about, you know, managing the real estate. So you focus on the first n hops first, but then from there you can expand and get to 5,000.
Do you How choose which one? 5,000? Yeah.
How do you choose which ones you show me? We look at the number of hops, so we are looking at few things. We're looking at, you know, what are the path to critical assets?
One of the things you can do in defender is tag your critical assets, right? Some will be system defined. For example, a domain admin is a critical asset, right?
A subscription owner is a critical asset. An M 365 global admin is a critical asset. So anything that leads to an escalation path to those critical assets, you know, those would be automatically shown.
And then if your, if your, if, if your blast radius goes beyond n hops, then we will basically, you know, I think we use seven hops to say, okay, what are the parts from this user up to seven? And then from there, we, you can, you can re-expand and so they can get to the fullness of your, um, of your graph. Okay.
I'm just confused about like the, the, the, the, the demo environment is, is very limited in that. Like, I don't get the view of, of what it looks like in real life, what, What it look like. Yeah.
Like, uh, uh, act hack on that feedback. Uh, I'll see if you can find like a more complex demo and send it offline. Thank you.
Ro Aish, if I may ask the question. Yeah. What's the bare minimum work, um, an enterprise needs to undertake to leverage, uh, this cap graph capability?
Yeah, so if they turn on, um, es essentially, you know, the Sentinel Lake and graph capabilities, like basically it's, it's literally one click in the portal, right? So, you know, uh, they'll get a banner, I think in, uh, in, in the portal. They just click on that once, once the underlying lake and the graph engines on enable, then these, these features start to light up, right?
Um, there's obviously a, a, a boot up time because we need to, you know, assess the environment for the first, uh, day, uh, look at, you know, all your assets and activity and start stitching to the graph. But once that is done, then then this, this, these capabilities slide up in different particularities in the book. Okay.
Thank you. Alright. Great questions folks.
Alright, so I have a Yeah, Go ahead. Sorry, just sort of related to that, I, I have a somewhat tongue in cheek question. Um, the, the graph showing the potential blast radius and, and sort of the incident, I think I asked this question on a previous, uh, Microsoft security briefing.
So it can show me like, this is an incident that has happened, it shows me after the fact. You can also sort of show me this is what I predict is likely to occur. Yes.
Yeah. Yes. Can, can that, uh, that's quite useful for an analyst perspective.
Can it kind of generate a report that you can then provide to the executive, for example, to explain to them what happens when they say that they accept the risk, uh, so that I can keep that in a draw for the, uh, for when the investigators come from the regulator or, or something else after the incident does actually occur? Um, yeah, that I'm, I'm thinking of this, it, it could be a very useful way to actually motivate, um, spend and budget to actually fix some of these issues. Excellent feedback.
Excellent question. So this example that I showed you before was exactly that. So this is before a breach has happened.
This is just pointing out what, where the risks in your environment are, right? And then you can export this, you could save this. And so at any point if later on in the, in the organization lifecycle this, this service was to get compromised and it was because this was exposed to the internet, you can go back and show the audit report to say, Hey, you know, this was flag previously, you know, for whatever reason the business group accepted the risk.
Uh, and now look, you know, it's part of an incident. So yes, this, this, that information that exists in the system and can be exported out. Yeah, it's, it's sort of a variation of what you've got there, I think, for the attack story.
So being able to surface that like a hybrid between that and the prioritization for like incident break fix, yeah. Um, that would be quite useful as a way particularly just to accelerate the report of like, I need to generate a summary of here is what the, the work plan that we would like to have for the next quarter in, in language that is easier for non-specialists to understand at the moment that, that actually is quite challenging to do. Uh, and, and it, as you say here is like, particularly when there's a lot going on, showing it in a prioritization way that is easy for non-specialists to understand, yes, that can then be attached to a budget line item would be maybe in handy.
Yeah. Excellent feedback there. In fact, you know, I don't have that in the demo today, but, you know, one of the things you can do is because this, this graph and, and the capabilities of accessing graph will be exposed to the MCP server, you can now have, imagine an AI is basically going through all of this and generating a, you know, very simplified, prioritized report for the business groups to say, Hey, this is what happens when you choose not to say, patch this device or change the configuration on the storage account, or, you know, reduce the access on this, uh, on this user.
Uh, and that, and, and explain what the impact could be if, if any of those were exploited. Yeah, I, I'm a little bit sensitive to the, uh, to the potential for generating like something which is a bit wrong or, or slightly misleading from lls because a lot of this is quite templated and, and fairly standardized. So I'm hoping that that variation would be fairly low, but it would be great to have, uh, just like the standard summary thing of like, what we have for this is what the incident means, or this is what the risk, uh, what the risk means for our environment.
Having that to be quite a reliable thing. Just be partly because that means that there's less for me to have to go through and then manually check and go and look into the data myself to make sure that I'm actually not misleading the board. Um, was if I, if I present that sort of thing in board papers, uh, I, I will do that precisely once, uh, before I will be, uh, finding somewhere else to, uh, try this again.
No e excellent feedback. Uh, I think all the building blocks exist, uh, in the product, uh, and that, that report generation can easily be built in a ED format so that you are, you know, very prescriptive, very precise in terms of the risk and what happens when you accept or, you know, choose not to fix the risk. Yeah.
And if it could, like, if you can link into some pricing information of somehow and just have that to start, like pre-fill in or just get your start or budget Yeah. Like you can, That would be amazing. Yeah.
Great, great discussion. I would love to have continue that, that, uh, I have a question as well, um, uh, context wise. So, um, my thoughts were just triggered by you just initially is, is putting in context into our environment.
So I'm assuming there's a way I could say, these are the critical assets, therefore I wanna prioritize them above the same asset. That's not a critical asset as well as here's a recommendation, this is your risk. You've had x amount of incidents that took this exact path already.
Is there any context setting there as well? Is that, do you get what I'm asking? Um, you might repeat the, the first part again.
So yes, we can tag all critical assets, right? And that helps you prioritize, right? So, uh, like which vulnerability or misconfiguration or oversharing you need to fix first, right?
And I think in this example, we are showing you choke points, right? So these resources are things through which multiple attack pos are going to these critical targets, right? So that helps you prioritize your, uh, your response.
And then if you have seen one of those being act, i, I guess your question was if you have seen one of those being played out in a previous incident, then you use that information to prioritize your subsequent Yeah. Like, like, 'cause I, I can give examples to senior leadership and say, you know, this is a huge risk and they can still say, I accept that risk, but if I've got a easy to generate result, um, report that says you've accepted that risk X amount of times that have led to this amount of incidents. Yeah.
Um, again, great feedback. You don't have that out of the box, but again, the APIs and the data in the system, uh, in the platform exists and, you know, that would be a great tool that somebody can build on top of this to kind of do that, you know, basically a backward audit and say how many times have the risk that you've accepted, led to a, uh, uh, to an incident. Uh, and then, you know, from there you come up with some sort of a cosmetic or a, you know, uh, that kind of a decision framework for that.
Uh, I think that would be great tool to, and stop this. Alright, so let me, uh, move forward in the demo flow here. Um, so one of the things that we l let any, uh, any soc team do is they have hunting teams.
You know, people wanna be able to get into the data and this is where, you know, the, the data lake and some of the Rizzo data lake starts to show up further. So what you're seeing here is advance something. This is a KT defender and central I've had for, uh, many years.
So here you are querying essentially the analytics tier. Um, so this is where you would have your 30 days data. In this case I'm looking for, you know, uh, a password spray attempt or unusual sign event in my, in my environment and see, you know, where different, uh, login events have been, um, uh, happening from, right?
So again, you know, all the different tables, uh, uh, that you get from either defender or sentinel are available here. And you can use Costco. Costo is, uh, a very popular query language in the micro ecosystem.
Um, you know, uh, uh, it, it enables you to do very fast searches on top of, uh, various data so you can quickly hunt and pivot for, uh, enormous activities in your environment. Uh, the new thing that I was showing was this is new, this capability, uh, that GI referred to is now you can also use graphs to start doing your hunt. So there's a bunch of predefined scenarios you can look at, you know, what are the parts that take to say a key vault or to a, a user access sensor data.
And then you get to this graph view, and from there you can start assessing, well, this is a key vault, uh, but we find that, you know, Laura has access to this. So, so the, the, the, the question you can gonna ask is, what happens if, and let's assume Laura doesn't have MFA setup or is not using, you know, uh, um, password, its authentication. So if Laura was to get compromised, then, you know, that attacker would get access to the key vault, and from there they would get access to whatever the, the access that this key vault was, was enabling, right?
So you can start doing, uh, I, I call this posture hunting, right? So typically hunting has been in the, you know, once a breach has happened, you're trying to find where the attacker is and where are they going next. But with this you can now do posture hunting to basically start exploring where do you have exposed nodes, where do you have overprivileged access, et cetera.
And then use that to drive further hygiene in your organization To pick on the, what I mentioned before, uh, looks very clean in a demo data set like you have here. What does this look like in production? Because a lot more people than war have access to, uh, likely have access to that resource.
So what kind of preemptive, uh, optimization are you able to do to help me and my team focus on people that need to be focused on? Yeah. Um, uh, ferdo, uh, excellent question.
So, so few things, let me just kind of talk to what's happening behind the scene, right? So, uh, behind the scene we have the link where all the data is, uh, is being organized, right? That is being used to cook these, these graphs that's being loaded into a scale out graph engine and from where these experiences are being served, right?
So we obviously wanna look at the, the practitioner we wanna focus on, you know, how many hops they're looking at at one time so they can really focus their investigation and analysis time. So we control that by the number of hops that we render at a time. Uh, we really focus on critical assets and, you know, parts that are leading to critical assets.
But then you have the opportunity then expand the graph and get into diff different parts of the, uh, of the visualizations. And this allows us to make sure that experience is fluid enough, why allowing you to get to even complex portions in terms of the total size of the data you that you wanna load into your experience. Perfect.
Thanks. Alright, so, um, so we talked about, you know, uh, our unified console, we showed you the exposure management, we showed you investigations and hunting. Uh, I think there was a question earlier saying, okay, you know, are you really about the Microsoft ecosystem or can you get broader, right?
And this is where the connectors that Scott and Gideon referred to, uh, comes into picture. So we have, uh, uh, you know, over 350 different connectors. In this case, I think there was a question about, Hey, what happens if you bring in Okta?
So we have connectors for Okta, we have connectors for SAP, you know, we have Okta for A-W-S-G-C-P, Zscaler CrowdStrike. So we truly support a hybrid environment, right? We do understand like security is a team sport and customers will use, you know, different security tools.
So we have made sure that all of that data can be brought into Sentinel and not just the data. Uh, we will of course make sure that data gets normalized. There was a question earlier about normalization.
That data gets normalized and then you can do detections and investigation response. So everything I showed you with respects to doing exposure management or doing, uh, incident correlation or doing advanced hunting, it works on data from all of these, uh, uh, different data providers, uh, as well. Uh, uh, so one of the things that, uh, I think there was a question earlier about sys logs and network logs and you know, what happens in terms of, hey, I don't wanna, you know, necessarily bring all of that into my analytics here 'cause I don't really find them, uh, they are high volume or can be possibly low fidelity.
So the, one of the other things that you can do in this experience is you have a new table management experience. And in this demo, I'm showing you AWS Cloud trail, but this could have been your s logs as well. You can click on manage tables.
And what I have done is basically said, look, all of that data, I want to go into the data lake and I want to retain for five years, right? So it's as simple as that. You know, you don't have to set up any, uh, your DIY infrastructure, you know, or set up anything else, say in Azure or in AWS.
It's literally one click for a security, uh, or a SOC architect to decide the layout of what, where they wanna send the data, right? So, um, uh, if, if they wanted to send it to analytics tier, that works as well. And as Scott mentioned, anything that goes, genetics automatically gets mirrored to the lake.
So Lake is always your kind of the full copy of all the data. And, uh, as there was a discussion on, on pricing. So the way that data lakes architected is it, it decouples from an architecture perspective, and that's why I like to use the word modern lake.
Um, it is separate storage and separate compute pricing, right? So you can really store high volume data at scale at really low cost. You know, we also pass on compress, we compress the data and we pass on the, say, savings to the customer as well.
So Lake really becomes a great place for you to, you know, park all your security data. Um, I have been in the security domain for, you know, 10 plus years. I was, you know, uh, running Microsoft's MDS services, uh, before, uh, stepping into this, uh, this team.
And the challenge that all security teams have is this un this tension of how much data should I store and how much budget do I have? And the vision for this offering is we, we solve that false choice, right? All security teams should be able to store all the data, right?
And then only when they need, you know, hopefully they never need it, but when they need that data is ready to be analyzed in multiple ways that enables them the security outcomes that they, that they want to achieve. A quick question, I wonder if, um, there is a possibility to take a look at maybe compliance from a perspective of let's say P-C-I-D-S-S, um, and storing the data for a year, you have to store it for a d for a year. Can you apply that to, um, a setting or configuration where it automatically identifies those devices and then configures this to store the data in the data lake for a year?
Wow, omi, brilliant idea. Um, you know, great feedback. We don't have that obviously right now, but, uh, you know, just, just amazing, amazing feedback.
I'm sure there's a way to script this and, uh, you know, like, you know, tag your devices and say, jump a part of like a, a, a specific kind of processing and make sure those logs are tagged. Okay? We showed you the connector.
So the fun part of the lake is, you know, you can actually analyze it in multiple ways, right? So when you, when you choose the connector and send that data to the lake, right? What we are doing is we are storing that data in an open format.
Um, it's, uh, we stored it in Delta parque format, and what that allows us to do is basically run different kinds of analysis engine on top of one copy of data, right? And that goes back to, you know, why this is, you know, from, from a architecture perspective, a great choice. And, and again, this is borrowed from what, uh, you know, other products in Microsoft, like Microsoft Fabric, et cetera, are doing, right?
So this is kind of the modern lake, uh, design point. Uh, so, uh, one, one of the things that we can now do on top of the data is imagine you are in, in an incident response or a forensic scenario, or you're trying to do a retro hunt that needs to go back, say a year back, right? So maybe, uh, you know, your local government or the CS a pushed out an advisory, you know, maybe it's, it's about a nation state actor, but you're going back a year to hunt for that.
Uh, and now that is just built in inside, inside the sentinel, uh, data Lake Explorer. So you can just come, uh, it's the same query that I ran before, but that was running for 30 days, uh, in the analytics gear. Now I can run that, uh, you know, going back 365 days and run that in the lake, right?
So, very easy for, you know, security teams to start driving insights from the lake. Now, when you're doing, uh, analysis of a large volumes of data, sometimes you wanna be able to convert them into jobs. Uh, so the lake now supports view viewing you to be able to batch analysis on top of the data as well.
So you can basically with one click convert that query into a job, and then that can be scheduled. So you can run it, you know, every hour or every night and do aggregations on the data in the lake. And any insights you find, you know, you can promote that, uh, back to your hot tier.
A great example of that would be retro threat intelligence hunting, right? So every day a new, um, TI feed like maybe an I uh, IP address, a domain A URL is being brought into your environment, and you need to match that, you know, going back, say, six months, one year, depending on, you know, whatever your regulated requirements are, right? So doing that now becomes super easy.
You can just schedule a job every night. You take all the TI data. So I think Gideon showed you the TI data's in the lake as well.
You take that, you scan it against all your logs, you know, and then, you know, any hits that you find, you can then promote that into the analytics tier that then becomes part of your regular SOC incident correlation hunting experiences. Okay? So, um, I love gusto.
Gusto is great, you know, but sometimes you need, you know, more horsepower. And this is where, you know, uh, on the same data in the lake, you know, we have enabled big data analytics again, out of the box, right? And to enable that, what we have done is basically released a new Microsoft Sentel extension, uh, that pairs very well, uh, with, you know, GitHub's copilot, uh, extension.
So let me really show you what that looks like, um, for a customer. So what I've done here is install the Microsoft Sentinels vs code extension, right? You can go into the, um, into the GitHub, uh, extension gallery, download this, install it.
Pretty straightforward. Once you've done that, all you need to do is basically log in into, um, into your, uh, security account. And from there, you know, you get to access the same cables that you were seeing, um, in the portal.
So it's literally, you know, one copy of data that now you have enabled multiple ways to access it. Uh, so what I've done in this, this view is this is literally a, a spark python notebook, uh, that is connecting to the lake, right? And doing a deep analysis on pho attempts in my organization going back over a year, right?
And in this case, it has found all the users that has been targeted, you know, that been sprayed at. And so that's where, you know, risk is possibly floating out, uh, in my environment, right? And again, these notebooks can be scheduled as a job as well.
Uh, so in terms of, you know, I think there was a question, uh, earlier about what kind of analytics you can do on the lake. Uh, I would say, you know a lot, right? You can run jobs or, uh, sorry, Fernando, I see this question coming.
No, I'm, I'm, yeah, I'm, I'm the one who have, uh, where does this run? Yeah. So when we provision the, the central data lake, the entire compute of that is provisioned internally.
So it's a fully SaaS offering. All you're doing is logging into Sentinel. You are connecting to the compute environment.
So you can select the kernel here if, uh, let me load. So all these are kernels that are available to you out of the box, uh, again, running inside your tenant that we have provision in the backend for you. And once you select the kernel, then when you hit run, it'll run in your managed compute environment.
So this is Managed compute. This, this is not like running on some, on some poor laptop just because No, no, this is managed compute. You know, you can choose between a small, uh, cluster or a large cluster, and depending on your job that you can do.
And this is, you know, full, full Python spice box. So you get to get all the libraries you can do. Uh, if you're sophisticated, soft teams with data science backgrounds, you can do ML training, you can train your own model, you know, do your mo your own anomaly detections, full power of data analysis now made easily available to every security analyst.
And I assume that this, uh, that this compute farms are CPU only. They're not GPU enabled yet. Currently they're p only.
Okay, thank you. Yeah. Alright.
So, um, this is a part that I get super excited about is, uh, because this isn't in VS code, you also can wire up the GitHub copilot, right? And in GitHub copilot, you can wire up the MCP servers for Sentinel. I've selected the MCP servers for Sentinel.
com/cp. Uh, and you can find it in the documentation. And once you do that, now you can start asking it fun questions, right?
So, um, I use the word vibe hunting or vibe investigation. I'm not sure if it'll catch up or not. But essentially what I'm doing here is, you know, I just ask a simple question, right?
You know, maybe I'm a SOC analyst, I don't quite know what data exists in my lake. I'm gonna ask a question saying, Hey, I'm investigating an incident related to password spray. Tell me what tables are relevant, right?
Um, so the AI will connect to the lake, it'll do a semantic search. So this is where the vector search capabilities start to show up. Uh, and it'll find basically what tables are relevant for me, and actually tell me, you know, why these are the relevant tables and what are the relevant fields for me, right?
So, very easy way to start exploring, or a new way to start exploring, you know, instead of just looking at tables in the schemas in the old way, you can now also start asking questions as to what data exists in my lake and start, uh, you know, start building an verification strategy from there. Alright? So once, once I've done that, uh, let me then ask you the question saying, okay, let me find signing failures in the last 24 hours, right?
So, and, and you summarize. So in this case, it'll connect to a different MCP tool. In this case, it's connecting to, you know, a, a, a query tool.
So it'll, it'll create the query, it'll run the query, and then essentially start finding, you know, uh, what were the failures and were there any anomalous events, uh, that we're seeing? So it's already started to find, hey, there's a password per indicator related to these, these specific IP addresses, et cetera, right? Again, very easy way for, uh, you know, you to do, you know, vibe, investigation, vibe, hunt, start, start using the power of the lake to start exploring the data, uh, with the CP two.
Uh, but sometimes as, as I was showing earlier, I wanna do a long range data analysis over here, right? So in this case, I'm asking the AI to connect to the lake, generate an Jupyter Notebook file, and generate the ping code to do this full analysis, right? So now I have, I, I did some quick queries, expose the data, but now I'm asking AI to essentially generate, you know, my Python code.
And, and as we all know, like one thing AI is really good at these days is generating code. So we are leveraging that for security operations and analysis as well. And so it goes ahead and does that.
And, and so essentially, I was cheating a bit when I showed you this notebook. This notebook was entirely generated, uh, by, uh, by the GitHub co-pilot, uh, agent mode. And it is now able to essentially generate the code, do the analysis by easily understanding the data in the lake, and now allowing me to find insights that otherwise I would've had to spend a lot of time, uh, you know, you know, set up the infrastructure, generate this notebook, do this analysis, and now all of this becomes really part of, uh, you know, I did this, uh, uh, on my own and I know I'm not a native Python developer.
It took me about couple of hours to be able to connect to the lake, do this analysis and find insights, uh, in this environment. Let me pause if there's any questions on what I've showed so far. Yeah, no, I think judge, I, it is just that the, the vibe coding and, and, and yeah, we're, we're still navigating that one.
Let's leave it at that. Yeah. Yeah.
We still, uh, ing, but, uh, I, I, yeah, like, uh, uh, my, uh, if I may, you know, um, uh, I, I, my previous job, I was a developer on the partial team. Uh, I hope, you know, people in this audience know what PowerShell is, and my learning from that journey was like before PowerShell, you know, IT, operations in Windows used to be click offs, right? You would go to, uh, MMC console and, you know, you know, load up, uh, a snap in and, you know, you would click around and, and do stuff and PowerShell opened up and revolutionize how, as an IT persona you could upskill yourself and create more value for your organizations through automation, right?
Uh, I see, like what I've showed you so far, you know, and, you know, obviously you're still learning what will happen in this, uh, AI era, but I believe is opportunity for everybody in the SOC team to use these modern tools to upskill themselves and create more value for themselves. We know that every security team is struggling with, you know, uh, uh, talented people and hiring and all of that. And one way to, you know, address that, uh, that, uh, challenge is, you know, use these modern tools to empower everybody to do more and create more value for their security.
Uh, teams Mostly agree. Yeah. Alright, so, um, switching back.
Um, so one of the things that we, uh, that Gide talked about was, uh, security copilot. Um, so, uh, as part of security copilot that we announced on nine 30, um, there's a whole bunch of agents that are now available with security copilot, again, you know, agents both from Microsoft themselves, but also from our rich partners, um, you know, around the globe that is now available that you can now install directly, uh, into a security cloud environment and start, you know, using the data in the lake and other analytics engines that we have provided to, you know, find interesting, uh, security outcomes. com, that is now live and, you know, a great set of solutions from, you know, partners like Illumio and our part of this offering.
So, you know, customers can go to the store, acquire their agents and solutions, install it on top of the platform, and when they install it on the platform, it comes with, you know, I, I use the word composite app. It'll have their agent, it'll have their notebook, it'll have the connector that is bringing the lumion sites on top, and then, you know, uh, doing data analysis and then being able to, you know, generate agentic insights on top of that. Alright, so that was my, uh, kind of planned demo.
Uh, I walked you through essentially everything that Vivian and Scott were talking through. We showed you how we have evolved. Uh, we have brought together all our, uh, you know, SOC products into one console.
You know, it in integrates deeply with Sentinel. Uh, from there it layers into the lake. And then Lake enables you to do deep, deep analysis, how we have used graph to light up different security outcomes in different places, you know, across pre breach and post breach, and how we have enabled, uh, you know, AI capabilities to enable, you know, security analysts and agents to derive more insights from the security data.
So, uh, slightly challenging question, given this is, this is all based in Azure, is that correct? The backend infrastructure for, you know, all these services is running in Azure? Yes.
Yeah. So for, if, if it's quite good, which parts of it look like they are, um, for some organizations they are somewhat reluctant, uh, to put some of their data in the cloud. Um, uh, is there a way to connect some of this capability to a data lake that isn't in Azure?
Can I, can I plug this into other data sources that I perhaps run on self-hosted infrastructure, Uh, not today, um, but, you know, would love to, you know, explore and understand, you know, what those setups are, if this is a regulated scenario, et cetera. Um, so we do have like not specific to this products, like we have, uh, you know, offerings of our cloud capabilities for specific, you know, uh, entities, et cetera. And so the ask is, Hey, can this be put in a box and made available to those specific entities?
Then, um, that is definitely a possibility. But you know, as what I've demo so far, it currently is running on Azure. Yeah.
And, um, I mean, I'm aware that you do have some, um, some high security, um, presences in, in various nations because there are certain government agencies, for example, that prefer to keep their, uh, their data away from the general public. Um, but it does. So there, there is essentially a requirement that if you want to take advantage of this, you do need to ingest your data into a cloud system somewhere.
How you architect that and how you actually, um, your comfort level for that, where that data is going, um, is something that you'll need to, to go through. Yeah. Um, and I, there I can see there are some advantages for things like, for example, rag, um, where I can have highly sensitive data sources that I can keep separate, but I can expose them to some of these analysis capability through kind of an arm's length Yeah.
Um, way of doing things. So it, if there are some of those capabilities, that's something I'd be interested in learning more about later. But if it doesn't sound like you right Out there are some capabilities that we are thinking internally or I'm not, uh, you know, allowed to share at this, uh, uh, at this time.
Sure. I'm, I'm sure it's, this is a question that has come up at least once I, I doubt I'm the first person to ask it. Yeah.
Uh, stay tuned and I'm sure we'll, you know, share some, some updates shortly. Okay. Right.
Um, I mean, that's all I had in terms of demos. I'm happy to take, you know, more questions. Um, Anyone?
Sorry, I, I was fiddling with the, with the, the, the audio button here. Uh, I'd love to understand, like, you've been, you've been evolving the, the, the, the product for a while now. I'd love to understand, what can you share about early experiences or early versions of something that were changed based on design partner alpha customer, beta customer type of input?
Like, what has been surprising you about how you thought people were going to deploy this versus how they actually deployed this from your early customers? Yeah, I think, um, uh, few things that, you know, pop to, to the top is, um, lot of, uh, enterprises are multinational enterprises are multi-tenant organizations. So, you know, uh, uh, as, as an early version of product, you design it for a single tenant, very quickly realize that, you know, not all data is necessarily in one region.
It might be spread out in like, and then you, you need to do, uh, access control differently. You need to do data resiliency differently. So for, for a data product, like, uh, like for a platform like ours, making sure we understand, you know, requirements for, you know, customs in different regions and let them manage them, enforce policies on that was, was one good learning, and we have made sure it's part of our product.
Yeah, it ties into, uh, Justin's question just now as well. So, yes. Uh, yes.
I think one, go ahead. Yeah, anything else? And particularly on the, on as organizations, maybe like, one of the things I'm poking at is how organizations are actually thinking about more agent workloads.
So anything has popped up there. Yeah, so, so couple of, uh, so, uh, one thing is like, you know, um, uh, as Gideon showed earlier, you know, product is, is very successful. They have 25,000 customers worldwide.
Uh, and we support a range of customers. We support everybody from, you know, you know, customers in the large Fortune 500 bucket all the way to, you know, uh, you know, uh, mid-size customers and everything, uh, in middle. And so we, we are seeing different customers use this platform for different scenarios.
So the first use case really is I think somebody, uh, initially asked with respect to, Hey, how can I optimize the cost of what I need to bring in to manage my sim? Right? So the first use case is, you know, there's log data sets, you know, maybe assists logs, maybe your network logs, you know, that you necessarily don't analyze on a daily basis.
You now have an easy way to park that in the lake, but it's still available for, uh, for rich analysis out of the box, right? So that is, uh, one use case I'm seeing from, from customers, right? And this was in fact, uh, Gideon referred to the, uh, case study from Nationwide.
That's what they, one of the use cases was like, Hey, we remove the false choice of, you know, what to store versus what to pay by enabling them to store that. So that's one use case. Then we have some customers, um, who are heavy data science, uh, based SOC teams, right?
So they take all the data in the lake and they, they have developed their, you know, Python notebooks. They're doing ML training on the data, they're doing anomaly detection, and they're essentially doing those, essentially those insights on top of the lake as can jobs to find things that are otherwise high to find, like, for example, retro ti hunting or being able to do to beacon detection. Uh, these, these are really hard problems to do, um, if you were just storing 30 days of data, right?
So that's, that's other cost of customers, uh, that we're, uh, seeing. Uh, then on the, on the AI front, we have both partners and customers who are now building co-pilot agents, uh, that connects to Sentinel, you know, quickly finds insights to complete a very core portion of the workflow. So these are the three core use cases that we are seeing early customers, uh, latch onto, That was gonna be my next question also, um, around AI agents that are able to resolve some of the, um, alerts or vulnerabilities that are found from a specific path.
Sorry, uh, uh, Rumi, if you may, uh, um, repeat or elaborate again? Uh, sure, Sure. Um, so say we've looked at a specific path that has, um, that has been identified as a risk, is there a possibility to build, I know I've seen, um, SOC agents built to resolve certain things, but is there a way to build a SOC agent that can resolve some of these, um, alerts that have been identified via a path?
Uh, yes. It's, it's, it's totally possible, right? So, um, um, uh, so far what I've seen is, you know, people are a little careful of letting an agent, you know, take an action, like, for example, quarantine a device or, uh, reset a password.
But technically it's, it's all possible for, so you can, you know, for example, you found a vulnerability, uh, in a device, can they go ahead and ask, uh, inq agent to say, for example, go patch it technically, you know, those are possible parts, uh, but we again, be careful to make sure how we expand into letting, you know, AI take actions in the environment. So, so like, uh, I would say start with read, triage, analyze, uh, and then graduate to act Absolutely. Um, um, uh, Again, as, as gonna make your systems more, more robust.
Yeah. Yeah. I was just curious around that.
Thank you for that. And so is that used in the queries that, that are kind of AI driven to actually set those guardrails to keep it from hallucinating? Yeah.
So, um, in the backend system, you know, when you, when we generate the query, we do have, you know, a bunch of checks and verifier that is happening, um, to make sure we scope down what is being returned so that it, it, it doesn't hallucinate, right? Like, uh, this is an industry-wide challenge, right? And as we all adopt ai, we have to, you know, continuously keep finding, you know, uh, techniques that, you know, reduces, uh, the, the rate of hallucination.
So the accuracy of the responses keeps improving. Uh, but, you know, as, as we've all learned, like dealing with the systems, we have to always keep in mind that, you know, it can sometimes not be accurate. And so we have to continuously either tune the input, tune the prompts, you know, uh, give it the right context, make sure that the, uh, that the, that the data that it's, it's is reasoning over is accurate enough so that doesn't, you know, make up stuff and, you know, uh, fill with wrong information.