{"id":25819,"date":"2019-02-28T18:00:14","date_gmt":"2019-02-28T18:00:14","guid":{"rendered":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/"},"modified":"2019-02-28T18:00:14","modified_gmt":"2019-02-28T18:00:14","slug":"in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/","title":{"rendered":"In the cloud, things aren&#8217;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel"},"content":{"rendered":"<p><strong class=\"trailer\">RSA<\/strong> Microsoft has wheeled out two new enterprise security tools \u2013 Azure Sentinel, a cloud-based SIEM, and Microsoft Threat Experts, an infosec advice-as-a-service bundled with a panic button.<\/p>\n<p>The two services are part of Redmond&#8217;s <a target=\"_blank\" href=\"https:\/\/www.theregister.co.uk\/2018\/09\/24\/microsoft_kills_passwords\/\">ongoing invasion of the cloud security market<\/a>. It will be showing off the technology at the RSA Conference in San Francisco next week.<\/p>\n<p>Ann Johnson, Microsoft&#8217;s cybersecurity solutions veep, described Azure Sentinel as the &#8220;first native SIEM within a major cloud platform&#8221;.<\/p>\n<p>Azure Sentinel customers are exhorted by Microsoft to marvel at &#8220;nearly limitless cloud speed and scale&#8221;, assuming the public cloud service and things hanging off it haven&#8217;t gone for an unscheduled nap, as happens from time to time.<\/p>\n<p>The hackneyed message from Johnson is for businesses to &#8220;invest your time in security and not servers&#8221;.<\/p>\n<p>&#8220;Azure Sentinel supports open standards such as Common Event Format (CEF) and broad partner connections, including&#8230; Check Point, Cisco, F5, Fortinet, Palo Alto and Symantec, as well as broader ecosystem partners such as ServiceNow.&#8221;<\/p>\n<h3 class=\"crosshead\"><span>Press the big red Microsoft panic button<\/span><\/h3>\n<p>Johnson also revealed Microsoft Threat Experts, another aaS product that appears to target businesses without an extensive in-house security presence or capability. It was presented as &#8220;a new service within Windows Defender ATP which provides managed hunting to extend the capability of your security operations centre team&#8221;.<\/p>\n<p>You give the keys to your castle over to Microsoft&#8217;s security folk, who will then &#8220;proactively hunt over your anonymized security data for the most important threats, such as human adversary intrusions, hands-on-keyboard attacks, and advanced attacks like cyberespionage&#8221; in Johnson&#8217;s words.<\/p>\n<div class=\"promo_article\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/regmedia.co.uk\/2017\/06\/07\/careerambition.jpg?x=174&amp;y=115&amp;crop=1\" width=\"174\" height=\"115\" alt=\"Business suit wearing man walks out of closing door in darkened room into the bright sunlight and blue sky\"\/><\/p>\n<h2 title=\"TypeScript tooling tweaks too, you lucky people\">Microsoft flings open Azure Functions to Java workloads<\/h2>\n<p><a href=\"https:\/\/www.theregister.co.uk\/2019\/02\/27\/java_azure_functions\/\"><span>READ MORE<\/span><\/a><\/div>\n<p>This is security-as-a-service comes with a panic button for when you just don&#8217;t know the answer to a burning infosec question yourself. Thanks to Redmond&#8217;s &#8220;Ask a Threat Expert&#8221;, you can &#8220;submit questions directly&#8221; to MS security bods via the Windows Defender ATP console.<\/p>\n<p>Tom Kranz, head of cyber labs at British tech consultancy 6point6 and a one-time enterprise security architect, was not impressed by the announcement. He told <em>The Register<\/em>:<\/p>\n<p>\u201cMicrosoft Azure Sentinel continues a worrying process of cloud providers eating their partners\u2019 lunch, which is neither good for the industry nor for customers. Azure Operations Management Suite and Security Centre lacked the event correlation and automation that market leaders like Splunk and Alienvault know is needed for a SIEM to be anything other than an irritating source of noise.&#8221;<\/p>\n<p>Kranz did concede that Sentinel &#8220;may fill that &#8216;just good enough&#8217; gap between basic tools like OMS and the full-fat products like Splunk.&#8221;<\/p>\n<p>To join the public preview of Microsoft Threat Experts, apply in the Windows Defender ATP settings, or if Azure Sentinel floats your corporate boat, there&#8217;s more about it on Microsoft&#8217;s <a target=\"_blank\" rel=\"nofollow\" href=\"https:\/\/azure.microsoft.com\/en-gb\/services\/azure-sentinel\">website<\/a>. \u00ae<\/p>\n<p class=\"wptl btm\"><span>Sponsored:<\/span> <a href=\"https:\/\/go.theregister.co.uk\/tl\/1810\/-7143\/cloud-security-from-start-point-to-end-point?td=wptl1810\">Cloud Security: From Start Point to End Point<\/a><\/p>\n<p>READ MORE <a href=\"http:\/\/go.theregister.com\/feed\/www.theregister.co.uk\/2019\/02\/28\/microsoft_azure_sentinel_wheeled_out\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>And &#8216;ask a Redmond security bod&#8217; panic button for Windows Defender ATP customers RSA\u00a0 Microsoft has wheeled out two new enterprise security tools \u2013 Azure Sentinel, a cloud-based SIEM, and Microsoft Threat Experts, an infosec advice-as-a-service bundled with a panic button.\u2026 READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":25820,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[63],"tags":[],"class_list":["post-25819","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-the-register"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.6 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>In the cloud, things aren&#039;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"In the cloud, things aren&#039;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2019-02-28T18:00:14+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"174\" \/>\n\t<meta property=\"og:image:height\" content=\"115\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"In the cloud, things aren&#8217;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel\",\"datePublished\":\"2019-02-28T18:00:14+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/\"},\"wordCount\":493,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg\",\"articleSection\":[\"The Register\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/\",\"name\":\"In the cloud, things aren't always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg\",\"datePublished\":\"2019-02-28T18:00:14+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2019\\\/03\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg\",\"width\":174,\"height\":115},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"In the cloud, things aren&#8217;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"In the cloud, things aren't always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/","og_locale":"en_US","og_type":"article","og_title":"In the cloud, things aren't always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2019-02-28T18:00:14+00:00","og_image":[{"width":174,"height":115,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"In the cloud, things aren&#8217;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel","datePublished":"2019-02-28T18:00:14+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/"},"wordCount":493,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg","articleSection":["The Register"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/","url":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/","name":"In the cloud, things aren't always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg","datePublished":"2019-02-28T18:00:14+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2019\/03\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel.jpg","width":174,"height":115},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/in-the-cloud-things-arent-always-what-they-siem-microsoft-rolls-out-ai-driven-azure-sentinel\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"In the cloud, things aren&#8217;t always what they SIEM: Microsoft rolls out AI-driven Azure Sentinel"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25819","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=25819"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/25819\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/25820"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=25819"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=25819"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=25819"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}