Monitoring and filtering just about any firewall has
never been so easy with Microsoft Sentinel and the SecQube Portal
A great feature of Microsoft Sentinel is monitoring firewalls. When combined with the SecQube Portal you have a powerful tool to quickly find the root cause of a firewall attack
Our unique No-Code KQL interface will allow you to click on any of the orange entries, for example a port. Harvey will then start to build the query for you
By using the No-Code KQL interface you can filter the devices actions to locate the action on the firewall. Like find all open ports after a port scan
A key requirement in the design of our portal was not to move data from its source. All data remains in your Microsoft Sentinel tenant; our API only reads the information. If you use the ticketing and/or change management solution, this does change. However, it will remain in the same Azure data centre
Configuring the SecQube Solution is straightforward, even for beginners. We use Azure Lighthouse to connect to Microsoft Sentinel, which involves running a pre-defined script in Azure by a user with the right permissions, like a Global or Security Administrator. This takes about 2-5 minutes. After that, add your Azure Subscription to our portal, wait 20 minutes, and you're set!
Harvey up-skills analysts, assisting with your every step whilst engaged in threat hunting. Harvey will educate you and give you calculated answers, speeding the triage period up.
Our solution stands out with its user-friendly interface and comprehensive features that cater to businesses of all sizes. Whether you're a small business or a large corporation, our platform adapts to your needs.
Yes. The SecQube portal can automatically alert you to an incident, and each incident is accompanied by triage steps as well as a severity level
SecQube Firewall monitoring is critical for several reasons:
1. Detect Threats: Monitoring your firewalls lets you detect potential threats or malicious activities in real-time. By continuously examining the traffic that passes through the firewall, you can identify patterns or behaviours that may indicate a security threat.
2. Prevent Breaches: Continuous firewall monitoring can help prevent security breaches. If a potential threat is detected, immediate action can be taken to neutralise it, preventing it from penetrating your network.
3. Compliance: Many regulations and standards require regular firewall monitoring. By continuously monitoring your firewall, you can ensure that you are meeting these requirements and avoid potential fines or penalties.
4. Performance Optimisation: Monitoring the firewall also helps to ensure it is performing optimally. If the firewall is not working efficiently, it can slow down the network and reduce productivity.
5. Incident Response: If a security incident does occur, having detailed logs from your firewall can help in the investigation and remediation process. It provides valuable information about the incident, such as when it occurred, how it happened, and what systems were affected.
6. Proactive Security: Regular monitoring allows for a more proactive approach to security.
Instead of waiting for a breach to occur, you can identify patterns or behaviours that may indicate a security threat by continuously examining the traffic that passes through the firewall, thereby identifying and addressing potential threats before they become a problem.