Microsoft Sentinel
Cloud-native SIEM that detects threats, investigates incidents, and automates response with a built-in data lake
The product is a cloud-native SIEM that detects threats across identities, endpoints, cloud apps and infrastructure, investigates incidents, and automates response while retaining logs in a built-in data lake to control costs. It is sold to security operations centers, IT and operations teams in businesses and government organizations of all sizes. It is delivered as a SaaS platform with 400+ connectors, unified SOAR, UEBA, threat intelligence and AI-assisted workflows within the Defender experience.
Key features
- Detect threats across multi-cloud environments
- Correlate signals across identities and endpoints
- Catch lateral movement and phishing
- Security orchestration automation and response
- User and entity behavior analytics
- Threat intelligence integration
- AI-assisted analyst workflows
- Ingest data from 400+ connectors
- Built-in data lake for log retention
- Flexible tiering to lower TCO
- No social media activity detected
GTM channels
- Blog
- Partner program
- Marketplace
- Docs
ICP
- Security teams
- IT teams
- Government public sector
VendorMicrosoft Azure