Skip to content
Home

Microsoft Sentinel

Cloud-native SIEM that detects threats, investigates incidents, and automates response with a built-in data lake

The product is a cloud-native SIEM that detects threats across identities, endpoints, cloud apps and infrastructure, investigates incidents, and automates response while retaining logs in a built-in data lake to control costs. It is sold to security operations centers, IT and operations teams in businesses and government organizations of all sizes. It is delivered as a SaaS platform with 400+ connectors, unified SOAR, UEBA, threat intelligence and AI-assisted workflows within the Defender experience.

Key features

  • Detect threats across multi-cloud environments
  • Correlate signals across identities and endpoints
  • Catch lateral movement and phishing
  • Security orchestration automation and response
  • User and entity behavior analytics
  • Threat intelligence integration
  • AI-assisted analyst workflows
  • Ingest data from 400+ connectors
  • Built-in data lake for log retention
  • Flexible tiering to lower TCO
  • No social media activity detected
GTM channels
  • Blog
  • Partner program
  • Marketplace
  • Docs
ICP
  • Security teams
  • IT teams
  • Government public sector
VendorMicrosoft Azure