Integrated Service Demo

This demo showcases how our solutions seamlessly integrate Microsoft Sentinel, Microsoft Teams (via Lumina), and D3 Security to provide a streamlined and effective security workflow.

1. Microsoft Sentinel

Scenario: A potential security incident is detected based on a custom analytic rule. The alert triggers within Sentinel, capturing key information about the suspicious activity.

Incident Overview: INC-00123
Title: Unusual Login Activity
Severity: Critical
Status: New
Created: 2024-04-01 10:30 AM
Owner: Unassigned
Entities:
  • User: john.doe@example.com
  • IP: 123.45.67.89 (North Korea)
  • Host: SRV-FIN-01
Description: Multiple failed login attempts followed by a successful login from an unrecognized IP.
Comments:

    2. D3 Security

    Response: D3 automatically generates the required tasks, based on the Incident categorisation. In this instance, it's an usual account activity. The Analyst is assigned a list of Tasks to work through, which interact with Teams and the tool required to remediate the event. In this scenario, it's Entra.

    Playbook Execution: INC-00123 - User Compromise Response
    Take Ownership
    Notify Client + Request Approval
    Reset User Password (Entra ID)
    Lock User Account (Entra ID)
    Revoke User Sessions (Entra ID)
    Notify Security Lead

    3. Microsoft Teams (via Lumina)

    Action: Lumina, our Teams integration bot, receives the alert details from Sentinel (triggered by D3) and posts an interactive card to a designated security channel. This card presents a summary of the incident and provides action buttons for quick response.

    Kocho x Customer Chat

    Teams chat is currently empty. Awaiting D3 action...

    Automated Playbook Execution (Background)

    Once approved via Teams, the D3 Security playbook orchestrates the following automated actions:

    Receive Approval Signal Pending
    Revoke User Sessions (Entra ID) Pending
    Reset User Password (Entra ID) Pending
    Lock User Account (Entra ID) Pending
    Update Sentinel Incident Pending
    Log Actions in D3 Case Pending

    This section visualizes the automated steps performed by the D3 playbook in the background.

    Return to Home Page