august 21, 2019 - owasp · 2019-08-26 · exam 346: managing office 365 identities... microsoft...

21
August 21, 2019 Log Analytics Web App

Upload: others

Post on 27-Jan-2020

0 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

August 21, 2019

Application Gateway

Log Analytics

Web App

Page 3: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 4: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 5: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

Open Web Application Security Project

OWASP ModSecurity Core Rule Set (CRS)

Page 7: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

*

https://www.zaproxy.org/

https://github.com/zaproxy/zap-hud

Page 8: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

Case ManagementAnalytics - Alerts

AzureSentinel

Page 9: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

Azure Application Gateway

▪ An application delivery controller

▪ layer 7 load balancing/routing capabilities

▪ web application firewall.

Page 10: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

OWASP

ModSecurity Core Rule Set

Page 11: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

https://docs.microsoft.com/en-us/azure/azure-monitor/azure-monitor-rebrand#log-analytics-redefinition

Page 12: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 13: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 14: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 15: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config

• Configuration

• Penetration Test

• Monitoring with Log Analytics

• Alert

• Security Center, Azure Sentinel

* see appendix slides for demo screenshots

Page 16: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 18: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 19: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 20: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config
Page 21: August 21, 2019 - OWASP · 2019-08-26 · Exam 346: Managing Office 365 Identities... Microsoft Microsoft@ MVP , Most Valuable Professional . Application Gateway Frontend IP Config