You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
### Enhanced integration with Microsoft Sentinel (Preview)
41
+
42
+
The new **IoT OT Threat Monitoring with Defender for IoT solution** is available and provides enhanced capabilities for Microsoft Defender for IoT integration with Microsoft Sentinel. The **IoT OT Threat Monitoring with Defender for IoT solution** is a set of bundled content, including analytics rules, workbooks, and playbooks, configured specifically for Defender for IoT data. This solution currently supports only Operational Networks (OT/ICS).
43
+
44
+
For information on integrating with Microsoft Sentinel, see [Tutorial: Integrate Defender for Iot and Sentinel](/azure/sentinel/iot-solution?tabs=use-out-of-the-box-analytics-rules-recommended)
45
+
46
+
### Apache Log4j vulnerability
37
47
38
48
Version 10.5.4 of Microsoft Defender for IoT mitigates the Apache Log4j vulnerability. For details, see [the security advisory update](https://techcommunity.microsoft.com/t5/microsoft-defender-for-iot/updated-15-dec-defender-for-iot-security-advisory-apache-log4j/m-p/3036844).
39
49
40
-
**Alerting**
50
+
### Alerting
41
51
42
52
Version 10.5.4 of Microsoft Defender for IoT delivers important alert enhancements:
43
53
@@ -46,7 +56,7 @@ Version 10.5.4 of Microsoft Defender for IoT delivers important alert enhancemen
46
56
47
57
These changes reduce alert volume and enable more efficient targeting and analysis of security and operational events.
48
58
49
-
### Alerts permanently disabled
59
+
####Alerts permanently disabled
50
60
51
61
The alerts listed below are permanently disabled with version 10.5.4. Detection and monitoring are still supported for traffic associated with the alerts.
52
62
@@ -56,7 +66,7 @@ The alerts listed below are permanently disabled with version 10.5.4. Detection
56
66
- Unauthorized HTTP Server
57
67
- Abnormal usage of MAC Addresses
58
68
59
-
### Alerts disabled by default
69
+
####Alerts disabled by default
60
70
61
71
The alerts listed below are disabled by default with version 10.5.4. You can re-enable the alerts from the Support page of the sensor console, if required.
62
72
@@ -77,7 +87,7 @@ Disabling these alerts also disables monitoring of related traffic. Specifically
77
87
- Unauthorized HTTP User Agent alert and HTTP User Agents Data Mining traffic
78
88
- Unauthorized HTTP SOAP Action and HTTP SOAP Actions Data Mining traffic
79
89
80
-
### Updated alert functionality
90
+
####Updated alert functionality
81
91
82
92
**Unauthorized Database Operation alert**
83
93
Previously, this alert covered DDL and DML alerting and Data Mining reporting. Now:
0 commit comments