Live Response just got smarter with Defender’s Library management
Library Management in the Microsoft Defender portal is a new way to centrally manage the scripts and files your SOC uses in Live Response.
Feb 18, 2026
Library - Topic
Merge the worlds of security and operations. Discover how SecOps practices proactively defend against cyber threats, streamline response mechanisms, and ensure a cohesive approach to organizational security
Articles open in this browser tab. Some require sign-in.
Library Management in the Microsoft Defender portal is a new way to centrally manage the scripts and files your SOC uses in Live Response.
Feb 18, 2026
UEBA in Microsoft Sentinel all in one picture. UEBA turns entities + telemetry into prioritized investigation context - so you spend less time stitching signals and more time acting with confidence.
Feb 09, 2026
New enhancements to Microsoft Sentinel UEBA (in preview) including near real-time behavioral insights, ability to enable from data connector experience and new data sources.
Feb 04, 2026
Microsoft Defender for Cloud - one infographic to get it all (plans, coverage, pricing structure)
Jan 28, 2026
AI is no longer “nice to have” in security operations. It’s quickly becoming the only practical way to keep up with attacker speed, alert volume, and fragmented signals across the digital estate.
Jan 25, 2026
💡 Building a SOC-as-a-Service (SOCaaS) is not just about tools. It’s about designing a repeatable operating model that delivers consistent outcomes across customers, industries, and environments. Many SOCaaS discussions start too deep, too fast. Recently I’ve been asked for a simpler way to frame the Microsoft-aligned approach upfront. This infographic is a bird’s-eye view to…
Jan 20, 2026
Microsoft Security Exposure Management (MSEM): capture the full story - features, integrations, benefits, who it is built for and more.
Jan 12, 2026
4th edition infographic updates Microsoft Security’s portfolio with new integrations, previews, expanded management category, AI posture features, data governance enhancements, and SIEM/XDR integration improvements.
Jan 07, 2026
Microsoft Sentinel SOC optimization turns “we should tune the SIEM” into a living set of recommendations that refresh every 24 hours.
Jan 06, 2026
Modern breach is no longer a sequence of discrete alerts. It’s a path: identity → token → device → cloud control plane → data plane → sensitive information. And the only reliable way to interrupt that path early is to understand, continuously, how the estate is connected.
Dec 17, 2025