ReliaQuest GreyMatter is a unified security operations platform that aggregates, normalizes, and correlates security data across your environment. This lab covers integrating GreyMatter with Microsoft Entra ID for comprehensive identity threat detection, investigation, and automated response—enabling your SOC to detect and respond to identity-based attacks at scale.
ReliaQuest GreyMatter provides a unified platform for security operations, combining detection, investigation, and response capabilities with your existing security tools including Microsoft Entra ID and the broader Microsoft security ecosystem.
| Component | Description |
|---|---|
| GreyMatter Detect | Threat detection across all integrated data sources |
| GreyMatter Investigate | Unified investigation with entity enrichment |
| GreyMatter Respond | Automated and orchestrated response actions |
| GreyMatter Hunt | Proactive threat hunting across data sources |
| Data Connectors | Pre-built integrations for 300+ security tools |
| Response Actions | Automated containment and remediation capabilities |
Sign-in Logs | Audit Logs | Risk Events | Identity Protection
Authentication | Log Export | User Management | Response Actions
Data Normalization | Correlation | Detection | SOAR
Alerts | Investigations | Automated Response | Reporting
Sign-in logs, audit logs, risk events, directory data
Identity-based threat detection with ML models
User entity pages, timeline, related alerts
Disable users, revoke sessions, block IPs
User context, group membership, risk score
Cross-platform identity correlation
Configure the data connector to ingest Entra ID logs into ReliaQuest.
Configure direct Graph API access for enrichment and response actions.
Build detection rules for identity-based attacks in GreyMatter.
Multiple users targeted from single IP with same password failures. Threshold: >10 users, same error code, within 5 minutes.
Multiple MFA push notifications followed by approval. Threshold: >5 MFA prompts within 10 minutes, then success.
User consented to OAuth app with sensitive permissions. Detect: Mail.Read, Files.ReadWrite, Directory.Read granted.
New secret or certificate added to service principal. Persistence mechanism for attackers.
Security policy disabled or modified. Could indicate attacker covering tracks.
Sign-in using protocols that don't support MFA (IMAP, POP3, SMTP).
Build investigation workflows for identity-related alerts.
Build automated response playbooks for identity threats.
Create dashboards for identity security monitoring and reporting.
Integrate threat intel feeds for enhanced identity detection.
Advanced detection and response patterns for complex threats.