SOP-35: Azure Firewall Threat Intelligence Alert
Detection and response procedures for Azure Firewall threat intelligence deny events and IDPS signature matches. Covers AzureDiagnostics parsing for TI deny logs, Azure Firewall Premium IDPS severity analysis, and the critical distinction between blocked TI traffic and IDPS alerts in Alert mode.
Rudra Verma, Senior Security Architect & Researcher