<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security Operations &amp; XDR on Microsoft 365 Security Insights</title><link>https://thecybersec.gr/categories/security-operations-xdr/</link><description>Recent content in Security Operations &amp; XDR on Microsoft 365 Security Insights</description><generator>Hugo</generator><language>el-gr</language><lastBuildDate>Sun, 30 Aug 2026 21:10:00 +0300</lastBuildDate><atom:link href="https://thecybersec.gr/categories/security-operations-xdr/index.xml" rel="self" type="application/rss+xml"/><item><title>Defender XDR: Μία ενέργεια, όλοι οι λογαριασμοί, το unified response actions για ταυτότητες έρχεται τον Οκτώβριο, τι φέρνει το MC1461704</title><link>https://thecybersec.gr/posts/new-features/defender-xdr-unified-response-actions-identity-accounts/</link><pubDate>Fri, 28 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/new-features/defender-xdr-unified-response-actions-identity-accounts/</guid><description>Μέχρι σήμερα, το να απενεργοποιήσεις έναν compromised χρήστη σήμαινε να ανοίξεις τρία ή τέσσερα διαφορετικά console, ένα για το AD, ένα για το Entra, ένα για το SaaS app, και να ελπίζεις ότι δεν ξέχασες κανένα. Το MC1461704 φέρνει αυτές τις ενέργειες σε ένα ενιαίο workflow μέσα από το Identity page, και αυτό αλλάζει άμεσα το πώς πρέπει να γράφονται τα playbooks απόκρισης.</description></item><item><title>Defender XDR: Το Timeline tab της ταυτότητας γίνεται πραγματικά ενιαίο, τι φέρνει το MC1461705</title><link>https://thecybersec.gr/posts/new-features/defender-xdr-unified-identity-timeline/</link><pubDate>Thu, 27 Aug 2026 08:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/new-features/defender-xdr-unified-identity-timeline/</guid><description>Μέχρι σήμερα, η ανασύνθεση μιας χρονολογικής ακολουθίας γύρω από μια ύποπτη ταυτότητα σήμαινε pivoting ανάμεσα σε sign-in logs, audit logs και advanced hunting tables. Το MC1461705 φέρνει όλα αυτά σε ένα timeline, με πεδία σαν το Session ID και το Unique token identifier να μπαίνουν επιτέλους στο investigation view, όχι μόνο στο raw log.</description></item><item><title>Live Webinar: Μάθε το Microsoft Defender XDR σε 60 λεπτά</title><link>https://thecybersec.gr/posts/microsoft-defender-xdr-full-tutorial-ciso/</link><pubDate>Tue, 25 Aug 2026 09:02:00 +0300</pubDate><guid>https://thecybersec.gr/posts/microsoft-defender-xdr-full-tutorial-ciso/</guid><description>Για δεύτερη φορά καλεσμένος στο live του Χρήστου Σπανουγάκη, αυτή τη φορά για ζωντανά demo πάνω στη σουίτα Microsoft Defender. Αυτό το άρθρο κρατάει τα συγκεκριμένα περιστατικά που δείξαμε, όχι έναν συστηματικό οδηγό ανά προϊόν, ο οποίος έρχεται σε ξεχωριστή σειρά.</description></item><item><title>Report a Call &amp; Report a Meeting στο Microsoft Teams: Νέα δυνατότητα αναφοράς ασφαλείας για χρήστες και διαχειριστές</title><link>https://thecybersec.gr/posts/new-features/report-a-call-report-a-meeting-teams-security-reporting/</link><pubDate>Fri, 07 Aug 2026 11:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/new-features/report-a-call-report-a-meeting-teams-security-reporting/</guid><description>Δύο νέα κουμπιά reporting στο Teams (Report a call, Report a meeting) μετατρέπουν τον χρήστη σε αισθητήρα ασφαλείας. Δες πώς δουλεύουν, τι φτάνει στο Defender, τι θέλει ποιο license, και τι πρέπει να ετοιμάσει το SOC σου πριν την GA τον Οκτώβριο 2026.</description></item><item><title>Project Perception: Το Agentic Security System της Microsoft με Red, Blue &amp; Green AI Agents. Τι είναι και τι σημαίνει για το SOC σου.</title><link>https://thecybersec.gr/posts/previews/project-perception-agentic-security-explained/</link><pubDate>Thu, 06 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/previews/project-perception-agentic-security-explained/</guid><description>Το Project Perception μπαίνει σε public preview (3 Αυγούστου 2026) μέσα στο Microsoft Defender. Δες πώς συνεργάζονται red/blue/green agents σε συνεχή βρόχο, τι είναι το «Cyber Stack» και το μοντέλο MAI-Cyber-1-Flash, γιατί δεν είναι το ίδιο με το Security Copilot, πώς χρεώνεται σε Security Compute Units, και μια ειλικρινή, GRC-ματιά για το τι σημαίνει αυτόνομη άμυνα όταν πρέπει να λογοδοτείς.</description></item><item><title>Microsoft Defender AIR: Πώς το Automated Investigation &amp; Response Αλλάζει το SOC (και τι γίνεται μετά την 1η Σεπτεμβρίου 2026)</title><link>https://thecybersec.gr/posts/microsoft-defender-air-automated-investigation-response/</link><pubDate>Tue, 04 Aug 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/microsoft-defender-air-automated-investigation-response/</guid><description>Το AIR είναι ο ψηφιακός αναλυτής που κάνει το βαρύ triage στη θέση σου. Σε αυτό το άρθρο εξηγώ πώς λειτουργεί το pipeline της αυτόματης έρευνας, τι σημαίνουν τα Malicious / Suspicious / No threats found, πώς δουλεύουν τα πέντε automation levels ανά device group, πώς διαβάζεις σωστά το Action Center και τι σημαίνει η αλλαγή της 1ης Σεπτεμβρίου 2026 για το πώς θα δουλεύεις με το AIR από εδώ και πέρα.</description></item><item><title>CaptiveCrunch: Ρώσοι χάκερ στήνουν παγίδα στο Wi-Fi των ξενοδοχείων. Τι είναι και πώς να προστατευτείς</title><link>https://thecybersec.gr/posts/captivecrunch-midnight-blizzard-hotel-wifi-attack/</link><pubDate>Mon, 03 Aug 2026 19:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/captivecrunch-midnight-blizzard-hotel-wifi-attack/</guid><description>Μια ρωσική κρατική ομάδα (Midnight Blizzard / Storm-2945) παραβιάζει το Wi-Fi ξενοδοχείων και συνεδρίων για να χτυπήσει εταιρικούς ταξιδιώτες. Σου δείχνω βήμα-βήμα πώς στήνεται η παγίδα με ψεύτικα updates και ClickFix, τι κάνουν τα εργαλεία CornFlake / ChocoShell / FruitStone, γιατί η κλοπή token είναι το πραγματικό πρόβλημα, και έναν πρακτικό οδηγό προστασίας για όποιον ταξιδεύει για δουλειά.</description></item><item><title>Microsoft Defender Part 1: All Products, Which One Do You Need</title><link>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-1-what-is-microsoft-defender/</link><pubDate>Mon, 18 May 2026 10:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-1-what-is-microsoft-defender/</guid><description>Confused by Microsoft Defender naming? You&amp;rsquo;re not alone. This guide maps the entire Microsoft Defender family, 8 core products, licensing tiers, and when you actually need each one. For CISOs, IT managers, and security teams implementing Microsoft 365 E5 or EMS E5.</description></item><item><title>Microsoft Defender Part 2: The Four Core XDR Workloads, Up Close</title><link>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-2-four-workloads/</link><pubDate>Mon, 25 May 2026 10:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-2-four-workloads/</guid><description>Deep dive into Microsoft Defender&amp;rsquo;s four XDR workloads. Endpoint EDR, Office 365 Safe Links, Identity lateral movement detection, and Cloud Apps shadow IT discovery. Includes a phishing-to-data-exfiltration attack scenario showing how XDR correlation transforms four separate alerts into one unified incident.</description></item><item><title>Microsoft Defender Part 5: A Walk Through the Microsoft Defender Portal</title><link>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-5-portal-tour/</link><pubDate>Mon, 27 Jul 2026 09:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/defender-demystified-series/defender-demystified-part-5-portal-tour/</guid><description>Part 5 closes the series. A guided walk through the unified Microsoft Defender portal, every major navigation section explained, where Microsoft Secure Score now lives inside Exposure Management, how to set up the right roles, a simple KQL hunting query to try, and a 60-minute first-time agenda.</description></item><item><title>Η Οικογένεια Προϊόντων του Microsoft Defender με πρακτικό Οδηγό για νέους επαγγελματίες ασφάλειας &amp; ΥΑΣΠΕ</title><link>https://thecybersec.gr/posts/microsoft-defender-oikogeneia-praktikos-odigos/</link><pubDate>Mon, 13 Jul 2026 10:00:00 +0300</pubDate><guid>https://thecybersec.gr/posts/microsoft-defender-oikogeneia-praktikos-odigos/</guid><description>Ένας πρακτικός χάρτης της οικογένειας Microsoft Defender για νέους επαγγελματίες ασφάλειας: Endpoint, Office 365, Identity, Cloud Apps, Cloud και το ενοποιημένο Defender XDR που τα συνδέει όλα σε ένα incident.</description></item></channel></rss>